3.5

CVSS3.1

CVE-2024-11924 - Email Subscribers < 5.7.52 - Admin+ Stored XSS

The Icegram Express formerly known as Email Subscribers WordPress plugin before 5.7.52 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for …

πŸ“… Published: April 17, 2025, 6 a.m. πŸ”„ Last Modified: April 17, 2025, 8:21 p.m.

7.2

CVSS3.1

CVE-2025-3294 - WP Editor <= 1.2.9.1 - Authenticated (Administrator+) Directory Traversal to Arbitrary File Update

The WP Editor plugin for WordPress is vulnerable to arbitrary file update due to missing file path validation in all versions up to, and including, 1.2.9.1. This makes it possible for authenticated attackers, with Administrator-level access and above, to overwrite arbitrary files on the affected si…

πŸ“… Published: April 17, 2025, 5:23 a.m. πŸ”„ Last Modified: April 17, 2025, 8:21 p.m.

4.9

CVSS3.1

CVE-2025-3295 - WP Editor <= 1.2.9.1 - Authenticated (Administrator+) Directory Traversal to Arbitrary File Read

The WP Editor plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.2.9.1. This makes it possible for authenticated attackers, with Administrator-level access and above, to read arbitrary files on the affected site's server which may reveal sensitive info…

πŸ“… Published: April 17, 2025, 5:23 a.m. πŸ”„ Last Modified: April 17, 2025, 8:21 p.m.

6.9

CVSS4.0

CVE-2025-31338 - Wisdom Master Pro - Missing Authorization

A missing authorization vulnerability in the retrieve teacher Information function of Wisdom Master Pro versions 5.0 through 5.2 allows remote attackers to obtain partial user data by accessing the API functionality.

πŸ“… Published: April 17, 2025, 2:01 a.m. πŸ”„ Last Modified: April 17, 2025, 8:21 p.m.

5.3

CVSS4.0

CVE-2025-31339 - Wisdom Master Pro - Unrestricted Upload of File with Dangerous Type

An unrestricted upload of file with dangerous type vulnerability in the course management function of Wisdom Master Pro versions 5.0 through 5.2 allows remote authenticated users to craft a malicious file.

πŸ“… Published: April 17, 2025, 2 a.m. πŸ”„ Last Modified: April 17, 2025, 8:21 p.m.

9.9

CVSS4.0

CVE-2025-31340 - Wisdom Master Pro - Improper Control of Filename for Include/Require Statement in PHP Program

A improper control of filename for include/require statement in PHP program vulnerability in the retrieve course Information function of Wisdom Master Pro versions 5.0 through 5.2 allows remote attackers to perform arbitrary system commands by running a malicious file.

πŸ“… Published: April 17, 2025, 1:59 a.m. πŸ”„ Last Modified: April 17, 2025, 8:21 p.m.

8.1

CVSS3.1

CVE-2025-1290 -

A race condition Use-After-Free vulnerability exists in the virtio_transport_space_update function within the Kernel 5.4 on ChromeOS. Concurrent allocation and freeing of the virtio_vsock_sock structure during an AF_VSOCK connect syscall can occur before a worker thread accesses it resulting in a …

πŸ“… Published: April 17, 2025, 12:13 a.m. πŸ”„ Last Modified: April 17, 2025, 8:21 p.m.

7.6

CVSS3.1

CVE-2025-29457 -

An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Import a Theme function.

πŸ“… Published: April 17, 2025, midnight πŸ”„ Last Modified: April 21, 2025, 2:23 p.m.

3.3

CVSS3.1

CVE-2021-47671 - can: etas_es58x: es58x_rx_err_msg(): fix memory leak in error path

In the Linux kernel, the following vulnerability has been resolved: can: etas_es58x: es58x_rx_err_msg(): fix memory leak in error path In es58x_rx_err_msg(), if can->do_set_mode() fails, the function directly returns without calling netif_rx(skb). This means that the skb previously allocated by a…

πŸ“… Published: April 17, 2025, midnight πŸ”„ Last Modified: April 17, 2025, 8:21 p.m.

7.8

CVSS3.1

CVE-2021-47668 - can: dev: can_restart: fix use after free bug

In the Linux kernel, the following vulnerability has been resolved: can: dev: can_restart: fix use after free bug After calling netif_rx_ni(skb), dereferencing skb is unsafe. Especially, the can_frame cf which aliases skb memory is accessed after the netif_rx_ni() in: stats->rx_bytes += cf-…

πŸ“… Published: April 17, 2025, midnight πŸ”„ Last Modified: April 17, 2025, 8:21 p.m.
Total resulsts: 291015
Page 47 of 29,102
Β« previous page Β» next page
Filters