CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

CVE-2025-32147

Description: Missing Authorization vulnerability in coothemes Easy WP Optimizer allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Easy WP Optimizer: from n/a through 1.1.0.

CVSS: HIGH (8.8)

EPSS Score: 0.04%

Source: CVE
April 4th, 2025 (3 months ago)

CVE-2025-32146

Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in JoomSky JS Job Manager allows PHP Local File Inclusion. This issue affects JS Job Manager: from n/a through 2.0.2.

CVSS: HIGH (8.8)

EPSS Score: 0.13%

Source: CVE
April 4th, 2025 (3 months ago)

CVE-2025-32142

Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Stylemix Motors allows PHP Local File Inclusion. This issue affects Motors: from n/a through 1.4.65.

CVSS: HIGH (8.8)

EPSS Score: 0.13%

Source: CVE
April 4th, 2025 (3 months ago)

CVE-2025-32141

Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Stylemix MasterStudy LMS allows PHP Local File Inclusion. This issue affects MasterStudy LMS: from n/a through 3.5.23.

CVSS: HIGH (8.8)

EPSS Score: 0.13%

Source: CVE
April 4th, 2025 (3 months ago)

CVE-2025-32127

Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in onOffice GmbH onOffice for WP-Websites allows SQL Injection. This issue affects onOffice for WP-Websites: from n/a through 5.7.

CVSS: HIGH (7.6)

EPSS Score: 0.04%

Source: CVE
April 4th, 2025 (3 months ago)

CVE-2025-32126

Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in cmsMinds Pay with Contact Form 7 allows SQL Injection. This issue affects Pay with Contact Form 7: from n/a through 1.0.4.

CVSS: HIGH (7.6)

EPSS Score: 0.04%

Source: CVE
April 4th, 2025 (3 months ago)

CVE-2025-32125

Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in silvasoft Silvasoft boekhouden allows SQL Injection. This issue affects Silvasoft boekhouden: from n/a through 3.0.1.

CVSS: HIGH (7.6)

EPSS Score: 0.04%

Source: CVE
April 4th, 2025 (3 months ago)

CVE-2025-32124

Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eleopard Behance Portfolio Manager allows Blind SQL Injection. This issue affects Behance Portfolio Manager: from n/a through 1.7.4.

CVSS: HIGH (7.6)

EPSS Score: 0.04%

Source: CVE
April 4th, 2025 (3 months ago)

CVE-2025-32122

Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix uListing allows Blind SQL Injection. This issue affects uListing: from n/a through 2.1.9.

CVSS: HIGH (7.6)

EPSS Score: 0.04%

Source: CVE
April 4th, 2025 (3 months ago)

CVE-2025-32121

Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SuitePlugins Video & Photo Gallery for Ultimate Member allows SQL Injection. This issue affects Video & Photo Gallery for Ultimate Member: from n/a through 1.1.3.

CVSS: HIGH (7.6)

EPSS Score: 0.04%

Source: CVE
April 4th, 2025 (3 months ago)