7.1

CVSS3.1

CVE-2025-22263 - WordPress Global Gallery plugin <= 8.8.0 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Global Gallery global-gallery allows Reflected XSS.This issue affects Global Gallery: from n/a through <= 8.8.0.

๐Ÿ“… Published: April 15, 2025, 9:53 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 1:58 p.m.

6.9

CVSS4.0

CVE-2025-31147 - Growatt Cloud portal Authorization Bypass Through User-Controlled Key

Unauthenticated attackers can query information about total energy consumed by EV chargers of arbitrary users.

๐Ÿ“… Published: April 15, 2025, 9:50 p.m. ๐Ÿ”„ Last Modified: Nov. 14, 2025, 6:12 p.m.

6.9

CVSS4.0

CVE-2025-31360 - Growatt Cloud portal Authorization Bypass Through User-Controlled Key

Unauthenticated attackers can trigger device actions associated with specific "scenes" of arbitrary users.

๐Ÿ“… Published: April 15, 2025, 9:48 p.m. ๐Ÿ”„ Last Modified: Nov. 12, 2025, 4:11 p.m.

6.9

CVSS4.0

CVE-2025-30512 - Growatt Cloud portal External Control of System or Configuration Setting

Unauthenticated attackers can send configuration settings to device and possible perform physical actions remotely (e.g., on/off).

๐Ÿ“… Published: April 15, 2025, 9:45 p.m. ๐Ÿ”„ Last Modified: Nov. 14, 2025, 6:12 p.m.

6.9

CVSS4.0

CVE-2025-27927 - Growatt Cloud portal Authorization Bypass Through User-Controlled Key

An unauthenticated attackers can obtain a list of smart devices by knowing a valid username through an unprotected API.

๐Ÿ“… Published: April 15, 2025, 9:43 p.m. ๐Ÿ”„ Last Modified: Nov. 14, 2025, 6:12 p.m.

9.3

CVSS4.0

CVE-2025-24297 - Growatt Cloud portal Cross-site Scripting

Due to lack of server-side input validation, attackers can inject malicious JavaScript code into users personal spaces of the web portal.

๐Ÿ“… Published: April 15, 2025, 9:39 p.m. ๐Ÿ”„ Last Modified: Nov. 14, 2025, 6:14 p.m.

9.3

CVSS4.0

CVE-2025-30510 - Growatt Cloud portal Insufficient Type Distinction

An attacker can upload an arbitrary file instead of a plant image.

๐Ÿ“… Published: April 15, 2025, 9:36 p.m. ๐Ÿ”„ Last Modified: Nov. 14, 2025, 6:12 p.m.

6.9

CVSS4.0

CVE-2025-24850 - Growatt Cloud portal Authorization Bypass Through User-Controlled Key

An attacker can export other users' plant information.

๐Ÿ“… Published: April 15, 2025, 9:33 p.m. ๐Ÿ”„ Last Modified: Nov. 14, 2025, 6:14 p.m.

0.0

CVE-2025-36542 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

๐Ÿ“… Published: April 15, 2025, 9:28 p.m. ๐Ÿ”„ Last Modified: Feb. 13, 2026, 6:11 p.m.

0.0

CVE-2025-36534 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

๐Ÿ“… Published: April 15, 2025, 9:28 p.m. ๐Ÿ”„ Last Modified: Feb. 13, 2026, 6:11 p.m.
Total resulsts: 346536
Page 5538 of 34,654
ยซ previous page ยป next page
Filters