4.4

CVSS3.1

CVE-2025-2205 - GDPR Cookie Compliance <= 4.15.6 - Authenticated (Admin+) Stored Cross-Site Scripting

The GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice – CCPA, DSGVO, RGPD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.15.6 due to insufficient input sanitization and output escaping. This makes it p…

πŸ“… Published: March 12, 2025, 3:21 a.m. πŸ”„ Last Modified: April 21, 2026, 10:15 p.m.

4.8

CVSS4.0

CVE-2025-2220 - Odyssey CMS reCAPTCHA odyssey_contact_form.php key management

A vulnerability was found in Odyssey CMS up to 10.34. It has been classified as problematic. Affected is an unknown function of the file /modules/odyssey_contact_form/odyssey_contact_form.php of the component reCAPTCHA Handler. The manipulation of the argument g-recaptcha-response leads to key mana…

πŸ“… Published: March 12, 2025, 1 a.m. πŸ”„ Last Modified: March 25, 2025, 5:15 p.m.

6.9

CVSS4.0

CVE-2025-2219 - LoveCards LoveCardsV2 image unrestricted upload

A vulnerability was found in LoveCards LoveCardsV2 up to 2.3.2 and classified as critical. This issue affects some unknown processing of the file /api/upload/image. The manipulation of the argument file leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclos…

πŸ“… Published: March 12, 2025, 12:31 a.m. πŸ”„ Last Modified: March 25, 2025, 5:19 p.m.

6.9

CVSS4.0

CVE-2025-2218 - LoveCards LoveCardsV2 Setting other access control

A vulnerability has been found in LoveCards LoveCardsV2 up to 2.3.2 and classified as critical. This vulnerability affects unknown code of the file /api/system/other of the component Setting Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The explo…

πŸ“… Published: March 12, 2025, 12:31 a.m. πŸ”„ Last Modified: March 25, 2025, 5:21 p.m.

5.3

CVSS4.0

CVE-2025-2217 - zzskzy Warehouse Refinement Management System getAdyData.ashx ProcessRequest sql injection

A vulnerability, which was classified as critical, was found in zzskzy Warehouse Refinement Management System 1.3. This affects the function ProcessRequest of the file /getAdyData.ashx. The manipulation of the argument showid leads to sql injection. It is possible to initiate the attack remotely. T…

πŸ“… Published: March 12, 2025, midnight πŸ”„ Last Modified: March 25, 2025, 5:22 p.m.

5.3

CVSS4.0

CVE-2025-2216 - zzskzy Warehouse Refinement Management System SaveCrash.ashx UploadCrash unrestricted upload

A vulnerability, which was classified as critical, has been found in zzskzy Warehouse Refinement Management System 1.3. Affected by this issue is the function UploadCrash of the file /crash/log/SaveCrash.ashx. The manipulation of the argument file leads to unrestricted upload. The attack may be lau…

πŸ“… Published: March 12, 2025, midnight πŸ”„ Last Modified: March 25, 2025, 5:24 p.m.

8.8

CVSS3.1

CVE-2025-26260 -

Plenti <= 0.7.16 is vulnerable to code execution. Users uploading '.svelte' files with the /postLocal endpoint can define the file name as javascript codes. The server executes the uploaded file name in host, and cause code execution.

πŸ“… Published: March 12, 2025, midnight πŸ”„ Last Modified: Oct. 2, 2025, 3:55 p.m.

7.5

CVSS3.1

CVE-2025-25709 -

An issue in dtp.ae tNexus Airport View v.2.8 allows a remote attacker to escalate privileges via the addUser and updateUser endpoints

πŸ“… Published: March 12, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-25774 -

An issue was discovered in Open5GS v2.7.2. When a UE switches between two gNBs and sends a handover request at a specific time, it may cause an exception in the AMF's internal state machine, leading to an AMF crash and resulting in a Denial of Service (DoS).

πŸ“… Published: March 12, 2025, midnight πŸ”„ Last Modified: April 29, 2025, 3:04 p.m.

5.5

CVSS3.1

CVE-2025-21850 - nvmet: Fix crash when a namespace is disabled

In the Linux kernel, the following vulnerability has been resolved: nvmet: Fix crash when a namespace is disabled The namespace percpu counter protects pending I/O, and we can only safely diable the namespace once the counter drop to zero. Otherwise we end up with a crash when running blktests/nv…

πŸ“… Published: March 12, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 8:18 p.m.
Total resulsts: 349182
Page 6361 of 34,919
Β« previous page Β» next page
Filters