6.4

CVSS3.1

CVE-2025-9075 - ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patte…

The ZoloBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Gutenberg blocks in versions up to, and including, 2.3.10. This is due to insufficient input sanitization and output escaping on user-supplied attributes within multiple block components including Google M…

πŸ“… Published: Oct. 1, 2025, 3:25 a.m. πŸ”„ Last Modified: Oct. 1, 2025, 1:19 p.m.

4

CVSS3.1

CVE-2025-10735 - Block For Mailchimp – Easy Mailchimp Form Integration <= 1.1.12 - Unauthenticated Blind Server-Side…

The Block For Mailchimp – Easy Mailchimp Form Integration plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 1.1.12 via the mcbSubmit_Form_Data(). This makes it possible for unauthenticated attackers to make web requests to arbitrary locati…

πŸ“… Published: Oct. 1, 2025, 3:25 a.m. πŸ”„ Last Modified: Oct. 1, 2025, 4:15 a.m.

5.3

CVSS3.1

CVE-2025-10744 - File Manager, Code editor, backup by Managefy <= 1.6.1 - Unauthenticated Information Exposure

The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.1 through publicly exposed log files. This makes it possible for unauthenticated attackers to view information like full paths and ful…

πŸ“… Published: Oct. 1, 2025, 3:25 a.m. πŸ”„ Last Modified: Oct. 1, 2025, 4:16 a.m.

0.0

CVE-2025-59684 -

DigiSign DigiSigner ONE 1.0.4.60 allows DLL Hijacking.

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 2:53 p.m.

0.0

CVE-2025-56515 -

File upload vulnerability in Fiora chat application 1.0.0 through user avatar upload functionality. The application fails to validate SVG file content, allowing malicious SVG files with embedded foreignObject elements containing iframe tags and JavaScript event handlers (onmouseover) to be uploaded…

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 3:30 p.m.

0.0

CVE-2025-57393 -

A stored cross-site scripting (XSS) in Kissflow Work Platform Kissflow Application Versions 7337 Account v2.0 to v4.2vallows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 5:54 p.m.

7.1

CVSS3.1

CVE-2025-59681 -

An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. QuerySet.annotate(), QuerySet.alias(), QuerySet.aggregate(), and QuerySet.extra() are subject to SQL injection in column aliases, when using a suitably crafted dictionary, with dictionary expansion, as the…

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 6:47 p.m.

0.0

CVE-2025-57444 -

An authenticated cross-site scripting (XSS) vulnerability in the Administrative interface of Radware AlteonOS Web UI Management v33.0.4.50 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Description parameter.

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 7:28 p.m.

0.0

CVE-2024-57494 -

Cross Site Scripting vulnerability in Neto E-Commerce CMS v.6.313.0 through v.6.3115 allows a remote attacker to escalate privileges via the kw parameter.

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 6:05 p.m.

0.0

CVE-2025-46205 -

A heap-use-after free in the PdfTokenizer::ReadDictionary function of podofo v0.10.0 to v0.10.5 allows attackers to cause a Denial of Service (DoS) via supplying a crafted PDF file.

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 6:16 p.m.
Total resulsts: 312451
Page 27 of 31,246
Β« previous page Β» next page
Filters