0.0

CVSS3.1

CVE-2023-6800 - keycloak-core: Session Fixation

No description is available for this CVE.

๐Ÿ“… Published: April 1, 2025, 5:48 p.m. ๐Ÿ”„ Last Modified: April 1, 2025, 5:48 p.m.

5.5

CVSS3.1

CVE-2025-25041 - Arbitrary File Overwrite in HPE Aruba Networking Virtual Intranet Access (VIA) Microsoft Windows Clโ€ฆ

A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could allow malicious users to overwrite arbitrary files as NT AUTHORITY\SYSTEM (root). A successful exploit could allow the creation of a Denial-of-Service (DoS) condition affecting the Microsoft Windows Operating Sysโ€ฆ

๐Ÿ“… Published: April 1, 2025, 4:45 p.m. ๐Ÿ”„ Last Modified: April 3, 2025, 6:15 p.m.

8.1

CVSS3.1

CVE-2025-31132 - Raven allows Remote Code Execution due to improper validation

Raven is an open-source messaging platform. A vulnerability allowed any logged in user to execute code via an API endpoint. This vulnerability is fixed in 2.1.10.

๐Ÿ“… Published: April 1, 2025, 3:06 p.m. ๐Ÿ”„ Last Modified: April 1, 2025, 8:26 p.m.

8.6

CVSS3.1

CVE-2025-31131 - Path Traversal allowing arbitrary read of files in Yeswiki

YesWiki is a wiki system written in PHP. The squelette parameter is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server. This vulnerability is fixed in 4.5.2.

๐Ÿ“… Published: April 1, 2025, 2:56 p.m. ๐Ÿ”„ Last Modified: May 9, 2025, 2:04 p.m.

7

CVSS4.0

CVE-2025-31121 - OpenEMR allows XSS in Patient Image feature

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 7.0.3.1, the Patient Image feature in OpenEMR is vulnerable to cross-site scripting attacks via the EXIF title in an image. This vulnerability is fixed in 7.0.3.1.

๐Ÿ“… Published: April 1, 2025, 2:53 p.m. ๐Ÿ”„ Last Modified: May 7, 2025, 3:35 p.m.

0.0

CVE-2025-31910 - WordPress BookingPress plugin <= 1.1.28 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in reputeinfosystems BookingPress bookingpress-appointment-booking allows SQL Injection.This issue affects BookingPress: from n/a through <= 1.1.28.

๐Ÿ“… Published: April 1, 2025, 2:52 p.m. ๐Ÿ”„ Last Modified: April 1, 2026, 5:21 p.m.

0.0

CVE-2025-31908 - WordPress JSON Structuring Markup plugin <= 0.1 - CSRF to Stored XSS vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Sami Ahmed Siddiqui JSON Structuring Markup json-structuring-markup allows Stored XSS.This issue affects JSON Structuring Markup: from n/a through <= 0.1.

๐Ÿ“… Published: April 1, 2025, 2:52 p.m. ๐Ÿ”„ Last Modified: April 1, 2026, 5:21 p.m.

0.0

CVE-2025-31906 - WordPress WP Profitshare Plugin <= 1.4.9 - CSRF to Stored XSS vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in ProfitShare.ro WP Profitshare wp-profitshare allows Stored XSS.This issue affects WP Profitshare: from n/a through <= 1.4.9.

๐Ÿ“… Published: April 1, 2025, 2:52 p.m. ๐Ÿ”„ Last Modified: April 1, 2026, 5:21 p.m.

0.0

CVE-2025-31904 - WordPress Ebook Downloader plugin <= 1.0 - CSRF to Stored XSS vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Infoway LLC Ebook Downloader ebook-downloader allows Cross Site Request Forgery.This issue affects Ebook Downloader: from n/a through <= 1.0.

๐Ÿ“… Published: April 1, 2025, 2:52 p.m. ๐Ÿ”„ Last Modified: April 1, 2026, 5:21 p.m.

0.0

CVE-2025-31897 - WordPress Arrow Custom Feed for Twitter plugin <= 1.5.3 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arrow Plugins Arrow Custom Feed for Twitter arrow-twitter-feed allows Stored XSS.This issue affects Arrow Custom Feed for Twitter: from n/a through <= 1.5.3.

๐Ÿ“… Published: April 1, 2025, 2:52 p.m. ๐Ÿ”„ Last Modified: April 1, 2026, 5:21 p.m.
Total resulsts: 344064
Page 5551 of 34,407
ยซ previous page ยป next page
Filters