6.1

CVSS3.1

CVE-2025-58091 -

Multiple reflected cross-site scripting (xss) vulnerabilities exist in the config.php functionality of MedDream PACS Premium 7.3.6.870. Specially crafted malicious URLs can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger these vulnerabilities.This vulne…

πŸ“… Published: Jan. 20, 2026, 2:49 p.m. πŸ”„ Last Modified: Jan. 29, 2026, 2:58 p.m.

6.1

CVSS3.1

CVE-2025-58090 -

Multiple reflected cross-site scripting (xss) vulnerabilities exist in the config.php functionality of MedDream PACS Premium 7.3.6.870. Specially crafted malicious URLs can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger these vulnerabilities.This vulne…

πŸ“… Published: Jan. 20, 2026, 2:49 p.m. πŸ”„ Last Modified: Jan. 29, 2026, 3:18 p.m.

6.1

CVSS3.1

CVE-2025-58089 -

Multiple reflected cross-site scripting (xss) vulnerabilities exist in the config.php functionality of MedDream PACS Premium 7.3.6.870. Specially crafted malicious URLs can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger these vulnerabilities.This vulne…

πŸ“… Published: Jan. 20, 2026, 2:49 p.m. πŸ”„ Last Modified: Jan. 29, 2026, 3:16 p.m.

6.1

CVSS3.1

CVE-2025-58088 -

Multiple reflected cross-site scripting (xss) vulnerabilities exist in the config.php functionality of MedDream PACS Premium 7.3.6.870. Specially crafted malicious URLs can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger these vulnerabilities.This vulne…

πŸ“… Published: Jan. 20, 2026, 2:49 p.m. πŸ”„ Last Modified: Jan. 29, 2026, 3:16 p.m.

6.1

CVSS3.1

CVE-2025-58087 -

Multiple reflected cross-site scripting (xss) vulnerabilities exist in the config.php functionality of MedDream PACS Premium 7.3.6.870. Specially crafted malicious URLs can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger these vulnerabilities.This vulne…

πŸ“… Published: Jan. 20, 2026, 2:49 p.m. πŸ”„ Last Modified: Jan. 29, 2026, 3:16 p.m.

6.1

CVSS3.1

CVE-2025-36556 -

A reflected cross-site scripting (xss) vulnerability exists in the ldapUser functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability.

πŸ“… Published: Jan. 20, 2026, 2:49 p.m. πŸ”„ Last Modified: Jan. 29, 2026, 3:23 p.m.

9.6

CVSS3.1

CVE-2025-53912 -

An arbitrary file read vulnerability exists in the encapsulatedDoc functionality of MedDream PACS Premium 7.3.6.870. A specially crafted HTTP request can lead to an arbitrary file read. An attacker can send http request to trigger this vulnerability.

πŸ“… Published: Jan. 20, 2026, 2:49 p.m. πŸ”„ Last Modified: Jan. 29, 2026, 3:26 p.m.

4.3

CVSS3.1

CVE-2026-0554 - NotificationX <= 3.1.11 - Missing Authorization to Authenticated (Contributor+) Analytics Reset

The NotificationX plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'regenerate' and 'reset' REST API endpoints in all versions up to, and including, 3.1.11. This makes it possible for authenticated attackers, with Contributor-level acc…

πŸ“… Published: Jan. 20, 2026, 2:26 p.m. πŸ”„ Last Modified: April 16, 2026, 2:15 a.m.

7.2

CVSS3.1

CVE-2025-15380 - NotificationX <= 3.2.0 - Unauthenticated DOM-Based Cross-Site Scripting via 'nx-preview'

The NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via the 'nx-preview' POST parameter in all versions up to, and including, 3.2.0. This …

πŸ“… Published: Jan. 20, 2026, 2:26 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2026-0608 - Head Meta Data <= 20251118 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta

The Head Meta Data plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'head-meta-data' post meta field in all versions up to, and including, 20251118 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contribut…

πŸ“… Published: Jan. 20, 2026, 2:26 p.m. πŸ”„ Last Modified: April 16, 2026, 2:15 a.m.
Total resulsts: 349182
Page 2060 of 34,919
Β« previous page Β» next page
Filters