6.1

CVSS3.1

CVE-2025-3433 - Advanced Advertising System <= 1.3.1 - Open Redirect

The Advanced Advertising System plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.3.1. This is due to insufficient validation on the redirect url supplied via the 'redir' parameter. This makes it possible for unauthenticated attackers to redirect users to p…

πŸ“… Published: April 8, 2025, 8:22 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.2

CVSS4.0

CVE-2024-41792 -

A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices contains a path traversal vulnerability. This could allow an unauthenticated attacker it to access arbitrary files on the device with root privileges.

πŸ“… Published: April 8, 2025, 8:22 a.m. πŸ”„ Last Modified: Sept. 23, 2025, 4:21 p.m.

6.4

CVSS3.1

CVE-2025-3432 - AAWEP Obfuscator <= 1.0 - Authenticated (Author+) Stored Cross-Site Scripting

The AAWP Obfuscator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data-aawp-web' parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access …

πŸ“… Published: April 8, 2025, 8:22 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2024-41791 -

A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not authenticate report creation requests. This could allow an unauthenticated remote attacker to read or clear the log files on the device, reset the device or set the…

πŸ“… Published: April 8, 2025, 8:22 a.m. πŸ”„ Last Modified: Sept. 23, 2025, 4:23 p.m.

9.4

CVSS4.0

CVE-2024-41790 -

A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not sanitize the region parameter in specific POST requests. This could allow an authenticated remote attacker to execute arbitrary code with root privileges.

πŸ“… Published: April 8, 2025, 8:22 a.m. πŸ”„ Last Modified: Sept. 23, 2025, 4:35 p.m.

9.4

CVSS4.0

CVE-2024-41789 -

A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not sanitize the language parameter in specific POST requests. This could allow an authenticated remote attacker to execute arbitrary code with root privileges.

πŸ“… Published: April 8, 2025, 8:22 a.m. πŸ”„ Last Modified: Sept. 23, 2025, 4:37 p.m.

9.4

CVSS4.0

CVE-2024-41788 -

A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not sanitize the input parameters in specific GET requests. This could allow an authenticated remote attacker to execute arbitrary code with root privileges.

πŸ“… Published: April 8, 2025, 8:22 a.m. πŸ”„ Last Modified: Sept. 23, 2025, 4:38 p.m.

5.3

CVSS3.1

CVE-2025-2882 - GreenPay(tm) by Green.Money 3.0.0 - 3.0.9 - Unauthenticated Information Exposure

The GreenPay(tm) by Green.Money plugin for WordPress is vulnerable to Sensitive Information Exposure in versions between 3.0.0 and 3.0.9 through the publicly accessible phpinfo.php script. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in th…

πŸ“… Published: April 8, 2025, 7:29 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-3431 - ZoomSounds - WordPress Wave Audio Player with Playlist <= 6.91 - Unauthenticated Arbitrary File Dow…

The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 6.91 via the 'dzsap_download' action. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server…

πŸ“… Published: April 8, 2025, 7:29 a.m. πŸ”„ Last Modified: April 8, 2026, 5:13 p.m.

4.3

CVSS3.1

CVE-2025-31333 - Odata meta-data tampering in SAP S4CORE entity

SAP S4CORE OData meta-data property is vulnerable to data tampering, due to which entity set could be externally modified by an attacker causing low impact on integrity of the application. Confidentiality and availability is not impacted.

πŸ“… Published: April 8, 2025, 7:15 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 345171
Page 5571 of 34,518
Β« previous page Β» next page
Filters