5.5

CVSS3.1

CVE-2025-20954 -

Use of implicit intent for sensitive communication in EnrichedCall prior to SMR May-2025 Release 1 allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability.

πŸ“… Published: May 7, 2025, 8:24 a.m. πŸ”„ Last Modified: May 13, 2025, 8:21 p.m.

5.1

CVSS3.1

CVE-2025-20953 -

Improper access control in SmartManagerCN prior to SMR May-2025 Release 1 allows local attackers to launch activities within SmartManagerCN.

πŸ“… Published: May 7, 2025, 8:24 a.m. πŸ”„ Last Modified: May 13, 2025, 8:21 p.m.

5.1

CVSS3.1

CVE-2025-20949 -

Path traversal vulnerability in Samsung Members prior to version 5.0.00.11 allows attackers to read and write arbitrary file with the privilege of Samsung Members.

πŸ“… Published: May 7, 2025, 8:24 a.m. πŸ”„ Last Modified: July 17, 2025, 12:42 a.m.

6.7

CVSS3.1

CVE-2025-20937 -

Out-of-bounds write in Keymaster trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

πŸ“… Published: May 7, 2025, 8:22 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

8.6

CVSS4.0

CVE-2025-0669 - BOINC Server Cross-Site Request Forgery

Cross-Site Request Forgery (CSRF) vulnerability in BOINC Server allows Cross Site Request Forgery.This issue affects BOINC Server: before 1.4.3.

πŸ“… Published: May 7, 2025, 7:39 a.m. πŸ”„ Last Modified: July 8, 2025, 4:48 p.m.

9.3

CVSS4.0

CVE-2025-0668 - BOINC Server Multiple SQL Injections

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BOINC Server allows Stored XSS.This issue affects BOINC Server: before 1.4.5.

πŸ“… Published: May 7, 2025, 7:39 a.m. πŸ”„ Last Modified: July 8, 2025, 4:47 p.m.

8.7

CVSS4.0

CVE-2025-0667 - BOINC Server Stored XSS Injection in pm.php

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BOINC Server allows Stored XSS.This issue affects BOINC Server: through 1.4.7.

πŸ“… Published: May 7, 2025, 7:38 a.m. πŸ”„ Last Modified: July 8, 2025, 4:48 p.m.

7

CVSS4.0

CVE-2025-0666 - BOINC Server Stored XSS Injection in host_venue_action.php

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BOINC Server allows Stored XSS.This issue affects BOINC Server: through 1.4.7.

πŸ“… Published: May 7, 2025, 7:38 a.m. πŸ”„ Last Modified: July 8, 2025, 4:44 p.m.

5.4

CVSS3.1

CVE-2024-12120 - Royal Elementor Addons and Templates <= 1.7.1017 - Authenticated (Contributor+) Stored Cross-Site S…

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown widget display_message_text parameter in all versions up to, and including, 1.7.1017 due to insufficient input sanitization and output escaping. This makes it possible for au…

πŸ“… Published: May 7, 2025, 7:21 a.m. πŸ”„ Last Modified: April 8, 2026, 4:56 p.m.

6.4

CVSS3.1

CVE-2025-4171 - WZ Followed Posts – Display what visitors are reading <= 3.1.0 - Authenticated (Contributor+) Store…

The WZ Followed Posts – Display what visitors are reading plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wfp' shortcode in all versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…

πŸ“… Published: May 7, 2025, 7:21 a.m. πŸ”„ Last Modified: April 8, 2026, 4:43 p.m.
Total resulsts: 343921
Page 4999 of 34,393
Β« previous page Β» next page
Filters