4.4

CVSS3.1

CVE-2025-2076 - binlayerpress <= 1.1 - Authenticated (Admin+) Stored Cross-Site Scripting

The binlayerpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and a…

πŸ“… Published: March 12, 2025, 3:21 a.m. πŸ”„ Last Modified: April 8, 2026, 4:50 p.m.

4.4

CVSS3.1

CVE-2025-2205 - GDPR Cookie Compliance <= 4.15.6 - Authenticated (Admin+) Stored Cross-Site Scripting

The GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice – CCPA, DSGVO, RGPD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.15.6 due to insufficient input sanitization and output escaping. This makes it p…

πŸ“… Published: March 12, 2025, 3:21 a.m. πŸ”„ Last Modified: April 8, 2026, 4:46 p.m.

4.8

CVSS4.0

CVE-2025-2220 - Odyssey CMS reCAPTCHA odyssey_contact_form.php key management

A vulnerability was found in Odyssey CMS up to 10.34. It has been classified as problematic. Affected is an unknown function of the file /modules/odyssey_contact_form/odyssey_contact_form.php of the component reCAPTCHA Handler. The manipulation of the argument g-recaptcha-response leads to key mana…

πŸ“… Published: March 12, 2025, 1 a.m. πŸ”„ Last Modified: March 25, 2025, 5:15 p.m.

6.9

CVSS4.0

CVE-2025-2219 - LoveCards LoveCardsV2 image unrestricted upload

A vulnerability was found in LoveCards LoveCardsV2 up to 2.3.2 and classified as critical. This issue affects some unknown processing of the file /api/upload/image. The manipulation of the argument file leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclos…

πŸ“… Published: March 12, 2025, 12:31 a.m. πŸ”„ Last Modified: March 25, 2025, 5:19 p.m.

6.9

CVSS4.0

CVE-2025-2218 - LoveCards LoveCardsV2 Setting other access control

A vulnerability has been found in LoveCards LoveCardsV2 up to 2.3.2 and classified as critical. This vulnerability affects unknown code of the file /api/system/other of the component Setting Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The explo…

πŸ“… Published: March 12, 2025, 12:31 a.m. πŸ”„ Last Modified: March 25, 2025, 5:21 p.m.

5.3

CVSS4.0

CVE-2025-2217 - zzskzy Warehouse Refinement Management System getAdyData.ashx ProcessRequest sql injection

A vulnerability, which was classified as critical, was found in zzskzy Warehouse Refinement Management System 1.3. This affects the function ProcessRequest of the file /getAdyData.ashx. The manipulation of the argument showid leads to sql injection. It is possible to initiate the attack remotely. T…

πŸ“… Published: March 12, 2025, midnight πŸ”„ Last Modified: March 25, 2025, 5:22 p.m.

5.3

CVSS4.0

CVE-2025-2216 - zzskzy Warehouse Refinement Management System SaveCrash.ashx UploadCrash unrestricted upload

A vulnerability, which was classified as critical, has been found in zzskzy Warehouse Refinement Management System 1.3. Affected by this issue is the function UploadCrash of the file /crash/log/SaveCrash.ashx. The manipulation of the argument file leads to unrestricted upload. The attack may be lau…

πŸ“… Published: March 12, 2025, midnight πŸ”„ Last Modified: March 25, 2025, 5:24 p.m.

5.4

CVSS3.1

CVE-2025-27915 -

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Classic Web Client due to insufficient sanitization of HTML content in ICS files. When a user views an e-mail message containing a malicious ICS entry, its em…

πŸ“… Published: March 12, 2025, midnight πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

5.4

CVSS3.1

CVE-2025-27914 -

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Reflected Cross-Site Scripting (XSS) vulnerability exists in the /h/rest endpoint, allowing authenticated attackers to inject and execute arbitrary JavaScript in a victim's session. Exploitation requires a valid auth tok…

πŸ“… Published: March 12, 2025, midnight πŸ”„ Last Modified: April 2, 2025, 8:38 p.m.

7.8

CVSS3.1

CVE-2025-21858 - geneve: Fix use-after-free in geneve_find_dev().

In the Linux kernel, the following vulnerability has been resolved: geneve: Fix use-after-free in geneve_find_dev(). syzkaller reported a use-after-free in geneve_find_dev() [0] without repro. geneve_configure() links struct geneve_dev.next to net_generic(net, geneve_net_id)->geneve_list. The n…

πŸ“… Published: March 12, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.
Total resulsts: 343932
Page 5836 of 34,394
Β« previous page Β» next page
Filters