6.4

CVSS3.1

CVE-2025-26704 -

Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.05.

๐Ÿ“… Published: March 11, 2025, 6:55 a.m. ๐Ÿ”„ Last Modified: March 19, 2025, 2:11 p.m.

5.3

CVSS3.1

CVE-2025-26705 -

Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.05.

๐Ÿ“… Published: March 11, 2025, 6:49 a.m. ๐Ÿ”„ Last Modified: March 19, 2025, 2:12 p.m.

5.4

CVSS3.1

CVE-2025-26706 -

Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.07.

๐Ÿ“… Published: March 11, 2025, 6:43 a.m. ๐Ÿ”„ Last Modified: March 19, 2025, 2:15 p.m.

6.9

CVSS4.0

CVE-2025-2174 - libzvbi conv.c vbi_strndup_iconv_ucs2 integer overflow

A vulnerability was found in libzvbi up to 0.2.43. It has been declared as problematic. Affected by this vulnerability is the function vbi_strndup_iconv_ucs2 of the file src/conv.c. The manipulation of the argument src_length leads to integer overflow. The attack can be launched remotely. The exploโ€ฆ

๐Ÿ“… Published: March 11, 2025, 6:31 a.m. ๐Ÿ”„ Last Modified: Oct. 3, 2025, 12:25 a.m.

6.9

CVSS4.0

CVE-2025-2173 - libzvbi conv.c vbi_strndup_iconv_ucs2 uninitialized pointer

A vulnerability was found in libzvbi up to 0.2.43. It has been classified as problematic. Affected is the function vbi_strndup_iconv_ucs2 of the file src/conv.c. The manipulation of the argument src_length leads to uninitialized pointer. It is possible to launch the attack remotely. The exploit hasโ€ฆ

๐Ÿ“… Published: March 11, 2025, 6:31 a.m. ๐Ÿ”„ Last Modified: Oct. 3, 2025, 12:26 a.m.

4.8

CVSS3.1

CVE-2025-0629 - Coronavirus (COVID-19) Notice Message <= 1.1.2 - Admin+ Stored XSS

The Coronavirus (COVID-19) Notice Message WordPress plugin through 1.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multโ€ฆ

๐Ÿ“… Published: March 11, 2025, 6 a.m. ๐Ÿ”„ Last Modified: May 21, 2025, 7:30 p.m.

7.1

CVSS3.1

CVE-2024-13864 - Countdown Timer <= 1.0 - Reflected XSS

The Countdown Timer WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

๐Ÿ“… Published: March 11, 2025, 6 a.m. ๐Ÿ”„ Last Modified: May 6, 2025, 3:05 p.m.

7.1

CVSS3.1

CVE-2024-13862 - S3Bubble Media Streaming <= 8.0 - Reflected XSS

The S3Bubble Media Streaming (AWS|Elementor|YouTube|Vimeo Functionality) WordPress plugin through 8.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

๐Ÿ“… Published: March 11, 2025, 6 a.m. ๐Ÿ”„ Last Modified: May 21, 2025, 7:33 p.m.

6.1

CVSS3.1

CVE-2024-13853 - SEO Tools <= 4.0.7 - Reflected XSS

The SEO Tools WordPress plugin through 4.0.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

๐Ÿ“… Published: March 11, 2025, 6 a.m. ๐Ÿ”„ Last Modified: May 21, 2025, 7:33 p.m.

7.1

CVSS3.1

CVE-2024-13836 - WP Login Control <= 2.0.0 - Reflected XSS

The WP Login Control WordPress plugin through 2.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

๐Ÿ“… Published: March 11, 2025, 6 a.m. ๐Ÿ”„ Last Modified: May 6, 2025, 4:06 p.m.
Total resulsts: 349182
Page 6393 of 34,919
ยซ previous page ยป next page
Filters