6.5

CVSS3.1

CVE-2025-2267 - WP01 โ€“ Speed, Security, SEO consultant <= 2.6.2 - Authenticated (Subscriber+) Arbitrary File Downloโ€ฆ

The WP01 plugin for WordPress is vulnerable to Arbitrary File Download in all versions up to, and including, 2.6.2 due to a missing capability check and insufficient restrictions on the make_archive() function. This makes it possible for authenticated attackers, with Subscriber-level access and aboโ€ฆ

๐Ÿ“… Published: March 15, 2025, 3:23 a.m. ๐Ÿ”„ Last Modified: March 17, 2025, 9:28 p.m.

6.1

CVSS3.1

CVE-2025-2164 - pixelstats <= 0.8.2 - Reflected Cross-Site Scripting

The pixelstats plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post_id' and 'sortby' parameters in all versions up to, and including, 0.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrโ€ฆ

๐Ÿ“… Published: March 15, 2025, 3:23 a.m. ๐Ÿ”„ Last Modified: March 17, 2025, 9:28 p.m.

6.1

CVSS3.1

CVE-2025-2163 - Zoorum Comments <= 0.9 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The Zoorum Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9. This is due to missing or incorrect nonce validation on the zoorum_set_options() function. This makes it possible for unauthenticated attackers to update settings and injโ€ฆ

๐Ÿ“… Published: March 15, 2025, 3:23 a.m. ๐Ÿ”„ Last Modified: March 17, 2025, 9:28 p.m.

4.9

CVSS3.1

CVE-2024-13847 - Portfolio and Projects <= 1.5.3 - Authenticated (Administrator+) Stored Cross-Site Scripting

The Portfolio and Projects plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level permisโ€ฆ

๐Ÿ“… Published: March 15, 2025, 3:23 a.m. ๐Ÿ”„ Last Modified: March 17, 2025, 9:28 p.m.

8.8

CVSS3.1

CVE-2025-1653 - Directory Listings WordPress plugin โ€“ uListing <= 2.1.7 - Authenticated (Subscriber+) Privilege Escโ€ฆ

The Directory Listings WordPress plugin โ€“ uListing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.7. This is due to the stm_listing_profile_edit AJAX action not having enough restriction on the user meta that can be updated. This makes it possibโ€ฆ

๐Ÿ“… Published: March 15, 2025, 2:22 a.m. ๐Ÿ”„ Last Modified: March 17, 2025, 9:28 p.m.

8.8

CVSS3.1

CVE-2025-1657 - Directory Listings WordPress plugin โ€“ uListing <= 2.1.7 - Missing Authorization to Authenticated (Sโ€ฆ

The Directory Listings WordPress plugin โ€“ uListing plugin for WordPress is vulnerable to unauthorized modification of data and PHP Object Injection due to a missing capability check on the stm_listing_ajax AJAX action in all versions up to, and including, 2.1.7. This makes it possible for authenticโ€ฆ

๐Ÿ“… Published: March 15, 2025, 2:22 a.m. ๐Ÿ”„ Last Modified: March 17, 2025, 9:28 p.m.

8.6

CVSS3.1

CVE-2025-30066 -

tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at commit 0e58ed8, which contained malicious updateFeatures code.)

๐Ÿ“… Published: March 15, 2025, midnight ๐Ÿ”„ Last Modified: March 17, 2025, 3:47 p.m.

0.0

CVE-2025-2333 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

๐Ÿ“… Published: March 14, 2025, 11:59 p.m. ๐Ÿ”„ Last Modified: March 15, 2025, 12:15 p.m.

6.9

CVSS4.0

CVE-2025-2320 - 274056675 springboot-openai-chatgpt User submit improper authorization

A vulnerability has been found in 274056675 springboot-openai-chatgpt e84f6f5 and classified as critical. Affected by this vulnerability is the function submit of the file /api/blade-user/submit of the component User Handler. The manipulation leads to improper authorization. The attack can be launcโ€ฆ

๐Ÿ“… Published: March 14, 2025, 10 p.m. ๐Ÿ”„ Last Modified: March 17, 2025, 3:20 p.m.

3.5

CVSS3.1

CVE-2025-2295 - Potential iSCSI R2T PDU Vulnerability

EDK2 contains a vulnerability in BIOS where a user may cause an Integer Overflow or Wraparound by network means. A successful exploitation of this vulnerability may lead to denial of service.

๐Ÿ“… Published: March 14, 2025, 9:35 p.m. ๐Ÿ”„ Last Modified: March 14, 2025, 10:15 p.m.
Total resulsts: 285588
Page 21 of 28,559
ยซ previous page ยป next page
Filters