6.4

CVSS3.1

CVE-2025-5116 - WP Plugin Info Card <= 5.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via containโ€ฆ

The WP Plugin Info Card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the โ€˜containeridโ€™ parameter in all versions up to, and including, 5.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-leveโ€ฆ

๐Ÿ“… Published: June 3, 2025, 8:21 a.m. ๐Ÿ”„ Last Modified: April 20, 2026, 10:45 p.m.

6.4

CVSS3.1

CVE-2025-4420 - Vayu Blocks <= 1.3.1 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripโ€ฆ

The Vayu Blocks โ€“ Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the โ€˜containerWidthโ€™ parameter in all versions up to, and including, 1.3.1 due to a missing capability check on the vayu_blocks_option_panel_callback() function and iโ€ฆ

๐Ÿ“… Published: June 3, 2025, 8:21 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 1:30 a.m.

6.4

CVSS3.1

CVE-2025-1725 - Bit File Manager โ€“ 100% Free & Open Source File Manager and Code Editor for WordPress <= 6.7 - Authโ€ฆ

The Bit File Manager โ€“ 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.7 due to insufficient input sanitization and output escaping. This makes it possibโ€ฆ

๐Ÿ“… Published: June 3, 2025, 8:21 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 8:30 p.m.

7

CVSS4.0

CVE-2025-46355 -

Incorrect default permissions issue in PC Time Tracer prior to 5.2. If exploited, arbitrary code may be executed with SYSTEM privilege on Windows system where the product is running by a local authenticated attacker.

๐Ÿ“… Published: June 3, 2025, 8:09 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-41428 -

Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in TimeWorks 10.0 to 10.3. If exploited, arbitrary JSON files on the server may be viewed by a remote unauthenticated attacker.

๐Ÿ“… Published: June 3, 2025, 8:09 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2025-49208 -

Not used

๐Ÿ“… Published: June 3, 2025, 7:46 a.m. ๐Ÿ”„ Last Modified: June 4, 2025, 3:15 a.m.

0.0

CVE-2025-49209 -

Not used

๐Ÿ“… Published: June 3, 2025, 7:46 a.m. ๐Ÿ”„ Last Modified: June 4, 2025, 3:15 a.m.

0.0

CVE-2025-49210 -

Not used

๐Ÿ“… Published: June 3, 2025, 7:46 a.m. ๐Ÿ”„ Last Modified: June 4, 2025, 3:15 a.m.

0.0

CVE-2025-49202 -

Not used

๐Ÿ“… Published: June 3, 2025, 7:46 a.m. ๐Ÿ”„ Last Modified: June 4, 2025, 3:15 a.m.

0.0

CVE-2025-49203 -

Not used

๐Ÿ“… Published: June 3, 2025, 7:46 a.m. ๐Ÿ”„ Last Modified: June 4, 2025, 3:15 a.m.
Total resulsts: 349182
Page 5191 of 34,919
ยซ previous page ยป next page
Filters