4.8

CVSS3.1

CVE-2025-1269 - Open Redirect in HAVELSAN's Open Source Project Liman MYS

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in HAVELSAN Liman MYS allows Cross-Site Flashing.This issue affects Liman MYS: before 2.1.1 - 1010.

πŸ“… Published: Feb. 18, 2025, 1:48 p.m. πŸ”„ Last Modified: Feb. 20, 2025, 11:20 a.m.

6.5

CVSS3.1

CVE-2025-1414 - firefox: Memory safety bugs fixed in Firefox 135.0.1

Memory safety bugs present in Firefox 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 135.0.1.

πŸ“… Published: Feb. 18, 2025, 1:39 p.m. πŸ”„ Last Modified: March 28, 2025, 7:05 p.m.

5.7

CVSS3.1

CVE-2025-1035 - Path Traversal in Komtera Technolgies' KLog Server

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Komtera Technolgies KLog Server allows Manipulating Web Input to File System Calls.This issue affects KLog Server: before 3.1.1.

πŸ“… Published: Feb. 18, 2025, 11:30 a.m. πŸ”„ Last Modified: Feb. 18, 2025, 2:14 p.m.

4.3

CVSS3.1

CVE-2024-13783 - FormCraft <= 3.9.11 - Missing Authorization to Plugin Data Export in formcraft-main.php

The FormCraft plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check in formcraft-main.php in all versions up to, and including, 3.9.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export all plugin data…

πŸ“… Published: Feb. 18, 2025, 11:10 a.m. πŸ”„ Last Modified: April 8, 2026, 5:33 p.m.

6.5

CVSS3.1

CVE-2024-13691 - Uncode <= 2.9.1.6 - Authenticated (Subscriber+) Arbitrary File Read in uncode_recordMedia

The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_recordMedia' function in all versions up to, and including, 2.9.1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read arbitrary …

πŸ“… Published: Feb. 18, 2025, 11:10 a.m. πŸ”„ Last Modified: April 8, 2026, 5:26 p.m.

5.4

CVSS3.1

CVE-2024-13667 - Uncode <= 2.9.1.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via mle-description

The Uncode theme for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜mle-description’ parameter in all versions up to, and including, 2.9.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access …

πŸ“… Published: Feb. 18, 2025, 11:10 a.m. πŸ”„ Last Modified: April 8, 2026, 5:03 p.m.

7.2

CVSS3.1

CVE-2025-0817 - FormCraft - Premium WordPress Form Builder <= 3.9.11 - Unauthenticated Stored Cross-Site Scripting …

The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.9.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…

πŸ“… Published: Feb. 18, 2025, 11:10 a.m. πŸ”„ Last Modified: April 8, 2026, 5:02 p.m.

7.5

CVSS3.1

CVE-2024-13681 - Uncode <= 2.9.1.6 - Unauthenticated Arbitrary File Read in uncode_admin_get_oembed

The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_admin_get_oembed' function in all versions up to, and including, 2.9.1.6. This makes it possible for unauthenticated attackers to read arbitrary files on the server.

πŸ“… Published: Feb. 18, 2025, 11:10 a.m. πŸ”„ Last Modified: April 8, 2026, 5:02 p.m.

0.0

CVE-2024-13636 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-24926. Reason: This candidate is a reservation duplicate of CVE-2024-24926. Notes: All CVE users should reference CVE-2024-24926 instead of this candidate. All references and descriptions in this candidate have been removed to prev…

πŸ“… Published: Feb. 18, 2025, 11:10 a.m. πŸ”„ Last Modified: Feb. 24, 2025, 10:15 p.m.

7.2

CVSS3.1

CVE-2025-0521 - Post SMTP <= 3.0.2 - Unauthenticated Stored Cross-Site Scripting

The Post SMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the from and subject parameter in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scr…

πŸ“… Published: Feb. 18, 2025, 11:10 a.m. πŸ”„ Last Modified: April 8, 2026, 4:46 p.m.
Total resulsts: 343924
Page 6174 of 34,393
Β« previous page Β» next page
Filters