CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

CVE-2025-39381

Description: Cross-Site Request Forgery (CSRF) vulnerability in Kiotviet KiotViet Sync allows Stored XSS. This issue affects KiotViet Sync: from n/a through 1.8.4.

CVSS: HIGH (7.1)

EPSS Score: 0.02%

Source: CVE
April 24th, 2025 (about 2 months ago)

CVE-2025-39379

Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Capturly Capturly allows PHP Local File Inclusion. This issue affects Capturly: from n/a through 2.0.1.

CVSS: HIGH (7.5)

EPSS Score: 0.11%

Source: CVE
April 24th, 2025 (about 2 months ago)

CVE-2025-39378

Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light allows PHP Local File Inclusion. This issue affects Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light: from n/a through 2.4.37.

CVSS: HIGH (7.5)

EPSS Score: 0.11%

Source: CVE
April 24th, 2025 (about 2 months ago)

CVE-2025-39377

Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs Appsero Helper allows SQL Injection. This issue affects Appsero Helper: from n/a through 1.3.4.

CVSS: HIGH (8.5)

EPSS Score: 0.03%

Source: CVE
April 24th, 2025 (about 2 months ago)

CVE-2025-39360

Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in everestthemes Grace Mag allows PHP Local File Inclusion. This issue affects Grace Mag: from n/a through 1.1.5.

CVSS: HIGH (7.5)

EPSS Score: 0.11%

Source: CVE
April 24th, 2025 (about 2 months ago)

CVE-2025-39359

Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Code Work Web CWW Portfolio allows PHP Local File Inclusion. This issue affects CWW Portfolio: from n/a through 1.3.1.

CVSS: HIGH (7.5)

EPSS Score: 0.11%

Source: CVE
April 24th, 2025 (about 2 months ago)

CVE-2025-32921

Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WPoperation Arrival allows PHP Local File Inclusion. This issue affects Arrival: from n/a through 1.4.5.

CVSS: HIGH (7.5)

EPSS Score: 0.11%

Source: CVE
April 24th, 2025 (about 2 months ago)

CVE-2024-24932

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Djo VK Poster Group allows Reflected XSS.This issue affects VK Poster Group: from n/a through 2.0.3.

CVSS: HIGH (7.1)

EPSS Score: 0.06%

SSVC Exploitation: none

Source: CVE
April 24th, 2025 (about 2 months ago)

CVE-2024-24926

Description: Deserialization of Untrusted Data vulnerability in UnitedThemes Brooklyn | Creative Multi-Purpose Responsive WordPress Theme.This issue affects Brooklyn | Creative Multi-Purpose Responsive WordPress Theme: from n/a through 4.9.7.6.

CVSS: HIGH (7.5)

EPSS Score: 33.93%

SSVC Exploitation: none

Source: CVE
April 24th, 2025 (about 2 months ago)

CVE-2024-24884

Description: Cross-Site Request Forgery (CSRF) vulnerability in ARI Soft Contact Form 7 Connector.This issue affects Contact Form 7 Connector: from n/a through 1.2.2.

CVSS: MEDIUM (4.3)

EPSS Score: 0.08%

SSVC Exploitation: none

Source: CVE
April 24th, 2025 (about 2 months ago)