2.4

CVSS3.1

CVE-2025-52687 - JavaScript Injection Vulnerability in the OmniAccess Stellar Web Management Interface

Successful exploitation of the vulnerability could allow an attacker with administrator credentials for the access point to inject malicious JavaScript into the payload of web traffics, potentially leading to session hijacking and denial-of-service (DoS).

📅 Published: July 16, 2025, 6:15 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.4

CVSS3.1

CVE-2025-2799 - WP Event Manager <= 3.1.49 - Authenticated (Administrator+) Stored Cross-Site Scripting

The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tag-name’ parameter in all versions up to, and including, 3.1.49 due to insufficient input sanitization and output escaping. This makes it …

📅 Published: July 16, 2025, 5:23 a.m. 🔄 Last Modified: April 20, 2026, 10:30 p.m.

7.2

CVSS3.1

CVE-2025-2800 - WP Event Manager <= 3.1.50 - Unauthenticated Stored Cross-Site Scripting via 'organizer_name'

The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘organizer_name' parameter in all versions up to, and including, 3.1.50 due to insufficient input sanitization and output escaping. This mak…

📅 Published: July 16, 2025, 5:23 a.m. 🔄 Last Modified: April 21, 2026, 7:45 p.m.

6.8

CVSS4.0

CVE-2025-53842 -

Use of hard-coded credentials issue exists in ZWX-2000CSW2-HN prior to 0.3.19 and ZWX-2000CS2-HN firmware all versions. If this vulnerability is exploited, an attacker may tamper with the settings of the device by obtaining the credentials. This vulnerability is caused by an insufficient fix for CV…

📅 Published: July 16, 2025, 4:30 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-6977 - ProfileGrid – User Profiles, Groups and Communities <= 5.9.5.4 - Reflected Cross-Site Scripting via…

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘pm_get_messenger_notification’ function in all versions up to, and including, 5.9.5.4 due to insufficient input sanitization and output escaping. This makes it possi…

📅 Published: July 16, 2025, 4:24 a.m. 🔄 Last Modified: April 20, 2026, 8:30 p.m.

5.4

CVSS3.1

CVE-2024-42912 -

A cross-site scripting (XSS) vulnerability in META-INF Kft. Email This Issue (Data Center) before 9.13.0-GA allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the recipient field of an e-mail message.

📅 Published: July 16, 2025, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-32874 -

An issue was discovered in Kaseya Rapid Fire Tools Network Detective through 2.0.16.0. A vulnerability exists in the EncryptionUtil class because symmetric encryption is implemented in a deterministic and non-randomized fashion. The method Encrypt(byte[] clearData) derives both the encryption key a…

📅 Published: July 16, 2025, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.2

CVSS3.1

CVE-2025-32353 -

Kaseya Rapid Fire Tools Network Detective 2.0.16.0 has Unencrypted Credentials (for privileged access) stored in the collector.txt configuration file.

📅 Published: July 16, 2025, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.1

CVSS3.1

CVE-2025-53906 - Vim has path traversal issue with zip.vim and special crafted zip archives

Vim is an open source, command line text editor. Prior to version 9.1.1551, a path traversal issue in Vim’s zip.vim plugin can allow overwriting of arbitrary files when opening specially crafted zip archives. Impact is low because this exploit requires direct user interaction. However, successfully…

📅 Published: July 15, 2025, 8:52 p.m. 🔄 Last Modified: April 1, 2026, 7:16 p.m.

4.1

CVSS3.1

CVE-2025-53905 - Vim has path traversial issue with tar.vim and special crafted tar files

Vim is an open source, command line text editor. Prior to version 9.1.1552, a path traversal issue in Vim’s tar.vim plugin can allow overwriting of arbitrary files when opening specially crafted tar archives. Impact is low because this exploit requires direct user interaction. However, successfully…

📅 Published: July 15, 2025, 8:48 p.m. 🔄 Last Modified: Nov. 4, 2025, 10:16 p.m.
Total resulsts: 347731
Page 4485 of 34,774
« previous page » next page
Filters