8.5

CVSS3.1

CVE-2025-31044 - WordPress Premium SEO Pack <= 3.3.2 - SQL Injection Vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Premium SEO Pack allows SQL Injection.This issue affects Premium SEO Pack: from n/a through 3.3.2.

πŸ“… Published: Jan. 5, 2026, 10:23 a.m. πŸ”„ Last Modified: Jan. 20, 2026, 3:16 p.m.

9.3

CVSS3.1

CVE-2025-30633 - WordPress Amazon Native Shopping Recommendations Plugin <= 1.3 - SQL Injection Vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Amazon Native Shopping Recommendations allows SQL Injection.This issue affects Amazon Native Shopping Recommendations: from n/a through 1.3.

πŸ“… Published: Jan. 5, 2026, 10:21 a.m. πŸ”„ Last Modified: Jan. 20, 2026, 3:16 p.m.

0.0

CVE-2025-69087 - WordPress FreeAgent theme <= 2.1.2 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes FreeAgent freeagent allows PHP Local File Inclusion.This issue affects FreeAgent: from n/a through <= 2.1.2.

πŸ“… Published: Jan. 5, 2026, 10:18 a.m. πŸ”„ Last Modified: April 1, 2026, 5:28 p.m.

5.3

CVSS3.1

CVE-2025-12519 - Information disclosure on Administration parameters API endpoint

Missing Authorization vulnerability in Centreon Infra Monitoring (Administration parameters API endpoint modules) allows Accessing Functionality Not Properly Constrained by ACLs, resulting in Information Disclosure like downtime or acknowledgement configurations.Β This issue affects Infra Monitoring…

πŸ“… Published: Jan. 5, 2026, 10:15 a.m. πŸ”„ Last Modified: Jan. 26, 2026, 3:08 p.m.

6.8

CVSS3.1

CVE-2025-13056 - A user with elevated privileges can inject XSS in the Administration ACL Menus configuration page

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Administration ACL menu configuration modules) allows Stored XSS to users with high privileges. This issue affects Infra Monitoring: from 25.10.0 before 25.10.2…

πŸ“… Published: Jan. 5, 2026, 10:10 a.m. πŸ”„ Last Modified: Jan. 26, 2026, 3:09 p.m.

7.2

CVSS3.1

CVE-2025-5965 - RCE via the backup feature available only to user with high privilege

In the backup parameters, a user with high privilege is able to concatenate custom instructions to the backup setup. Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Centreon Infra Monitoring (Backup configuration in the administration setu…

πŸ“… Published: Jan. 5, 2026, 10:06 a.m. πŸ”„ Last Modified: Jan. 26, 2026, 3:07 p.m.

6.9

CVSS4.0

CVE-2026-0585 - code-projects Online Product Reservation System GET Parameter order_view.php sql injection

A security vulnerability has been detected in code-projects Online Product Reservation System 1.0. Impacted is an unknown function of the file /order_view.php of the component GET Parameter Handler. Such manipulation of the argument transaction_id leads to sql injection. The attack can be executed …

πŸ“… Published: Jan. 5, 2026, 10:02 a.m. πŸ”„ Last Modified: Feb. 23, 2026, 8:14 a.m.

5.3

CVSS4.0

CVE-2026-0584 - code-projects Online Product Reservation System left_cart.php sql injection

A weakness has been identified in code-projects Online Product Reservation System 1.0. This issue affects some unknown processing of the file app/products/left_cart.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been ma…

πŸ“… Published: Jan. 5, 2026, 9:32 a.m. πŸ”„ Last Modified: Feb. 23, 2026, 8:14 a.m.

6.9

CVSS4.0

CVE-2026-0583 - code-projects Online Product Reservation System User Login login.php sql injection

A security flaw has been discovered in code-projects Online Product Reservation System 1.0. This vulnerability affects unknown code of the file app/user/login.php of the component User Login. The manipulation of the argument emailadd results in sql injection. The attack may be launched remotely. Th…

πŸ“… Published: Jan. 5, 2026, 9:02 a.m. πŸ”„ Last Modified: Feb. 23, 2026, 8:13 a.m.

8.8

CVSS4.0

CVE-2025-66518 - Apache Kyuubi: Unauthorized directory access due to missing path normalization

Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and use local files which are not listed in the config. This issue affects Apache Kyuubi: from 1.6.0 through 1.10.2. Users are recommended to upgrade t…

πŸ“… Published: Jan. 5, 2026, 8:46 a.m. πŸ”„ Last Modified: Jan. 27, 2026, 9:32 p.m.
Total resulsts: 344089
Page 1783 of 34,409
Β« previous page Β» next page
Filters