LoveCardsLoveCards LoveCardsV2 image unrestricted upload

7.5
First published (updated )

LoveCardsLoveCards LoveCardsV2 Setting other access control

First published (updated )

zzskzy Warehouse Refinement Management Systemzzskzy Warehouse Refinement Management System getAdyData.ashx ProcessRequest sql injection

First published (updated )

zzskzy Warehouse Refinement Management Systemzzskzy Warehouse Refinement Management System SaveCrash.ashx UploadCrash unrestricted upload

First published (updated )

Doufox DoufoxDoufox s=doudou path traversal

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Microweber WHMCSMicroweber Settings index.php cross site scripting

First published (updated )

Castlenet CBW383G2NCastlenet CBW383G2N Wireless Menu wlanPrimaryNetwork.asp cross site scripting

First published (updated )

Castlenet CBW383G2NCastlenet CBW383G2N RgSwInfo.asp cross site scripting

First published (updated )

SmartThingsSamsung SmartThings Improper Verification of Cryptographic Signature Authentication Bypass Vulnerability

8.8
First published (updated )

aitangbao springboot-manageraitangbao springboot-manager add cross site scripting

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

aitangbao springboot-manageraitangbao springboot-manager add cross site scripting

First published (updated )

go/github.com/cheqd/cheqd-node# Description [An issue was discovered in IBC-Go's deserialization of acknowledgements](https://git…

First published (updated )

OBiBa OpalOpal vulnerable to CSRF protection bypass

7.7
First published (updated )

composer/pimcore/pimcoreSQL Injection

First published (updated )

OBiBa OpalBroken Access Control in Opal filesystem's copy functionality exposes all user data

7.3
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

pip/rembgRembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the CORS middleware is set…

First published (updated )

aitangbao springboot-manageraitangbao springboot-manager add cross site scripting

First published (updated )

pip/rembgSSRF

7.5
First published (updated )

WordPress Review SchemaReview Schema <= 2.2.4 - Authenticated (Contributor+) Local File Inclusion via Post Meta

8.8
First published (updated )

rust/below### Impact A privilege escalation vulnerability existed in the Below service prior to v0.9.0 due to …

7.8
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

ZipList RecipeWordPress ZipList Recipe plugin <= 3.1 - Cross Site Request Forgery (CSRF) vulnerability

First published (updated )

WordPress DP ALTerminator - Missing ALT managerWordPress DP ALTerminator - Missing ALT manager Plugin <= 1.0.2 - Cross Site Scripting (XSS) vulnerability

First published (updated )

Ohtan Spam ByebyeWordPress SPAM-BYBYE Plugin <= 2.2.4 - Cross Site Request Forgery (CSRF) vulnerability

First published (updated )

arkapravamajumder Back To TopWordPress Back To Top Plugin <= 2.0 - Cross Site Request Forgery (CSRF) vulnerability

First published (updated )

WordPress WP Performance PackWordPress WP Performance Pack plugin <= 2.5.3 - Broken Access Control vulnerability

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Lava Ajax SearchWordPress Lava Ajax Search plugin <= 1.1.9 - Cross Site Scripting (XSS) vulnerability

First published (updated )

sakurapixel LunarWordPress Lunar plugin <= 1.3.0 - Cross Site Scripting (XSS) vulnerability

First published (updated )

Maxfoundry MaxA/BWordPress MaxA/B plugin <= 2.2.2 - CSRF to Stored XSS vulnerability

7.1
First published (updated )

BCS Website Solutions Insert CodeWordPress Insert Code plugin <= 2.4 - CSRF to Stored XSS vulnerability

7.1
First published (updated )

DevriX HashtagsWordPress WordPress Hashtags plugin <= 0.3.2 - CSRF to Stored XSS vulnerability

7.1
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203