6.4

CVSS3.1

CVE-2025-14865 - Passster – Password Protect Pages and Content <= 4.2.24 - Authenticated (Contributor+) Stored Cross…

The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'content_protector' shortcode in all versions up to, and including, 4.2.24. This makes it possible for authenticated attackers, with Contributor-level access and abov…

πŸ“… Published: Jan. 28, 2026, 12:28 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2026-1056 - Snow Monkey Forms <= 12.0.3 - Unauthenticated Arbitrary File Deletion via Path Traversal

The Snow Monkey Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'generate_user_dirpath' function in all versions up to, and including, 12.0.3. This makes it possible for unauthenticated attackers to delete arbitrary files on the se…

πŸ“… Published: Jan. 28, 2026, 12:28 p.m. πŸ”„ Last Modified: April 15, 2026, 9:45 p.m.

8.5

CVSS4.0

CVE-2025-59901 - authenticated reflected XSS vulnerability in Sync Breeze Enterprise Server

Disk Pulse Enterprise v10.4.18 has an authenticated reflected XSS vulnerability in the '/monitor_directory?sid=' endpoint, caused by insufficient validation of the 'monitor_directory' parameter sent by POST. An attacker could exploit this weakness to send malicious content to an authenticated user …

πŸ“… Published: Jan. 28, 2026, 12:01 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-59900 - Authenticated Cross-Site Scripting (XSS) vulnerability in Sync Breeze Enterprise Server

Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site Scripting (XSS) vulnerability. An attacker could send malicious content to an authenticated user and steal information from their session due to insufficient validation of user in…

πŸ“… Published: Jan. 28, 2026, noon πŸ”„ Last Modified: Feb. 10, 2026, 9:03 p.m.

5.1

CVSS4.0

CVE-2025-59899 - Authenticated Cross-Site Scripting (XSS) vulnerability in Sync Breeze Enterprise Server

Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site Scripting (XSS) vulnerability. An attacker could send malicious content to an authenticated user and steal information from their session due to insufficient validation of user in…

πŸ“… Published: Jan. 28, 2026, 11:59 a.m. πŸ”„ Last Modified: Feb. 10, 2026, 9:04 p.m.

5.1

CVSS4.0

CVE-2025-59898 - Authenticated Cross-Site Scripting (XSS) vulnerability in Sync Breeze Enterprise Server

Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site Scripting (XSS) vulnerability. An attacker could send malicious content to an authenticated user and steal information from their session due to insufficient validation of user in…

πŸ“… Published: Jan. 28, 2026, 11:58 a.m. πŸ”„ Last Modified: Feb. 10, 2026, 9:04 p.m.

5.1

CVSS4.0

CVE-2025-59897 - Authenticated Cross-Site Scripting (XSS) vulnerability in Sync Breeze Enterprise Server

Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site Scripting (XSS) vulnerability. An attacker could send malicious content to an authenticated user and steal information from their session due to insufficient validation of user in…

πŸ“… Published: Jan. 28, 2026, 11:58 a.m. πŸ”„ Last Modified: Feb. 10, 2026, 9:04 p.m.

5.1

CVSS4.0

CVE-2025-59896 - Authenticated Cross-Site Scripting (XSS) vulnerability in Sync Breeze Enterprise Server

Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site Scripting (XSS) vulnerability. An attacker could send malicious content to an authenticated user and steal information from their session due to insufficient validation of user in…

πŸ“… Published: Jan. 28, 2026, 11:58 a.m. πŸ”„ Last Modified: Feb. 10, 2026, 9:04 p.m.

8.2

CVSS4.0

CVE-2025-59895 - Remote denial-of-service (DoS) vulnerability in Sync Breeze Enterprise Server

Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a remote denial-of-service (DoS) vulnerability in the configuration restore functionality. The issue is due to insufficient validation of user-supplied data during this process. An attacker could send malicious reques…

πŸ“… Published: Jan. 28, 2026, 11:55 a.m. πŸ”„ Last Modified: Feb. 10, 2026, 9:07 p.m.

8.5

CVSS4.0

CVE-2025-59894 - Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server

Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause another user to perform unwanted actions within the application they are logged into. This vulnerability is possible due to the lack of pro…

πŸ“… Published: Jan. 28, 2026, 11:53 a.m. πŸ”„ Last Modified: Feb. 10, 2026, 9:08 p.m.
Total resulsts: 349182
Page 1912 of 34,919
Β« previous page Β» next page
Filters