7.6

CVSS3.1

CVE-2024-7872 - Sensetive Data Exposure in ExtremePACS' Extreme XDS

Insertion of Sensitive Information Into Sent Data vulnerability in ExtremePACS Extreme XDS allows Retrieve Embedded Sensitive Data.This issue affects Extreme XDS: before 3933.

๐Ÿ“… Published: March 6, 2025, 11:14 a.m. ๐Ÿ”„ Last Modified: July 12, 2025, 10:09 p.m.

4.3

CVSS3.1

CVE-2025-1666 - Cookie banner plugin for WordPress โ€“ Cookiebot CMP by Usercentrics <= 4.4.1 - Missing Authorizationโ€ฆ

The Cookie banner plugin for WordPress โ€“ Cookiebot CMP by Usercentrics plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the send_uninstall_survey() function in all versions up to, and including, 4.4.1. This makes it possible for authenticaโ€ฆ

๐Ÿ“… Published: March 6, 2025, 11:11 a.m. ๐Ÿ”„ Last Modified: April 20, 2026, 11:45 p.m.

4.3

CVSS3.1

CVE-2025-1383 - Podlove Podcast Publisher <= 4.2.2 - Cross-Site Request Forgery via ajax_transcript_delete Function

The Podlove Podcast Publisher plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.2. This is due to missing or incorrect nonce validation on the ajax_transcript_delete() function. This makes it possible for unauthenticated attackers to delete aโ€ฆ

๐Ÿ“… Published: March 6, 2025, 11:11 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 6 p.m.

4.3

CVSS3.1

CVE-2024-56202 - Apache Traffic Server: Expect header field can unreasonably retain resource

Expected Behavior Violation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are recommended to upgrade to versions 9.2.9 or 10.0.4 or newer, which fixes the issue.

๐Ÿ“… Published: March 6, 2025, 11:09 a.m. ๐Ÿ”„ Last Modified: April 29, 2025, 4:41 p.m.

4.8

CVSS4.0

CVE-2024-13902 - huang-yk student-manage Edit a Student Information Page cross site scripting

A vulnerability, which was classified as problematic, was found in huang-yk student-manage 1.0. This affects an unknown part of the component Edit a Student Information Page. The manipulation of the argument Class leads to cross site scripting. It is possible to initiate the attack remotely. The exโ€ฆ

๐Ÿ“… Published: March 6, 2025, 10 a.m. ๐Ÿ”„ Last Modified: Oct. 15, 2025, 8:44 p.m.

5.5

CVSS3.1

CVE-2025-1672 - Notibar <= 2.1.5 - Authenticated (Administrator+) Stored Cross-Site Scripting

The Notibar โ€“ Notification Bar for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administโ€ฆ

๐Ÿ“… Published: March 6, 2025, 9:21 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 10:15 p.m.

3.1

CVSS3.1

CVE-2025-1540 - Incorrect Authorization in GitLab

An issue has been discovered in GitLab CE/EE for Self-Managed and Dedicated instances affecting all versions from 17.5 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2. It was possible for a user added as an External to read and clone internal projects under certain circumstances."

๐Ÿ“… Published: March 6, 2025, 8:31 a.m. ๐Ÿ”„ Last Modified: Aug. 6, 2025, 6:33 p.m.

6.5

CVSS3.1

CVE-2024-13897 - Moving Media Library <= 1.22 - Authenticated (Administrator+) Directory Traversal to Arbitrary Fileโ€ฆ

The Moving Media Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the generate_json_page function in all versions up to, and including, 1.22. This makes it possible for authenticated attackers, with Administrator-level access and abovโ€ฆ

๐Ÿ“… Published: March 6, 2025, 8:21 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-13868 - Easy Broken Link Checker <= 9.0.2 - Reflected XSS

The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

๐Ÿ“… Published: March 6, 2025, 6 a.m. ๐Ÿ”„ Last Modified: May 21, 2025, 3:28 p.m.

5.1

CVSS4.0

CVE-2025-22623 - Ad Inserter - Reflected cross-site scripting (XSS)

Ad Inserter - Ad Manager and AdSense Ads 2.8.0 was found to be vulnerable. The web application dynamically generates web content without validating the source of the potentially untrusted data in myapp/includes/dst/dst.php.

๐Ÿ“… Published: March 6, 2025, 5:08 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 6431 of 34,919
ยซ previous page ยป next page
Filters