4.3

CVSS3.1

CVE-2025-1926 - Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.8 - Cross-Site Request Forgery (CSRF…

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.8. This is due to missing or incorrect nonce validation on the pagelayer_save_post function. This makes it possible for unauthentica…

πŸ“… Published: March 10, 2025, 4:21 a.m. πŸ”„ Last Modified: April 21, 2026, 10:15 p.m.

8.7

CVSS3.1

CVE-2024-41724 -

Improper Certificate Validation (CWE-295) in the Gallagher Command Centre SALTO integration allowed an attacker to spoof the SALTO server. This issue affects all versions of Gallagher Command Centre prior to 9.20.1043.

πŸ“… Published: March 10, 2025, 2:44 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2024-43107 -

Improper Certificate Validation (CWE-295) in the Gallagher Milestone Integration Plugin (MIP) permits unauthenticated messages (e.g. alarm events) to be sent to the Plugin. This issue effects Gallagher MIPS PluginΒ v4.0 prior to v4.0.32, all versions of v3.0 and prior.

πŸ“… Published: March 10, 2025, 2:44 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.6

CVSS3.1

CVE-2025-25616 -

Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows students to modify rules for exams. The affected endpoint is /exams/edit-rule?exam_rule_id=1.

πŸ“… Published: March 10, 2025, midnight πŸ”„ Last Modified: March 13, 2025, 6:04 p.m.

7.5

CVSS3.1

CVE-2025-25382 -

An issue in the Property Tax Payment Portal in Information Kerala Mission SANCHAYA v3.0.4 allows attackers to arbitrarily modify payment amounts via a crafted request.

πŸ“… Published: March 10, 2025, midnight πŸ”„ Last Modified: June 23, 2025, 7:49 p.m.

8.8

CVSS3.1

CVE-2025-25614 -

Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation, which allows teachers to update the personal data of fellow teachers.

πŸ“… Published: March 10, 2025, midnight πŸ”„ Last Modified: June 23, 2025, 6:35 p.m.

2.1

CVSS4.0

CVE-2025-27913 -

Passbolt API before 5, if the server is misconfigured (with an incorrect installation process and disregarding of Health Check results), can send email messages with a domain name taken from an attacker-controlled HTTP Host header.

πŸ“… Published: March 10, 2025, midnight πŸ”„ Last Modified: June 19, 2025, 12:14 a.m.

5.4

CVSS3.1

CVE-2025-25620 -

Unifiedtransform 2.0 is vulnerable to Cross Site Scripting (XSS) in the Create assignment function.

πŸ“… Published: March 10, 2025, midnight πŸ”„ Last Modified: June 23, 2025, 7:47 p.m.

6

CVSS3.1

CVE-2025-25615 -

Unifiedtransform 2.0 is vulnerable to Incorrect Access Control which allows viewing attendance list for all class sections.

πŸ“… Published: March 10, 2025, midnight πŸ”„ Last Modified: March 13, 2025, 6:01 p.m.

5.4

CVSS3.1

CVE-2024-53307 -

A reflected cross-site scripting (XSS) vulnerability in the /mw/ endpoint of Evisions MAPS v6.10.2.267 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.

πŸ“… Published: March 10, 2025, midnight πŸ”„ Last Modified: June 23, 2025, 8:08 p.m.
Total resulsts: 349182
Page 6406 of 34,919
Β« previous page Β» next page
Filters