5.3

CVSS3.1

CVE-2024-13887 - Business Directory Plugin - Easy Listing Directories for WordPress <= 6.4.14 - Insecure Direct Obje…

The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.4.14 via the 'ajax_listing_submit_image_upload' function due to missing validation on a user controlled key. This mak…

πŸ“… Published: March 13, 2025, 3:21 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-2107 - Arielbrailovsky-Viralad <= 1.0.8 - Unauthenticated SQL Injection

The ArielBrailovsky-ViralAd plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the printResultAndDie() function in all versions up to, and including, 1.0.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL q…

πŸ“… Published: March 13, 2025, 1:45 a.m. πŸ”„ Last Modified: April 21, 2026, 10 p.m.

4.3

CVSS3.1

CVE-2024-13703 - CRM and Lead Management by vcita <= 2.7.5 - Missing Authorization to Authenticated (Susbcriber+) Wi…

The CRM and Lead Management by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_ajax_toggle_ae() function in all versions up to, and including, 2.7.5. This makes it possible for authenticated attackers, with Subscriber-leve…

πŸ“… Published: March 13, 2025, 1:45 a.m. πŸ”„ Last Modified: April 8, 2026, 6:20 p.m.

6.4

CVSS3.1

CVE-2025-1559 - CC-IMG-Shortcode <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

The CC-IMG-Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'img' shortcode in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attack…

πŸ“… Published: March 13, 2025, 1:45 a.m. πŸ”„ Last Modified: April 21, 2026, 10 p.m.

7.5

CVSS3.1

CVE-2025-2106 - Arielbrailovsky-Viralad <= 1.0.8 - Unauthenticated SQL Injection

The ArielBrailovsky-ViralAd plugin for WordPress is vulnerable to SQL Injection via the 'text' and 'id' parameters of the limpia() function in all versions up to, and including, 1.0.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL …

πŸ“… Published: March 13, 2025, 1:45 a.m. πŸ”„ Last Modified: April 21, 2026, 10 p.m.

8.8

CVSS3.1

CVE-2024-53406 -

Espressif Esp idf v5.3.0 is vulnerable to Insecure Permissions resulting in Authentication bypass. In the reconnection phase, the device reuses the session key from a previous connection session, creating an opportunity for attackers to execute security bypass attacks.

πŸ“… Published: March 13, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 1:04 a.m.

7.5

CVSS3.1

CVE-2025-29363 -

Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to buffer overflow via the schedStartTime and schedEndTime parameters at /goform/saveParentControlInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.

πŸ“… Published: March 13, 2025, midnight πŸ”„ Last Modified: Aug. 25, 2025, 2:14 a.m.

7.5

CVSS3.1

CVE-2025-29358 -

Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the firewallEn parameter at /goform/SetFirewallCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.

πŸ“… Published: March 13, 2025, midnight πŸ”„ Last Modified: Aug. 1, 2025, 2:15 a.m.

5.4

CVSS3.1

CVE-2025-28010 -

A cross-site scripting (XSS) vulnerability has been identified in MODX prior to 3.1.0. The vulnerability allows authenticated users to upload SVG files containing malicious JavaScript code as profile images, which gets executed in victims' browsers when viewing the profile image.

πŸ“… Published: March 13, 2025, midnight πŸ”„ Last Modified: April 3, 2025, 4:42 p.m.

7.5

CVSS3.1

CVE-2025-29361 -

Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the list parameter at /goform/SetVirtualServerCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.

πŸ“… Published: March 13, 2025, midnight πŸ”„ Last Modified: Aug. 25, 2025, 2:14 a.m.
Total resulsts: 349182
Page 6353 of 34,919
Β« previous page Β» next page
Filters