9.3

CVSS3.1

CVE-2025-22523 - WordPress Schedule Plugin <= 1.0.0 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in scheduler Schedule schedule allows Blind SQL Injection.This issue affects Schedule: from n/a through <= 1.0.0.

πŸ“… Published: March 28, 2025, 3:12 p.m. πŸ”„ Last Modified: April 23, 2026, 3:23 p.m.

7.1

CVSS3.1

CVE-2025-22501 - WordPress Improve My City plugin <= 1.6 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Improve My City Improve My City improve-my-city allows Reflected XSS.This issue affects Improve My City: from n/a through <= 1.6.

πŸ“… Published: March 28, 2025, 3:12 p.m. πŸ”„ Last Modified: April 23, 2026, 3:23 p.m.

7.1

CVSS3.1

CVE-2025-22360 - WordPress WP Azure offload plugin <= 2.0 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in promact WP Azure offload wp-azure-offload allows Reflected XSS.This issue affects WP Azure offload: from n/a through <= 2.0.

πŸ“… Published: March 28, 2025, 3:12 p.m. πŸ”„ Last Modified: April 23, 2026, 3:23 p.m.

7.1

CVSS3.1

CVE-2025-22356 - WordPress Stencies plugin <= 0.58 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stencies Stencies stencies allows Reflected XSS.This issue affects Stencies: from n/a through <= 0.58.

πŸ“… Published: March 28, 2025, 3:12 p.m. πŸ”„ Last Modified: April 23, 2026, 3:23 p.m.

8.1

CVSS3.1

CVE-2024-54362 - WordPress GetShop ecommerce plugin <= 1.3 - Path Traversal vulnerability

Path Traversal: '.../...//' vulnerability in boggibill GetShop ecommerce getshop-ecommerce allows Path Traversal.This issue affects GetShop ecommerce: from n/a through <= 1.3.

πŸ“… Published: March 28, 2025, 3:12 p.m. πŸ”„ Last Modified: April 23, 2026, 3:22 p.m.

8.6

CVSS3.1

CVE-2024-54291 - WordPress PluginPass plugin <= 0.9.10 - Arbitrary File Download/Delete vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in labs64 PluginPass pluginpass-pro-plugintheme-licensing allows Manipulating Web Input to File System Calls.This issue affects PluginPass: from n/a through <= 0.9.10.

πŸ“… Published: March 28, 2025, 3:12 p.m. πŸ”„ Last Modified: April 23, 2026, 3:22 p.m.

7.1

CVSS3.1

CVE-2024-51624 - WordPress JΓ‘-JΓ‘ Pagamentos for WooCommerce plugin <= 1.3.0 - Reflected Cross Site Scripting (XSS) v…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jajapagamentos JΓ‘-JΓ‘ Pagamentos for WooCommerce wc-ja-ja-pagamentos-multicaixa-express allows Reflected XSS.This issue affects JΓ‘-JΓ‘ Pagamentos for WooCommerce: from n/a through <= 1.3.0.

πŸ“… Published: March 28, 2025, 3:12 p.m. πŸ”„ Last Modified: April 23, 2026, 3:20 p.m.

7.5

CVSS3.1

CVE-2025-30211 - KEX init error results with excessive memory usage

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.1, 26.2.5.10, and 25.3.2.19, a maliciously formed KEX init message can result with high memory usage. Implementation does not verify RFC specified limits on algorithm names (64 characters) provided in K…

πŸ“… Published: March 28, 2025, 2:55 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.7

CVSS4.0

CVE-2025-30372 - Emlog Pro contains an SQL injection vulnerability.

Emlog is an open source website building system. Emlog Pro versions pro-2.5.7 and pro-2.5.8 contain an SQL injection vulnerability. `search_controller.php` does not use addslashes after urldecode, allowing the preceeding addslashes to be bypassed by URL double encoding. This could result in potenti…

πŸ“… Published: March 28, 2025, 2:51 p.m. πŸ”„ Last Modified: April 14, 2025, 2:49 p.m.

2.1

CVSS4.0

CVE-2025-30371 - Metabase vulnerable to circumvention of local link access protection in GeoJson endpoint

Metabase is a business intelligence and embedded analytics tool. Versions prior to v0.52.16.4, v1.52.16.4, v0.53.8, and v1.53.8 are vulnerable to circumvention of local link access protection in GeoJson endpoint. Self hosted Metabase instances that are using the GeoJson feature could be potentially…

πŸ“… Published: March 28, 2025, 2:47 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 347586
Page 5985 of 34,759
Β« previous page Β» next page
Filters