4.3
CVE-2025-39472 - WordPress WooCommerce Social Login plugin < 2.8.3 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in wpweb WooCommerce Social Login woo-social-login allows Cross Site Request Forgery.This issue affects WooCommerce Social Login: from n/a through < 2.8.3.
6.5
CVE-2025-22872 - Incorrect Neutralization of Input During Web Page Generation in x/net in golang.org/x/net
The tokenizer incorrectly interprets tags with unquoted attribute values that end with a solidus character (/) as self-closing. When directly using Tokenizer, this can result in such tags incorrectly being marked as self-closing, and when using the Parse functions, this can result in content followโฆ
5.9
CVE-2025-3739 - Drupal 8 Google Optimize Hide Page - Critical - Unsupported - SA-CONTRIB-2025-040
Vulnerability in Drupal Drupal 8 Google Optimize Hide Page.This issue affects Drupal 8 Google Optimize Hide Page: *.*.
5.9
CVE-2025-3738 - Google Optimize - Critical - Unsupported - SA-CONTRIB-2025-039
Vulnerability in Drupal Google Optimize.This issue affects Google Optimize: *.*.
5.9
CVE-2025-3737 - Google Maps: Store Locator - Critical - Unsupported - SA-CONTRIB-2025-038
Vulnerability in Drupal Google Maps: Store Locator.This issue affects Google Maps: Store Locator: *.*.
5.9
CVE-2025-3736 - Simple GTM - Critical - Unsupported - SA-CONTRIB-2025-037
Vulnerability in Drupal Simple GTM.This issue affects Simple GTM: *.*.
5.9
CVE-2025-3735 - Panelizer (obsolete) - Critical - Unsupported - SA-CONTRIB-2025-036
Vulnerability in Drupal Panelizer (obsolete).This issue affects Panelizer (obsolete): *.*.
5.9
CVE-2025-3734 - Stage File Proxy - Moderately critical - Denial of Service - SA-CONTRIB-2025-035
Allocation of Resources Without Limits or Throttling vulnerability in Drupal Stage File Proxy allows Flooding.This issue affects Stage File Proxy: from 0.0.0 before 3.1.5.
6.5
CVE-2025-3733 - baguetteBox.js - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-034
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal baguetteBox.Js allows Cross-Site Scripting (XSS).This issue affects baguetteBox.Js: from 0.0.0 before 2.0.4, from 3.0.0 before 3.0.1.
5.9
CVE-2024-22314 - IBM Storage Defender - Resiliency Service information disclosure
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.12 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.