6.9

CVSS4.0

CVE-2025-34469 - Cowrie < 2.9.0 Unrestricted wget/curl Emulation Enables SSRF-Based DDoS Amplification

Cowrie versions prior to 2.9.0 contain a server-side request forgery (SSRF) vulnerability in the emulated shell implementation of wget and curl. In the default emulated shell configuration, these command emulations perform real outbound HTTP requests to attacker-supplied destinations. Because no ou…

πŸ“… Published: Dec. 31, 2025, 9:36 p.m. πŸ”„ Last Modified: March 5, 2026, 12:04 p.m.

8.6

CVSS4.0

CVE-2025-68700 - RAGFlow Remote Code Execution Vulnerability

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.23.0, a low-privileged authenticated user (normal login account) can execute arbitrary system commands on the server host process via the frontend Canvas CodeExec component, completely bypassing sandbox is…

πŸ“… Published: Dec. 31, 2025, 9:17 p.m. πŸ”„ Last Modified: Jan. 6, 2026, 6:02 p.m.

5.1

CVSS4.0

CVE-2023-7331 - PKrystian Full-Stack-Bank User sql injection

A vulnerability was detected in PKrystian Full-Stack-Bank up to bf73a0179e3ff07c0d7dc35297cea0be0e5b1317. This vulnerability affects unknown code of the component User Handler. Performing manipulation results in sql injection. It is possible to initiate the attack remotely. This product is using a …

πŸ“… Published: Dec. 31, 2025, 9:02 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2015-10145 - Gargoyle 1.5.x Authenticated OS Command Execution via run_commands.sh

Gargoyle router management utility versions 1.5.x contain an authenticated OS command execution vulnerability in /utility/run_commands.sh. The application fails to properly restrict or validate input supplied via the 'commands' parameter, allowing an authenticated attacker to execute arbitrary shel…

πŸ“… Published: Dec. 31, 2025, 8:48 p.m. πŸ”„ Last Modified: March 23, 2026, 3:43 p.m.

7.1

CVSS3.1

CVE-2025-53235 - WordPress Easy Social plugin <= 1.3 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osuthorpe Easy Social easy-social-media allows Reflected XSS.This issue affects Easy Social: from n/a through <= 1.3.

πŸ“… Published: Dec. 31, 2025, 8:11 p.m. πŸ”„ Last Modified: April 23, 2026, 3:32 p.m.

7.1

CVSS3.1

CVE-2025-52739 - WordPress Sala theme <= 1.1.3 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxper Sala allows Reflected XSS.This issue affects Sala: from n/a through 1.1.3.

πŸ“… Published: Dec. 31, 2025, 8:10 p.m. πŸ”„ Last Modified: April 28, 2026, 4:13 p.m.

7.1

CVSS3.1

CVE-2025-50053 - WordPress Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App Plugin <= 0.8…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nebelhorn Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App yournewsapp allows Reflected XSS.This issue affects Blappsta Mobile App Plugin – Your native, mobile iPhone App…

πŸ“… Published: Dec. 31, 2025, 8:09 p.m. πŸ”„ Last Modified: April 28, 2026, 4:13 p.m.

7.1

CVSS3.1

CVE-2025-47566 - WordPress ZoomSounds plugin <= 6.91 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZoomSounds allows Reflected XSS.This issue affects ZoomSounds: from n/a through 6.91.

πŸ“… Published: Dec. 31, 2025, 8:07 p.m. πŸ”„ Last Modified: April 28, 2026, 4:12 p.m.

7.1

CVSS3.1

CVE-2025-31054 - WordPress Bloggie theme <= 2.0.8 - Cross Site Scripting (XSS) Vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Themefy Bloggie allows Reflected XSS.This issue affects Bloggie: from n/a through 2.0.8.

πŸ“… Published: Dec. 31, 2025, 8:05 p.m. πŸ”„ Last Modified: April 28, 2026, 4:12 p.m.

8.5

CVSS3.1

CVE-2025-30628 - WordPress Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer) plugin <= 1.…

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer) allows SQL Injection.This issue affects Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Compo…

πŸ“… Published: Dec. 31, 2025, 8:03 p.m. πŸ”„ Last Modified: April 28, 2026, 4:11 p.m.
Total resulsts: 347632
Page 2161 of 34,764
Β« previous page Β» next page
Filters