6.5

CVSS3.1

CVE-2024-30147 - HCL Leap is affected by a cross-site scripting (XSS) vulnerability

Multiple vectors in HCL Leap allow client-side script injection in the authoring environment and deployed applications.

πŸ“… Published: April 24, 2025, 4:21 p.m. πŸ”„ Last Modified: Nov. 17, 2025, 9:48 p.m.

4.1

CVSS3.1

CVE-2024-30148 - HCL Leap is affected by improper access control

Improper access control of endpoint in HCL Leap allows certain admin users to import applications from the server's filesystem.

πŸ“… Published: April 24, 2025, 4:10 p.m. πŸ”„ Last Modified: Nov. 17, 2025, 9:38 p.m.

0.0

CVE-2025-46498 - WordPress Zalo Official Live Chat plugin <= 1.0.0 - Cross Site Request Forgery (CSRF) Vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in nghialuu Zalo Official Live Chat zalo-official-live-chat allows Cross Site Request Forgery.This issue affects Zalo Official Live Chat: from n/a through <= 1.0.0.

πŸ“… Published: April 24, 2025, 4:09 p.m. πŸ”„ Last Modified: April 1, 2026, 5:23 p.m.

0.0

CVE-2025-46473 - WordPress Social Counter plugin <= 2.0.5 - PHP Object Injection Vulnerability

Deserialization of Untrusted Data vulnerability in Prisna Social Counter social-counter allows Object Injection.This issue affects Social Counter: from n/a through <= 2.0.5.

πŸ“… Published: April 24, 2025, 4:09 p.m. πŸ”„ Last Modified: April 1, 2026, 5:23 p.m.

0.0

CVE-2025-46523 - WordPress COVID-19 (Coronavirus) Update Your Customers plugin <= 1.5.1 - Cross Site Scripting (XSS)…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in devignstudiosltd COVID-19 (Coronavirus) Update Your Customers covid-19-alert allows Stored XSS.This issue affects COVID-19 (Coronavirus) Update Your Customers: from n/a through <= 1.5.1.

πŸ“… Published: April 24, 2025, 4:09 p.m. πŸ”„ Last Modified: April 1, 2026, 5:23 p.m.

0.0

CVE-2025-46507 - WordPress Unsafe Mimetypes plugin <= 0.1.4 - Cross Site Request Forgery (CSRF) to Stored XSS vulner…

Cross-Site Request Forgery (CSRF) vulnerability in ldrumm Unsafe Mimetypes unsafe-mimetypes allows Stored XSS.This issue affects Unsafe Mimetypes: from n/a through <= 0.1.4.

πŸ“… Published: April 24, 2025, 4:09 p.m. πŸ”„ Last Modified: April 1, 2026, 5:23 p.m.

0.0

CVE-2025-46481 - WordPress Flickr Shortcode Importer plugin <= 2.2.3 - PHP Object Injection Vulnerability

Deserialization of Untrusted Data vulnerability in Michael Cannon Flickr Shortcode Importer flickr-shortcode-importer allows Object Injection.This issue affects Flickr Shortcode Importer: from n/a through <= 2.2.3.

πŸ“… Published: April 24, 2025, 4:09 p.m. πŸ”„ Last Modified: April 1, 2026, 5:23 p.m.

0.0

CVE-2025-46447 - WordPress Fable Extra plugin <= 1.0.6 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFable Fable Extra fable-extra allows DOM-Based XSS.This issue affects Fable Extra: from n/a through <= 1.0.6.

πŸ“… Published: April 24, 2025, 4:09 p.m. πŸ”„ Last Modified: April 1, 2026, 5:23 p.m.

0.0

CVE-2025-46531 - WordPress WP AVCL Automation Helper (formerly WPFlyLeads) plugin <= 3.4 - Server Side Request Forge…

Server-Side Request Forgery (SSRF) vulnerability in Ankur Vishwakarma WP AVCL Automation Helper (formerly WPFlyLeads) woozap allows Server Side Request Forgery.This issue affects WP AVCL Automation Helper (formerly WPFlyLeads): from n/a through <= 3.4.

πŸ“… Published: April 24, 2025, 4:09 p.m. πŸ”„ Last Modified: April 1, 2026, 5:23 p.m.

0.0

CVE-2025-46519 - WordPress Media Library Downloader plugin <= 1.3.1 - Broken Access Control Vulnerability

Missing Authorization vulnerability in M.Code Media Library Downloader media-library-downloader allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Media Library Downloader: from n/a through <= 1.3.1.

πŸ“… Published: April 24, 2025, 4:09 p.m. πŸ”„ Last Modified: April 1, 2026, 5:23 p.m.
Total resulsts: 344062
Page 5158 of 34,407
Β« previous page Β» next page
Filters