0.0

CVE-2025-31099 - WordPress Slider by BestWebSoft plugin <= 1.1.0 - SQL Injection Vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bestweblayout Slider by BestWebSoft slider-bws allows SQL Injection.This issue affects Slider by BestWebSoft: from n/a through <= 1.1.0.

πŸ“… Published: March 28, 2025, 9:39 a.m. πŸ”„ Last Modified: April 1, 2026, 5:20 p.m.

0.0

CVE-2025-31102 - WordPress Hostel plugin <= 1.1.5.5 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Hostel hostel allows Reflected XSS.This issue affects Hostel: from n/a through <= 1.1.5.5.

πŸ“… Published: March 28, 2025, 9:39 a.m. πŸ”„ Last Modified: April 1, 2026, 5:20 p.m.

0.0

CVE-2025-27001 - WordPress Shipmondo – A complete shipping solution for WooCommerce plugin <= 5.0.3 - Authenticated …

Insertion of Sensitive Information Into Sent Data vulnerability in Shipmondo Shipmondo – A complete shipping solution for WooCommerce pakkelabels-for-woocommerce allows Retrieve Embedded Sensitive Data.This issue affects Shipmondo – A complete shipping solution for WooCommerce: from n/a through <= …

πŸ“… Published: March 28, 2025, 9:38 a.m. πŸ”„ Last Modified: April 1, 2026, 5:19 p.m.

5.4

CVSS3.1

CVE-2019-16149 -

An Improper Neutralization of Input During Web Page Generation in FortiClientEMS version 6.2.0 may allow a remote attacker to execute unauthorized code by injecting malicious payload in the user profile of a FortiClient instance being managed by the vulnerable system.

πŸ“… Published: March 28, 2025, 9:07 a.m. πŸ”„ Last Modified: July 15, 2025, 6:59 p.m.

6.1

CVSS3.1

CVE-2025-1705 - tagDiv Composer <= 5.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The tagDiv Composer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.3. This is due to missing or incorrect nonce validation within the td_ajax_get_views AJAX action. This makes it possible for unauthenticated attackers to inject malicious web…

πŸ“… Published: March 28, 2025, 8:23 a.m. πŸ”„ Last Modified: April 8, 2026, 4:43 p.m.

8.1

CVSS3.0

CVE-2025-27932 -

Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file deletion process of the USB storage file-sharing function of HGW-BL1500HM Ver 002.002.003 and earlier. If this vulnerability is exploited, an attacker may delete a file on the device or cause a d…

πŸ“… Published: March 28, 2025, 8:19 a.m. πŸ”„ Last Modified: March 28, 2025, 6:11 p.m.

2.1

CVSS3.0

CVE-2025-27726 -

Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file download process of the USB storage file-sharing function of HGW-BL1500HM Ver 002.002.003 and earlier. If this vulnerability is exploited, the product's files may be obtained and/or altered by a …

πŸ“… Published: March 28, 2025, 8:18 a.m. πŸ”„ Last Modified: March 28, 2025, 6:11 p.m.

8.8

CVSS3.0

CVE-2025-27718 -

Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file upload process of the USB storage file-sharing function of HGW-BL1500HM Ver 002.002.003 and earlier. If this vulnerability is exploited, the product's files may be obtained and/or altered or arbi…

πŸ“… Published: March 28, 2025, 8:18 a.m. πŸ”„ Last Modified: March 28, 2025, 6:11 p.m.

6.5

CVSS3.0

CVE-2025-27716 -

Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file/folder listing process of the USB storage file-sharing function of HGW-BL1500HM Ver 002.002.003 and earlier. If this vulnerability is exploited, the product's files may be obtained and/or altered…

πŸ“… Published: March 28, 2025, 8:18 a.m. πŸ”„ Last Modified: March 28, 2025, 6:11 p.m.

3.6

CVSS3.0

CVE-2025-27574 -

Cross-site scripting vulnerability exists in the USB storage file-sharing function of HGW-BL1500HM Ver 002.002.003 and earlier. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is using the configuration page or functions accessible only fro…

πŸ“… Published: March 28, 2025, 8:18 a.m. πŸ”„ Last Modified: March 28, 2025, 6:11 p.m.
Total resulsts: 343749
Page 5610 of 34,375
Β« previous page Β» next page
Filters