0.0

CVE-2025-1249 - WordPress Events Manager plugin <= 6.6.4.1 - Broken Access Control vulnerability

Missing Authorization vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Events Manager: from n/a through <= 6.6.4.1.

πŸ“… Published: Feb. 26, 2025, 2:32 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-0719 - IBM Cloud Pak for Data cross-site scripting

IBM Cloud Pak for Data 4.0.0 through 4.8.5 and 5.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted …

πŸ“… Published: Feb. 26, 2025, 2:04 p.m. πŸ”„ Last Modified: Aug. 8, 2025, 7:35 p.m.

4.3

CVSS3.1

CVE-2025-26925 - WordPress Admin Menu Manager plugin <= 1.0.3 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Required Admin Menu Manager allows Cross Site Request Forgery.This issue affects Admin Menu Manager: from n/a through 1.0.3.

πŸ“… Published: Feb. 26, 2025, 1:21 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2024-47051 - Remote Code Execution & File Deletion in Asset Uploads

This advisory addresses two critical security vulnerabilities present in Mautic versions before 5.2.3. These vulnerabilities could be exploited by authenticated users. * Remote Code Execution (RCE) via Asset Upload:Β A Remote Code Execution vulnerability has been identified in the asset upload f…

πŸ“… Published: Feb. 26, 2025, 12:01 p.m. πŸ”„ Last Modified: Oct. 16, 2025, 5:11 p.m.

7.7

CVSS3.1

CVE-2024-47053 - Improper Authorization in Reporting API

This advisory addresses an authorization vulnerability in Mautic's HTTP Basic Authentication implementation. This flaw could allow unauthorized access to sensitive report data. * Improper Authorization:Β An authorization flaw exists in Mautic's API Authorization implementation. Any authenticated…

πŸ“… Published: Feb. 26, 2025, 11:54 a.m. πŸ”„ Last Modified: Oct. 16, 2025, 5:12 p.m.

4.3

CVSS3.1

CVE-2022-25773 - Relative Path Traversal in assets file upload

This advisory addresses a file placement vulnerability that could allow assets to be uploaded to unintended directories on the server. * Improper Limitation of a Pathname to a Restricted Directory:Β A vulnerability exists in the asset upload functionality that allows users to upload files to dir…

πŸ“… Published: Feb. 26, 2025, 11:48 a.m. πŸ”„ Last Modified: Oct. 16, 2025, 5:08 p.m.

4.4

CVSS3.1

CVE-2024-6810 - Quiz Organizer <= 2.9.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

The Quiz Organizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web s…

πŸ“… Published: Feb. 26, 2025, 11:12 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-0731 - SMA: Sunny Portal Remote Code Execution

An unauthenticated remote attacker can upload a .aspx file instead of a PV system picture through the demo account. The code can only be executed in the security context of the user.

πŸ“… Published: Feb. 26, 2025, 10:01 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.7

CVSS3.0

CVE-2025-26698 -

Incorrect resource transfer between spheres issue exists in RevoWorks SCVX and RevoWorks Browser. If exploited, malicious files may be downloaded to the system where using the product.

πŸ“… Published: Feb. 26, 2025, 8:42 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2025-1517 - Sina Extension for Elementor <= 3.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting vi…

The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Fancy Text, Countdown Widget, and Login Form shortcodes in all versions up to, …

πŸ“… Published: Feb. 26, 2025, 8:21 a.m. πŸ”„ Last Modified: April 8, 2026, 5:30 p.m.
Total resulsts: 345132
Page 6144 of 34,514
Β« previous page Β» next page
Filters