6.5

CVSS3.1

CVE-2025-53984 - WordPress JetTabs plugin <= 2.2.9 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetTabs jet-tabs allows Stored XSS.This issue affects JetTabs: from n/a through <= 2.2.9.

πŸ“… Published: July 16, 2025, 10:36 a.m. πŸ”„ Last Modified: April 23, 2026, 3:32 p.m.

6.5

CVSS3.1

CVE-2025-53982 - WordPress JetElements For Elementor plugin <= 2.7.7 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElements For Elementor jet-elements allows Stored XSS.This issue affects JetElements For Elementor: from n/a through <= 2.7.7.

πŸ“… Published: July 16, 2025, 10:36 a.m. πŸ”„ Last Modified: April 23, 2026, 3:32 p.m.

6.3

CVSS4.0

CVE-2024-9342 -

In Eclipse GlassFish version 7.0.16 or earlier it is possible to perform Login Brute Force attacks as there is no limitation in the number of failed login attempts.

πŸ“… Published: July 16, 2025, 10:14 a.m. πŸ”„ Last Modified: July 16, 2025, 7:55 p.m.

7.1

CVSS4.0

CVE-2025-7699 - An improper access control vulnerability was found in the EZ Sync Manager of ADM

An improper access control vulnerability was found in the EZ Sync Manager of ADM, which allows authenticated users to copy arbitrary files from the server file system into their own EZSync folder. The vulnerability is due to a lack of authorization checks on the file parameter of the HTTP request.…

πŸ“… Published: July 16, 2025, 9:41 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-22227 - CVE-2025-22227: Authentication Leak On Redirect With Reactor Netty HTTP Client

In some specific scenarios with chained redirects, Reactor Netty HTTP client leaks credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects.

πŸ“… Published: July 16, 2025, 9:31 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.3

CVSS4.0

CVE-2025-40985 - SQL Injection in SCATI Vision Web

SQL injection vulnerability in SCATI Vision Web of SCATI Labs from version 4.8 to 7.2. This vulnerability allows an attacker to exfiltrate some data from the database via the β€˜login’ parameter in the endpoint β€˜/scatevision_web/index.php/loginForm’.

πŸ“… Published: July 16, 2025, 9:27 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-40724 - Stored Cross-Site Scripting (XSS) in Pharmacy POS PHP Script

Stored Cross-Site Scripting (XSS) vulnerability in Pharmacy POS PHP Script. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the u_medicine_name parameter in /edit_medicine.php. This vulnerability can be exploited t…

πŸ“… Published: July 16, 2025, 9:23 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2025-7035 - Media Library Assistant <= 3.26 - Authenticated (Contributor+) Stored Cross-Site Scripting via mla_…

The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mla_tag_cloud and mla_term_list shortcodes in all versions up to, and including, 3.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it …

πŸ“… Published: July 16, 2025, 9:22 a.m. πŸ”„ Last Modified: April 20, 2026, 8:30 p.m.

7.5

CVSS3.1

CVE-2025-6993 - Ultimate WP Mail 1.0.17 - 1.3.6 - Missing Authorization to Authenticated (Contributor+) Privilege E…

The Ultimate WP Mail plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the get_email_log_details() AJAX handler in versions 1.0.17 to 1.3.6. The handler reads the client-supplied post_id and retrieves the corresponding email log post content (including …

πŸ“… Published: July 16, 2025, 9:22 a.m. πŸ”„ Last Modified: Aug. 2, 2025, 1:29 a.m.

6.4

CVSS3.1

CVE-2025-5284 - Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Anima…

The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom JS extension in all versions up to, and including, 2.0.8.2 due to insufficient capability restriction, and in…

πŸ“… Published: July 16, 2025, 9:22 a.m. πŸ”„ Last Modified: April 22, 2026, 5:15 p.m.
Total resulsts: 349182
Page 4628 of 34,919
Β« previous page Β» next page
Filters