8.7

CVSS4.0

CVE-2025-3574 - Insecure Direct Object Reference on Deporsite by T-INNOVA

Insecure Direct Object Reference vulnerability in Deporsite from T-INNOVA allows an attacker to retrieve sensitive information from others users via "idUsuario" parameter in "/helper/Familia/obtenerFamiliaUsuario" endpoint.

πŸ“… Published: April 15, 2025, 8:47 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-3579 - Code Injection Vulnerability in AiDex

In versions prior to Aidex 1.7, an authenticated malicious user, taking advantage of an open registry, could execute unauthorised commands within the system. This includes executing operating system (Unix) commands, interacting with internal services such as PHP or MySQL, and even invoking native f…

πŸ“… Published: April 15, 2025, 8:44 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-3578 - Adversarial Input Handling Vulnerability in AiDex

A malicious, authenticated user in Aidex, versions prior to 1.7, could list credentials of other users, create or modify existing users in the application, list credentials of users in production or development environments. In addition, it would be possible to cause bugs that would result in the e…

πŸ“… Published: April 15, 2025, 8:42 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.6

CVSS3.1

CVE-2024-45712 - SolarWinds Serv-U Client-Side Cross-Site Scripting Vulnerability

SolarWinds Serv-U is vulnerable to a client-side cross-site scripting (XSS) vulnerability. The vulnerability can only be performed by an authenticated account, on the local machine, from the local browser session. Therefore the risk is very low.

πŸ“… Published: April 15, 2025, 8:39 a.m. πŸ”„ Last Modified: Nov. 18, 2025, 9:45 p.m.

4.8

CVSS3.1

CVE-2024-13610 - Simple Social Media Share Buttons < 6.0.0 - Admin+ Stored XSS

The Simple Social Media Share Buttons WordPress plugin before 6.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisit…

πŸ“… Published: April 15, 2025, 6 a.m. πŸ”„ Last Modified: April 29, 2025, 8:08 p.m.

4.8

CVSS3.1

CVE-2024-13207 - Widget for Social Page Feeds < 6.4.2 - Admin+ Stored XSS

The Widget for Social Page Feeds WordPress plugin before 6.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setu…

πŸ“… Published: April 15, 2025, 6 a.m. πŸ”„ Last Modified: April 29, 2025, 8:11 p.m.

5.1

CVSS4.0

CVE-2025-3622 - Xorbits Inference model.py load deserialization

A vulnerability, which was classified as critical, has been found in Xorbits Inference up to 1.4.1. This issue affects the function load of the file xinference/thirdparty/cosyvoice/cli/model.py. The manipulation leads to deserialization.

πŸ“… Published: April 15, 2025, 5:31 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2025-2225 - Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates <= 1.6.9 - A…

The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜rael_title_tag' parameter in all versions up to, and including, 1.6.9 due to insufficient input sanitization and output escaping. Thi…

πŸ“… Published: April 15, 2025, 5:23 a.m. πŸ”„ Last Modified: April 20, 2026, 11:30 p.m.

5.3

CVSS4.0

CVE-2025-3573 - jquery-validation: XSS Vulnerability in jquery-validation

Versions of the package jquery-validation before 1.20.0 are vulnerable to Cross-site Scripting (XSS) in the showLabel() function, which may take input from a user-controlled placeholder value. This value will populate a message via $.validator.messages in a user localizable dictionary.

πŸ“… Published: April 15, 2025, 5 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.7

CVSS3.1

CVE-2025-29984 -

Dell Trusted Device, versions prior to 7.0.3.0, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

πŸ“… Published: April 15, 2025, 3:38 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.
Total resulsts: 346541
Page 5619 of 34,655
Β« previous page Β» next page
Filters