CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

CVE-2025-39365

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rocket Apps wProject allows Reflected XSS.This issue affects wProject: from n/a before 5.8.0.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
May 19th, 2025 (28 days ago)

CVE-2025-39357

Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla Hospital Management System allows SQL Injection.This issue affects Hospital Management System: from n/a through 47.0(20-11-2023).

CVSS: HIGH (8.5)

EPSS Score: 0.03%

Source: CVE
May 19th, 2025 (28 days ago)

CVE-2025-39355

Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in roninwp FAT Services Booking allows SQL Injection.This issue affects FAT Services Booking: from n/a through 5.6.

CVSS: HIGH (8.5)

EPSS Score: 0.03%

Source: CVE
May 19th, 2025 (28 days ago)

CVE-2025-39352

Description: Missing Authorization vulnerability in ThemeGoods Grand Restaurant WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Grand Restaurant WordPress: from n/a through 7.0.

CVSS: HIGH (8.2)

EPSS Score: 0.05%

Source: CVE
May 19th, 2025 (28 days ago)

CVE-2025-39350

Description: Missing Authorization vulnerability in Rocket Apps wProject.This issue affects wProject: from n/a before 5.8.0.

CVSS: HIGH (8.2)

EPSS Score: 0.05%

Source: CVE
May 19th, 2025 (28 days ago)

CVE-2025-32925

Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in FantasticPlugins SUMO Reward Points allows PHP Local File Inclusion.This issue affects SUMO Reward Points: from n/a through 30.7.0.

CVSS: HIGH (8.3)

EPSS Score: 0.11%

Source: CVE
May 19th, 2025 (28 days ago)

CVE-2025-32924

Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in roninwp Revy allows SQL Injection.This issue affects Revy: from n/a through 2.1.

CVSS: HIGH (8.5)

EPSS Score: 0.03%

Source: CVE
May 19th, 2025 (28 days ago)

CVE-2025-31027

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jocoxdesign Tiger tiger allows Reflected XSS.This issue affects Tiger: from n/a through 2.0.

CVSS: HIGH (7.1)

EPSS Score: 0.03%

Source: CVE
May 19th, 2025 (28 days ago)

CVE-2025-47934

Description: OpenPGP.js is a JavaScript implementation of the OpenPGP protocol. Startinf in version 5.0.1 and prior to versions 5.11.3 and 6.1.1, a maliciously modified message can be passed to either `openpgp.verify` or `openpgp.decrypt`, causing these functions to return a valid signature verification result while returning data that was not actually signed. This flaw allows signature verifications of inline (non-detached) signed messages (using `openpgp.verify`) and signed-and-encrypted messages (using `openpgp.decrypt` with `verificationKeys`) to be spoofed, since both functions return extracted data that may not match the data that was originally signed. Detached signature verifications are not affected, as no signed data is returned in that case. In order to spoof a message, the attacker needs a single valid message signature (inline or detached) as well as the plaintext data that was legitimately signed, and can then construct an inline-signed message or signed-and-encrypted message with any data of the attacker's choice, which will appear as legitimately signed by affected versions of OpenPGP.js. In other words, any inline-signed message can be modified to return any other data (while still indicating that the signature was valid), and the same is true for signed+encrypted messages if the attacker can obtain a valid signature and encrypt a new message (of the attacker's choice) together with that signature. The issue has been patched in versions 5.11.3 and 6.1.1. Some workaroun...

CVSS: HIGH (8.7)

EPSS Score: 0.01%

Source: CVE
May 19th, 2025 (28 days ago)

CVE-2025-43839

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shanebp BP Messages Tool allows Reflected XSS.This issue affects BP Messages Tool: from n/a through 2.2.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

SSVC Exploitation: none

Source: CVE
May 19th, 2025 (28 days ago)