5.1

CVSS4.0

CVE-2025-8555 - atjiu pybbs search cross site scripting

A vulnerability, which was classified as problematic, was found in atjiu pybbs up to 6.0.0. Affected is an unknown function of the file /search. The manipulation of the argument keyword leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to th…

📅 Published: Aug. 5, 2025, 9:32 a.m. 🔄 Last Modified: Sept. 2, 2025, 7:24 p.m.

4.8

CVSS4.0

CVE-2025-8554 - atjiu pybbs list cross site scripting

A vulnerability, which was classified as problematic, has been found in atjiu pybbs up to 6.0.0. This issue affects some unknown processing of the file /admin/user/list. The manipulation of the argument Username leads to cross site scripting. The attack may be initiated remotely. The exploit has be…

📅 Published: Aug. 5, 2025, 9:02 a.m. 🔄 Last Modified: Sept. 2, 2025, 7:24 p.m.

4.8

CVSS4.0

CVE-2025-8553 - atjiu pybbs list cross site scripting

A vulnerability classified as problematic was found in atjiu pybbs up to 6.0.0. This vulnerability affects unknown code of the file /admin/sensitive_word/list. The manipulation of the argument word leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed t…

📅 Published: Aug. 5, 2025, 8:32 a.m. 🔄 Last Modified: Sept. 4, 2025, 3:38 p.m.

5.5

CVSS3.1

CVE-2025-2810 - Draeger: ICMHelper is vulnerable to use of Hard-coded Cryptographic Key

A low privileged local attacker can abuse the affected service by using a hardcoded cryptographic key.

📅 Published: Aug. 5, 2025, 8:06 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2025-41698 - Draeger: ICMHelper is vulnerable to a privilege escalation due too missing authorization

A low privileged local attacker can interact with the affected service although user-interaction should not be allowed.

📅 Published: Aug. 5, 2025, 8:06 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-8552 - atjiu pybbs list cross site scripting

A vulnerability classified as problematic has been found in atjiu pybbs up to 6.0.0. This affects an unknown part of the file /admin/tag/list. The manipulation of the argument Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the p…

📅 Published: Aug. 5, 2025, 8:02 a.m. 🔄 Last Modified: Sept. 4, 2025, 3:37 p.m.

5.1

CVSS4.0

CVE-2025-8551 - atjiu pybbs list cross site scripting

A vulnerability was found in atjiu pybbs up to 6.0.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/comment/list. The manipulation of the argument Username leads to cross site scripting. The attack may be launched remotely. The exploit has…

📅 Published: Aug. 5, 2025, 7:32 a.m. 🔄 Last Modified: Sept. 4, 2025, 3:37 p.m.

6.4

CVSS3.1

CVE-2025-8294 - Download Counter <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via name Paramet…

The Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘name’ parameter in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and…

📅 Published: Aug. 5, 2025, 7:24 a.m. 🔄 Last Modified: April 21, 2026, 3:45 a.m.

6.4

CVSS3.1

CVE-2025-8295 - Employee Directory <= 4.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via noaccess…

The Employee Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ parameter in all versions up to, and including, 4.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-leve…

📅 Published: Aug. 5, 2025, 7:24 a.m. 🔄 Last Modified: April 21, 2026, 3:45 a.m.

7.5

CVSS3.1

CVE-2025-5061 - WP Import Export Lite <= 3.9.29 - Authenticated (Subscriber+) Arbitrary File Upload

The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_parse_upload_data' function in all versions up to, and including, 3.9.29. This makes it possible for authenticated attackers, with Subscriber-level access and abov…

📅 Published: Aug. 5, 2025, 7:24 a.m. 🔄 Last Modified: April 21, 2026, 7:30 p.m.
Total resulsts: 347974
Page 4288 of 34,798
« previous page » next page
Filters