7.1
CVE-2025-26992 - WordPress Landing Page Cat plugin <= 1.7.8 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fatcatapps Landing Page Cat landing-page-cat allows Reflected XSS.This issue affects Landing Page Cat: from n/a through <= 1.7.8.
3.7
CVE-2025-32943 - PeerTube HLS Video Files Path Traversal
The vulnerability allows any authenticated user to leak the contents of arbitrary β.m3u8β files from the PeerTube server due to a path traversal in the HLS endpoint.
5.5
CVE-2025-1688 - System configuration password reset
Milestone Systems has discovered a security vulnerability in Milestone XProtect installer that resets system configuration password after the upgrading from older versions using specific installers. The system configuration password is an additional, optional protection that is enabled on the Maβ¦
6.4
CVE-2025-2083 - Logo Carousel Gutenberg Block <= 2.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting vβ¦
The Logo Carousel Gutenberg Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the βsliderIdβ parameter in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributβ¦
8.7
CVE-2025-3575 - Insecure Direct Object Reference en Deporsite de T-INNOVA
Insecure Direct Object Reference vulnerability in Deporsite from T-INNOVA allows an attacker to retrieve sensitive information from others users via "idUsuario" parameter in "/helper/Familia/establecerUsuarioSeleccion" endpoint.
8.7
CVE-2025-3574 - Insecure Direct Object Reference on Deporsite by T-INNOVA
Insecure Direct Object Reference vulnerability in Deporsite from T-INNOVA allows an attacker to retrieve sensitive information from others users via "idUsuario" parameter in "/helper/Familia/obtenerFamiliaUsuario" endpoint.
9.3
CVE-2025-3579 - Code Injection Vulnerability in AiDex
In versions prior to Aidex 1.7, an authenticated malicious user, taking advantage of an open registry, could execute unauthorised commands within the system. This includes executing operating system (Unix) commands, interacting with internal services such as PHP or MySQL, and even invoking native fβ¦
9.3
CVE-2025-3578 - Adversarial Input Handling Vulnerability in AiDex
A malicious, authenticated user in Aidex, versions prior to 1.7, could list credentials of other users, create or modify existing users in the application, list credentials of users in production or development environments. In addition, it would be possible to cause bugs that would result in the eβ¦
2.6
CVE-2024-45712 - SolarWinds Serv-U Client-Side Cross-Site Scripting Vulnerability
SolarWinds Serv-U is vulnerable to a client-side cross-site scripting (XSS) vulnerability. The vulnerability can only be performed by an authenticated account, on the local machine, from the local browser session. Therefore the risk is very low.
4.8
CVE-2024-13610 - Simple Social Media Share Buttons < 6.0.0 - Admin+ Stored XSS
The Simple Social Media Share Buttons WordPress plugin before 6.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisitβ¦