7.5

CVSS4.0

CVE-2024-48851 - Remote Code Execution

Improper Validation of Specified Type of Input vulnerability in ABB FLXEON.A remote code execution is possible due to an improper input validation. This issue affects FLXEON: through 9.3.5.

πŸ“… Published: Sept. 18, 2025, 11:17 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-10663 - PHPGurukul Online Course Registration my-profile.php sql injection

A vulnerability was found in PHPGurukul Online Course Registration 3.1. This affects an unknown function of the file /my-profile.php. Performing manipulation of the argument cgpa results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used.

πŸ“… Published: Sept. 18, 2025, 11:02 a.m. πŸ”„ Last Modified: Sept. 20, 2025, 2:36 a.m.

5.1

CVSS4.0

CVE-2025-10662 - SeaCMS admin_members.php sql injection

A vulnerability has been found in SeaCMS up to 13.3. The impacted element is an unknown function of the file /admin_members.php?ac=editsave. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used…

πŸ“… Published: Sept. 18, 2025, 10:32 a.m. πŸ”„ Last Modified: Sept. 19, 2025, 8:30 p.m.

8.1

CVSS3.1

CVE-2025-8565 - Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages <= 3.4.3 -…

The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on the wplp_gdpr_install_plugin_ajax_handler() function in all versions up to, and including, 3.4…

πŸ“… Published: Sept. 18, 2025, 9:31 a.m. πŸ”„ Last Modified: April 20, 2026, 7:45 p.m.

6.4

CVSS3.1

CVE-2025-9992 - Ghost Kit <= 3.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Ghost Kit – Page Builder Blocks, Motion Effects & Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS field in all versions up to, and including, 3.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

πŸ“… Published: Sept. 18, 2025, 9:31 a.m. πŸ”„ Last Modified: April 20, 2026, 10 p.m.

3.7

CVSS3.1

CVE-2025-30187 - Denial of service via crafted DoH exchange in PowerDNS DNSdist

In some circumstances, when DNSdist is configured to use the nghttp2 library to process incoming DNS over HTTPS queries, an attacker might be able to cause a denial of service by crafting a DoH exchange that triggers an unbounded I/O read loop, causing an unexpected consumption of CPU resources.

πŸ“… Published: Sept. 18, 2025, 9:21 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.7

CVSS3.1

CVE-2025-0547 - XSS in Mikrogrup's Bizmu

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Paraşüt Software Bizmu allows Cross-Site Scripting (XSS).This issue affects Bizmu: from 2.27.0 through 20250212.

πŸ“… Published: Sept. 18, 2025, 8:59 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.0

CVE-2025-6237 - Path Traversal and Arbitrary File Deletion in invoke-ai/invokeai

A vulnerability in invokeai version v6.0.0a1 and below allows attackers to perform path traversal and arbitrary file deletion via the GET /api/v1/images/download/{bulk_download_item_name} endpoint. By manipulating the filename arguments, attackers can read and delete any files on the server, includ…

πŸ“… Published: Sept. 18, 2025, 8:34 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-10493 - Chained Quiz <= 1.3.5 - Unauthenticated Insecure Direct Object Reference via Cookie

The Chained Quiz plugin for WordPress is vulnerable to Insecure Direct Object Reference in version 1.3.4 and below via the quiz submission and completion mechanisms due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to hijack and modify other us…

πŸ“… Published: Sept. 18, 2025, 6:49 a.m. πŸ”„ Last Modified: April 22, 2026, 10:15 p.m.

8.4

CVSS3.1

CVE-2023-49565 - Remote Code Execution

The cbis_manager Podman container is vulnerable to remote command execution via the /api/plugins endpoint. Improper sanitization of the HTTP Headers X-FILENAME, X-PAGE, and X-FIELD allows for command injection. These headers are directly utilized within the subprocess.Popen Python function without …

πŸ“… Published: Sept. 18, 2025, 6:11 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3782 of 34,919
Β« previous page Β» next page
Filters