CVE Alert: CVE-2025-3438
Vulnerability Summary: CVE-2025-3438 The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is...
Vulnerability Summary: CVE-2025-3438 The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is...
Vulnerability Summary: CVE-2025-3488 The WPML plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpml_language_switcher shortcode in...
Vulnerability Summary: CVE-2025-3514 The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which...
Vulnerability Summary: CVE-2024-13858 The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘invitee_name’ parameter in...
Vulnerability Summary: CVE-2024-13859 The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bp_nouveau_ajax_media_save’ function in...
Vulnerability Summary: CVE-2024-13860 The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bbp_topic_title’ parameter in...
Vulnerability Summary: CVE-2024-11142 Cross-Site Request Forgery (CSRF) vulnerability in Gosoft Software Proticaret E-Commerce allows Cross Site Request Forgery.This issue affects...
Vulnerability Summary: CVE-2025-2812 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mydata Informatics Ticket...
Vulnerability Summary: CVE-2025-2421 Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Informatics SambaBox allows Code Injection.This issue...
Vulnerability Summary: CVE-2025-2605 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Honeywell MB-Secure...
Vulnerability Summary: CVE-2025-2488 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Profelis Informatics SambaBox...
Vulnerability Summary: CVE-2025-1301 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Yordam Informatics Library...
Vulnerability Summary: CVE-2025-4204 The Ultimate Auction Pro plugin for WordPress is vulnerable to SQL Injection via the ‘auction_id’ parameter in...
Vulnerability Summary: CVE-2025-4166 Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in server...
Vulnerability Summary: CVE-2025-1883 Out-Of-Bounds Write vulnerability exists in the OBJ file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop...
Vulnerability Summary: CVE-2025-4210 A vulnerability classified as critical was found in Casdoor up to 1.811.0. This vulnerability affects the function...
Vulnerability Summary: CVE-2025-3879 Vault Community, Vault Enterprise (“Vault”) Azure Auth method did not correctly validate the claims in the Azure-issued...
Vulnerability Summary: CVE-2025-1884 Use-After-Free vulnerability exists in the SLDPRT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025....
Vulnerability Summary: CVE-2024-58253 In the obfstr crate before 0.4.4 for Rust, the obfstr! argument type is not restricted to string...
Vulnerability Summary: CVE-2025-4214 A vulnerability was found in PHPGuruku Online DJ Booking Management System 1.0 and classified as critical. This...
Vulnerability Summary: CVE-2025-46332 Flags SDK is an open-source feature flags toolkit for Next.js and SvelteKit. Impacted versions include flags from...
Vulnerability Summary: CVE-2025-4215 A vulnerability was found in gorhill uBlock Origin up to 1.63.3b16. It has been classified as problematic....
Vulnerability Summary: CVE-2025-4213 A vulnerability has been found in PHPGurukul Online Birth Certificate System 1.0 and classified as critical. This...
Vulnerability Summary: CVE-2022-21546 In newer version of the SBC specs, we have a NDOB bit that indicates there is no...