6.5

CVSS3.1

CVE-2025-31730 - WordPress Marketer Addons Plugin <= 1.0.1 - Stored Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DigitalCourt Marketer Addons marketer-addons allows Stored XSS.This issue affects Marketer Addons: from n/a through <= 1.0.1.

πŸ“… Published: April 1, 2025, 2:51 p.m. πŸ”„ Last Modified: April 23, 2026, 3:28 p.m.

6.1

CVSS3.1

CVE-2025-30676 - Apache OFBiz: Stored XSS Vulnerability

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.19. Users are recommended to upgrade to version 18.12.19, which fixes the issue.

πŸ“… Published: April 1, 2025, 2:43 p.m. πŸ”„ Last Modified: April 29, 2025, 8:52 p.m.

5.1

CVSS4.0

CVE-2025-30224 - MyDumper arbitrary file read issue

MyDumper is a MySQL Logical Backup Tool. The MySQL C client library (libmysqlclient) allows authenticated remote actors to read arbitrary files from client systems via a crafted server response to LOAD LOCAL INFILE query, leading to sensitive information disclosure when clients connect to untrusted…

πŸ“… Published: April 1, 2025, 2:38 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-30354 - Bruno ignores Safe-Mode in Asserts expressions

Bruno is an open source IDE for exploring and testing APIs. A bug in the assertion runtime caused assert expressions to run in Developer Mode, even if Safe Mode was selected. The bug resulted in the sandbox settings to be ignored for the particular case where a single request is run/sent. This vuln…

πŸ“… Published: April 1, 2025, 2:21 p.m. πŸ”„ Last Modified: Sept. 22, 2025, 2:33 p.m.

8.7

CVSS4.0

CVE-2025-30210 - Bruno XSS On Environment Name

Bruno is an open source IDE for exploring and testing APIs. Prior to 1.39.1, the custom tool-tip components which internally use react-tooltip were setting the content (in this case the Environment name) as raw HTML which then gets injected into DOM on hover. This, combined with loose Content Secur…

πŸ“… Published: April 1, 2025, 2:16 p.m. πŸ”„ Last Modified: Sept. 23, 2025, 5:01 p.m.

0.0

CVE-2025-3094 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: April 1, 2025, 2:02 p.m. πŸ”„ Last Modified: July 5, 2025, 11:15 p.m.

4.3

CVSS3.1

CVE-2025-31408 - WordPress Zoho Flow plugin <= 2.13.3 - Broken Access Control vulnerability

Missing Authorization vulnerability in Zoho Flow Zoho Flow zoho-flow allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zoho Flow: from n/a through <= 2.13.3.

πŸ“… Published: April 1, 2025, 1:07 p.m. πŸ”„ Last Modified: April 23, 2026, 3:27 p.m.

7.8

CVSS3.1

CVE-2025-22231 - VMware Aria Operations updates address a local privilege escalation vulnerability (CVE-2025-22231)

VMware Aria Operations contains a local privilege escalation vulnerability.Β A malicious actor with local administrative privileges can escalate their privileges to root on the appliance running VMware Aria Operations.

πŸ“… Published: April 1, 2025, 12:59 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2025-1660 - DWFX File Parsing Memory Corruption Vulnerability

A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

πŸ“… Published: April 1, 2025, 12:29 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:29 p.m.

5.3

CVSS3.1

CVE-2025-3035 - Tab title disclosure across pages when using AI chatbot

By first using the AI chatbot in one tab and later activating it in another tab, the document title of the previous tab would leak into the chat prompt. This vulnerability was fixed in Firefox 137.

πŸ“… Published: April 1, 2025, 12:29 p.m. πŸ”„ Last Modified: April 20, 2026, 8:45 p.m.
Total resulsts: 348618
Page 6022 of 34,862
Β« previous page Β» next page
Filters