6.1

CVSS3.1

CVE-2025-2165 - SH Email Alert <= 1.0 - Reflected Cross-Site Scripting

The SH Email Alert plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mid' parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts …

πŸ“… Published: March 26, 2025, 2:23 a.m. πŸ”„ Last Modified: April 21, 2026, 9:45 p.m.

6.4

CVSS3.1

CVE-2025-2573 - Amazing service box Addons For WPBakery Page Builder <= 2.0.0 - Authenticated (Author+) Stored Cros…

The Amazing service box Addons For WPBakery Page Builder (formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping. This makes it possible f…

πŸ“… Published: March 26, 2025, 2:23 a.m. πŸ”„ Last Modified: April 21, 2026, 9:45 p.m.

6.4

CVSS3.1

CVE-2025-2576 - Ayyash Studio <= 1.0.3 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

The Ayyash Studio β€” The kick-start kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level…

πŸ“… Published: March 26, 2025, 2:23 a.m. πŸ”„ Last Modified: April 22, 2026, 4:15 a.m.

6.5

CVSS3.1

CVE-2024-55965 -

An issue was discovered in Appsmith before 1.51. Users invited as "App Viewer" incorrectly have access to development information of a workspace (specifically, a list of datasources in a workspace they're a member of). This information disclosure does not expose sensitive data in the datasources, s…

πŸ“… Published: March 26, 2025, midnight πŸ”„ Last Modified: July 8, 2025, 5:35 p.m.

9.8

CVSS3.1

CVE-2025-26004 -

Telesquare TLR-2005KSH 1.1.4 is vulnerable to unauthorized stack buffer overflow vulnerability when requesting admin.cgi parameter with setDdns.

πŸ“… Published: March 26, 2025, midnight πŸ”„ Last Modified: April 1, 2025, 4:34 p.m.

7.5

CVSS3.1

CVE-2025-28361 -

Unauthorized stack overflow vulnerability in Telesquare TLR-2005KSH v.1.1.4 allows a remote attacker to obtain sensitive information via the systemutil.cgi component.

πŸ“… Published: March 26, 2025, midnight πŸ”„ Last Modified: April 1, 2025, 3:43 p.m.

7.5

CVSS3.1

CVE-2025-26009 -

Telesquare TLR-2005KSH 1.1.4 has an Information Disclosure vulnerability when requesting systemutilit.cgi.

πŸ“… Published: March 26, 2025, midnight πŸ”„ Last Modified: April 1, 2025, 4:33 p.m.

6.5

CVSS3.1

CVE-2024-55963 -

An issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the restart API on Appsmith, causing a server restart. This is still within the Appsmith container, and the impact is limited to Appsmith's own server only, but there is a denial of s…

πŸ“… Published: March 26, 2025, midnight πŸ”„ Last Modified: April 1, 2025, 4:34 p.m.

5.3

CVSS3.1

CVE-2025-30742 -

httpd.c in atophttpd 2.8.0 has an off-by-one error and resultant out-of-bounds read because a certain 1024-character req string would not have a final '\0' character.

πŸ“… Published: March 26, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-26002 -

Telesquare TLR-2005KSH 1.1.4 is affected by an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setSyncTimeHost.

πŸ“… Published: March 26, 2025, midnight πŸ”„ Last Modified: April 1, 2025, 4:35 p.m.
Total resulsts: 349182
Page 6214 of 34,919
Β« previous page Β» next page
Filters