5.4

CVSS3.1

CVE-2025-30767 - WordPress PDF for WPForms plugin <= 5.3.0 - Arbitrary Shortcode Execution vulnerability

Missing Authorization vulnerability in add-ons.org PDF for WPForms pdf-for-wpforms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PDF for WPForms: from n/a through <= 5.3.0.

๐Ÿ“… Published: March 27, 2025, 10:54 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:27 p.m.

6.5

CVSS3.1

CVE-2025-30766 - WordPress Happy Addons for Elementor plugin <= 3.16.2 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons allows DOM-Based XSS.This issue affects Happy Addons for Elementor: from n/a through <= 3.16.2.

๐Ÿ“… Published: March 27, 2025, 10:54 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:27 p.m.

7.6

CVSS3.1

CVE-2025-30765 - WordPress FlexStock plugin <= 3.13.1 - SQL Injection Vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPPOOL FlexStock stock-sync-with-google-sheet-for-woocommerce allows Blind SQL Injection.This issue affects FlexStock: from n/a through <= 3.13.1.

๐Ÿ“… Published: March 27, 2025, 10:54 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:27 p.m.

4.3

CVSS3.1

CVE-2025-30764 - WordPress Football Pool plugin <= 2.12.2 - Cross Site Request Forgery (CSRF) to Settings Change vulโ€ฆ

Cross-Site Request Forgery (CSRF) vulnerability in AntoineH Football Pool football-pool allows Cross Site Request Forgery.This issue affects Football Pool: from n/a through <= 2.12.2.

๐Ÿ“… Published: March 27, 2025, 10:54 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:27 p.m.

6.5

CVSS3.1

CVE-2025-30763 - WordPress EO4WP plugin <= 1.0.8.4 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Olaf Lederer EO4WP fw-integration-for-emailoctopus allows Stored XSS.This issue affects EO4WP: from n/a through <= 1.0.8.4.

๐Ÿ“… Published: March 27, 2025, 10:54 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:27 p.m.

0.0

CVE-2025-2856 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

๐Ÿ“… Published: March 27, 2025, 10:02 a.m. ๐Ÿ”„ Last Modified: July 5, 2025, 11:15 p.m.

5.3

CVSS3.0

CVE-2025-29993 -

The affected versions of PowerCMS allow HTTP header injection. This vulnerability can be leveraged to direct the affected product to send email with a tampered URL, such as password reset mail.

๐Ÿ“… Published: March 27, 2025, 9:06 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-45361 - Mi Connect Service APP protocol flaws lead to leaking sensitive user information

A protocol flaw vulnerability exists in the Xiaomi Mi Connect Service APP. The vulnerability is caused by the validation logic is flawed and can be exploited by attackers to leak sensitive user information.

๐Ÿ“… Published: March 27, 2025, 7:16 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS3.1

CVE-2024-45356 - Xiaomi phone framework has unauthorized access vulnerability

A unauthorized access vulnerability exists in the Xiaomi phone framework. The vulnerability is caused by improper validation and can be exploited by attackers to Access sensitive methods.

๐Ÿ“… Published: March 27, 2025, 7:11 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2024-45355 - Xiaomi phone framework has unauthorized access vulnerability

A unauthorized access vulnerability exists in the Xiaomi phone framework. The vulnerability is caused by improper validation and can be exploited by attackers to Access sensitive methods.

๐Ÿ“… Published: March 27, 2025, 6:48 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 6180 of 34,919
ยซ previous page ยป next page
Filters