CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

CVE-2025-47549

Description: Unrestricted Upload of File with Dangerous Type vulnerability in Themefic BEAF allows Upload a Web Shell to a Web Server. This issue affects BEAF: from n/a through 4.6.10.

CVSS: CRITICAL (9.1)

EPSS Score: 0.06%

Source: CVE
May 7th, 2025 (about 1 month ago)

CVE-2025-47548

Description: Server-Side Request Forgery (SSRF) vulnerability in Varun Dubey Wbcom Designs - Activity Link Preview For BuddyPress allows Server Side Request Forgery. This issue affects Wbcom Designs - Activity Link Preview For BuddyPress: from n/a through 1.4.4.

CVSS: MEDIUM (5.4)

EPSS Score: 0.04%

Source: CVE
May 7th, 2025 (about 1 month ago)

CVE-2025-47547

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SendPulse SendPulse Email Marketing Newsletter allows Stored XSS. This issue affects SendPulse Email Marketing Newsletter: from n/a through 2.1.6.

CVSS: MEDIUM (6.5)

EPSS Score: 0.03%

Source: CVE
May 7th, 2025 (about 1 month ago)

CVE-2025-47546

Description: Cross-Site Request Forgery (CSRF) vulnerability in AresIT WP Compress allows Cross Site Request Forgery. This issue affects WP Compress: from n/a through 6.30.30.

CVSS: HIGH (7.1)

EPSS Score: 0.02%

Source: CVE
May 7th, 2025 (about 1 month ago)

CVE-2025-47545

Description: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Ays Pro Poll Maker allows Leveraging Race Conditions. This issue affects Poll Maker: from n/a through 5.7.7.

CVSS: MEDIUM (5.3)

EPSS Score: 0.06%

Source: CVE
May 7th, 2025 (about 1 month ago)

CVE-2025-47544

Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in acowebs Dynamic Pricing With Discount Rules for WooCommerce allows Blind SQL Injection. This issue affects Dynamic Pricing With Discount Rules for WooCommerce: from n/a through 4.5.8.

CVSS: HIGH (7.6)

EPSS Score: 0.04%

Source: CVE
May 7th, 2025 (about 1 month ago)

CVE-2025-47543

Description: Cross-Site Request Forgery (CSRF) vulnerability in themetechmount TrueBooker allows Cross Site Request Forgery. This issue affects TrueBooker: from n/a through 1.0.7.

CVSS: MEDIUM (4.3)

EPSS Score: 0.02%

Source: CVE
May 7th, 2025 (about 1 month ago)

CVE-2025-47542

Description: Cross-Site Request Forgery (CSRF) vulnerability in Michael Simple calendar for Elementor allows Cross Site Request Forgery. This issue affects Simple calendar for Elementor: from n/a through 1.6.5.

CVSS: MEDIUM (4.3)

EPSS Score: 0.02%

Source: CVE
May 7th, 2025 (about 1 month ago)

CVE-2025-47540

Description: Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs weMail allows Retrieve Embedded Sensitive Data. This issue affects weMail: from n/a through 1.14.13.

CVSS: MEDIUM (5.3)

EPSS Score: 0.04%

Source: CVE
May 7th, 2025 (about 1 month ago)

CVE-2025-47538

Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdever Cart tracking for WooCommerce allows SQL Injection. This issue affects Cart tracking for WooCommerce: from n/a through 1.0.17.

CVSS: HIGH (7.6)

EPSS Score: 0.04%

Source: CVE
May 7th, 2025 (about 1 month ago)