8.7

CVSS3.1

CVE-2025-9642 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could allow an attacker to inject malicious content that may lead to account takeover.

πŸ“… Published: Sept. 26, 2025, 9:04 a.m. πŸ”„ Last Modified: Sept. 29, 2025, 1:10 p.m.

7.7

CVSS3.1

CVE-2025-9958 - Insertion of Sensitive Information Into Sent Data in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that could have allowed Guest users to access sensitive information stored in virtual registry configurations.

πŸ“… Published: Sept. 26, 2025, 9:04 a.m. πŸ”„ Last Modified: Nov. 6, 2025, 6:15 p.m.

7.5

CVSS3.1

CVE-2025-10858 - Allocation of Resources Without Limits or Throttling in GitLab

An issue was discovered in GitLab CE/EE affecting all versions before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that allows unauthenticated users to cause a Denial of Service (DoS) condition while uploading specifically crafted large JSON files.

πŸ“… Published: Sept. 26, 2025, 9:04 a.m. πŸ”„ Last Modified: Sept. 29, 2025, 1:09 p.m.

3.5

CVSS3.1

CVE-2025-10867 - Allocation of Resources Without Limits or Throttling in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could have allowed an authenticated user to create a denial-of-service condition by exploiting an unprotected GraphQL API through repeated requests.

πŸ“… Published: Sept. 26, 2025, 9:04 a.m. πŸ”„ Last Modified: Sept. 29, 2025, 1:09 p.m.

3.8

CVSS3.1

CVE-2025-10871 - Missing Authorization in GitLab

An issue has been discovered in GitLab EE affecting all versions from 16.6 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1. Project Maintainers can exploit a vulnerability where they can assign custom roles to users with permissions exceeding their own, effectively granting themselves ele…

πŸ“… Published: Sept. 26, 2025, 9:04 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:47 p.m.

10

CVSS3.1

CVE-2025-60219 - WordPress WooCommerce Designer Pro Plugin <= 1.9.24 - Arbitrary File Upload Vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in HaruTheme WooCommerce Designer Pro wc-designer-pro allows Upload a Web Shell to a Web Server.This issue affects WooCommerce Designer Pro: from n/a through <= 1.9.24.

πŸ“… Published: Sept. 26, 2025, 8:32 a.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

5.9

CVSS3.1

CVE-2025-60186 - WordPress Google+ Comments Plugin <= 1.0 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alex Moss Google+ Comments google-plus-comments allows Stored XSS.This issue affects Google+ Comments: from n/a through <= 1.0.

πŸ“… Published: Sept. 26, 2025, 8:32 a.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

5.9

CVSS3.1

CVE-2025-60185 - WordPress kontur Admin Style Plugin <= 1.0.4 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kontur.us kontur Admin Style kontur-admin-style allows Stored XSS.This issue affects kontur Admin Style: from n/a through <= 1.0.4.

πŸ“… Published: Sept. 26, 2025, 8:32 a.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

5.9

CVSS3.1

CVE-2025-60184 - WordPress SEO Search Permalink Plugin <= 1.0.3 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Terry L. SEO Search Permalink seo-search-permalink allows Stored XSS.This issue affects SEO Search Permalink: from n/a through <= 1.0.3.

πŸ“… Published: Sept. 26, 2025, 8:32 a.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

5.4

CVSS3.1

CVE-2025-60181 - WordPress Silencesoft RSS Reader Plugin <= 0.6 - Server Side Request Forgery (SSRF) Vulnerability

Server-Side Request Forgery (SSRF) vulnerability in silence Silencesoft RSS Reader external-rss-reader allows Server Side Request Forgery.This issue affects Silencesoft RSS Reader: from n/a through <= 0.6.

πŸ“… Published: Sept. 26, 2025, 8:32 a.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.
Total resulsts: 349182
Page 3664 of 34,919
Β« previous page Β» next page
Filters