6.1
CVE-2025-2164 - pixelstats <= 0.8.2 - Reflected Cross-Site Scripting
The pixelstats plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post_id' and 'sortby' parameters in all versions up to, and including, 0.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrβ¦
6.1
CVE-2025-2163 - Zoorum Comments <= 0.9 - Cross-Site Request Forgery to Stored Cross-Site Scripting
The Zoorum Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9. This is due to missing or incorrect nonce validation on the zoorum_set_options() function. This makes it possible for unauthenticated attackers to update settings and injβ¦
0.0
CVE-2024-13847 -
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.
8.8
CVE-2025-1653 - Directory Listings WordPress plugin β uListing <= 2.2.0 - Authenticated (Subscriber+) Privilege Escβ¦
The Directory Listings WordPress plugin β uListing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.2.0. This is due to the stm_listing_profile_edit AJAX action not having enough restriction on the user meta that can be updated. This makes it possibβ¦
8.8
CVE-2025-1657 - Directory Listings WordPress plugin β uListing <= 2.2.0 - Missing Authorization to Authenticated (Sβ¦
The Directory Listings WordPress plugin β uListing plugin for WordPress is vulnerable to unauthorized modification of data and PHP Object Injection due to a missing capability check on the stm_listing_ajax AJAX action in all versions up to, and including, 2.2.0. This makes it possible for authenticβ¦
8.6
CVE-2025-30066 -
tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at commit 0e58ed8, which contained malicious updateFeatures code.)
0.0
CVE-2025-2333 -
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.
6.9
CVE-2025-2320 - 274056675 springboot-openai-chatgpt User submit improper authorization
A vulnerability has been found in 274056675 springboot-openai-chatgpt e84f6f5 and classified as critical. Affected by this vulnerability is the function submit of the file /api/blade-user/submit of the component User Handler. The manipulation leads to improper authorization. The attack can be launcβ¦
3.5
CVE-2025-2295 - Potential iSCSI R2T PDU Vulnerability
EDK2 contains a vulnerability in BIOS where a user may cause an Integer Overflow or Wraparound by network means. A successful exploitation of this vulnerability may lead to denial of service.
4.8
CVE-2025-2310 - HDF5 Metadata Attribute Decoder H5MM_strndup heap-based overflow
A vulnerability was found in HDF5 1.14.6 and classified as critical. This issue affects the function H5MM_strndup of the component Metadata Attribute Decoder. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and mβ¦