7.6
CVE-2024-7872 - Sensetive Data Exposure in ExtremePACS' Extreme XDS
Insertion of Sensitive Information Into Sent Data vulnerability in ExtremePACS Extreme XDS allows Retrieve Embedded Sensitive Data.This issue affects Extreme XDS: before 3933.
4.3
CVE-2025-1666 - Cookie banner plugin for WordPress โ Cookiebot CMP by Usercentrics <= 4.4.1 - Missing Authorizationโฆ
The Cookie banner plugin for WordPress โ Cookiebot CMP by Usercentrics plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the send_uninstall_survey() function in all versions up to, and including, 4.4.1. This makes it possible for authenticaโฆ
4.3
CVE-2025-1383 - Podlove Podcast Publisher <= 4.2.2 - Cross-Site Request Forgery via ajax_transcript_delete Function
The Podlove Podcast Publisher plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.2. This is due to missing or incorrect nonce validation on the ajax_transcript_delete() function. This makes it possible for unauthenticated attackers to delete aโฆ
4.3
CVE-2024-56202 - Apache Traffic Server: Expect header field can unreasonably retain resource
Expected Behavior Violation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are recommended to upgrade to versions 9.2.9 or 10.0.4 or newer, which fixes the issue.
4.8
CVE-2024-13902 - huang-yk student-manage Edit a Student Information Page cross site scripting
A vulnerability, which was classified as problematic, was found in huang-yk student-manage 1.0. This affects an unknown part of the component Edit a Student Information Page. The manipulation of the argument Class leads to cross site scripting. It is possible to initiate the attack remotely. The exโฆ
5.5
CVE-2025-1672 - Notibar <= 2.1.5 - Authenticated (Administrator+) Stored Cross-Site Scripting
The Notibar โ Notification Bar for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administโฆ
3.1
CVE-2025-1540 - Incorrect Authorization in GitLab
An issue has been discovered in GitLab CE/EE for Self-Managed and Dedicated instances affecting all versions from 17.5 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2. It was possible for a user added as an External to read and clone internal projects under certain circumstances."
6.5
CVE-2024-13897 - Moving Media Library <= 1.22 - Authenticated (Administrator+) Directory Traversal to Arbitrary Fileโฆ
The Moving Media Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the generate_json_page function in all versions up to, and including, 1.22. This makes it possible for authenticated attackers, with Administrator-level access and abovโฆ
6.1
CVE-2024-13868 - Easy Broken Link Checker <= 9.0.2 - Reflected XSS
The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
5.1
CVE-2025-22623 - Ad Inserter - Reflected cross-site scripting (XSS)
Ad Inserter - Ad Manager and AdSense Ads 2.8.0 was found to be vulnerable. The web application dynamically generates web content without validating the source of the potentially untrusted data in myapp/includes/dst/dst.php.