Total
9949 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-47942 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| The Open edX Platform is a learning management platform. Prior to commit 6740e75c0fdc7ba095baf88e9f5e4f3e15cfd8ba, edxapp has no built-in protection against downloading the python_lib.zip asset from courses, which is a concern since it often contains custom grading code or answers to course problems. This potentially affects any course using custom Python-graded problem blocks. The openedx/configuration repo has had a patch since 2016 in the form of an nginx rule, but this was only intended as a temporary mitigation. As the configuration repo has been deprecated and we have not been able to locate any similar protection in Tutor, it is likely that most deployments have no protection against python_lib.zip being downloaded. The recommended mitigation, implemented in commit 6740e75c0fdc7ba095baf88e9f5e4f3e15cfd8ba, restricts python_lib.zip downloads to just the course team and site staff/superusers. | |||||
| CVE-2025-47887 | 1 Jenkins | 1 Cadence Vmanager | 2026-06-17 | N/A | 4.3 MEDIUM |
| Missing permission checks in Jenkins Cadence vManager Plugin 4.0.1-286.v9e25a_740b_a_48 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified username and password. | |||||
| CVE-2025-47792 | 1 Nextcloud | 1 Desktop | 2026-06-17 | N/A | 5.0 MEDIUM |
| Nextcloud Desktop is the desktop sync client for Nextcloud. In versions of Nextcloud Desktop prior to 3.15, 3rdparty applications already installed on a user machine can create link shares for almost all data via the socket API. These shares can then be easily sent off to an external service. Nextcloud Desktop fixes the issue in version 3.15. No known workarounds are available. | |||||
| CVE-2025-47709 | 1 Miniorange | 1 Miniorange 2fa | 2026-06-17 | N/A | 6.5 MEDIUM |
| Missing Authorization vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Forceful Browsing.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0. | |||||
| CVE-2025-47692 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| Missing Authorization vulnerability in contentstudio Contentstudio contentstudio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contentstudio: from n/a through <= 1.3.5. | |||||
| CVE-2025-47690 | 2026-06-17 | N/A | 8.8 HIGH | ||
| Missing Authorization vulnerability in Smackcoders Inc., Lead Form Data Collection to CRM wp-leads-builder-any-crm allows Privilege Escalation.This issue affects Lead Form Data Collection to CRM: from n/a through <= 3.1. | |||||
| CVE-2025-47688 | 1 Advancedfilemanager | 1 Advanced File Manager | 2026-06-17 | N/A | 5.3 MEDIUM |
| Missing Authorization vulnerability in Saad Iqbal Advanced File Manager file-manager-advanced allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced File Manager: from n/a through <= 5.3.1. | |||||
| CVE-2025-47634 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| Missing Authorization vulnerability in Keylor Mendoza WC Pickup Store wc-pickup-store allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WC Pickup Store: from n/a through <= 1.8.9. | |||||
| CVE-2025-47628 | 1 Quomodosoft | 1 Qs Dark Mode | 2026-06-17 | N/A | 5.4 MEDIUM |
| Missing Authorization vulnerability in quomodosoft QS Dark Mode qs-dark-mode allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects QS Dark Mode: from n/a through <= 3.0. | |||||
| CVE-2025-47619 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| Missing Authorization vulnerability in 6Storage 6Storage Rentals 6storage-rentals allows Path Traversal.This issue affects 6Storage Rentals: from n/a through <= 2.20.2. | |||||
| CVE-2025-47612 | 1 Flowdee | 1 Clickwhale | 2026-06-17 | N/A | 5.4 MEDIUM |
| Missing Authorization vulnerability in ClickWhale ClickWhale clickwhale allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ClickWhale: from n/a through <= 2.4.6. | |||||
| CVE-2025-47602 | 2026-06-17 | N/A | 5.4 MEDIUM | ||
| Missing Authorization vulnerability in ammarahmad786 Calculate Prices based on Distance For WooCommerce calculate-prices-based-on-distance-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Calculate Prices based on Distance For WooCommerce: from n/a through <= 1.3.5. | |||||
| CVE-2025-47601 | 2026-06-17 | N/A | 8.8 HIGH | ||
| Missing Authorization vulnerability in Christiaan Pieterse MaxiBlocks maxi-blocks allows Privilege Escalation.This issue affects MaxiBlocks: from n/a through <= 2.1.0. | |||||
| CVE-2025-47591 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| Missing Authorization vulnerability in CreedAlly Bulk Featured Image bulk-featured-image allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bulk Featured Image: from n/a through <= 1.2.4. | |||||
| CVE-2025-47585 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Booking and Rental Manager: from n/a through <= 2.3.8. | |||||
| CVE-2025-47580 | 1 Etoilewebdesign | 1 Front End Users | 2026-06-17 | N/A | 5.4 MEDIUM |
| Missing Authorization vulnerability in Rustaurius Front End Users front-end-only-users allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Front End Users: from n/a through <= 3.2.35. | |||||
| CVE-2025-47565 | 2026-06-17 | N/A | 6.3 MEDIUM | ||
| Missing Authorization vulnerability in ashanjay EventON eventon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventON: from n/a through <= 4.9.9. | |||||
| CVE-2025-47564 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| Missing Authorization vulnerability in ashanjay EventON eventon allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects EventON: from n/a through <= 4.9.8. | |||||
| CVE-2025-47563 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| Missing Authorization vulnerability in villatheme CURCY woocommerce-multi-currency allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects CURCY: from n/a through <= 2.3.7. | |||||
| CVE-2025-47560 | 2026-06-17 | N/A | 5.0 MEDIUM | ||
| Missing Authorization vulnerability in RomanCode MapSVG mapsvg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MapSVG: from n/a through < 8.6.13. | |||||
