9.3

CVSS4.0

CVE-2025-22273 - Lack of rate-limiting in password change mechanism in CyberArk Endpoint Privilege Manager

Application does not limit the number or frequency of user interactions, such as the number of incoming requests. At the "/EPMUI/VfManager.asmx/ChangePassword" endpoint it is possible to perform a brute force attack on the current password in use. This issue affects CyberArk Endpoint Privilege Ma…

📅 Published: Feb. 28, 2025, 12:33 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

2.1

CVSS4.0

CVE-2025-22272 - Self Reflected XSS in CyberArk Endpoint Privilege Manager

In the "/EPMUI/ModalDlgHandler.ashx?value=showReadonlyDlg" endpoint, it is possible to inject code in the "modalDlgMsgInternal" parameter via POST, which is then executed in the browser. The risk of exploiting vulnerability is reduced due to the required additional bypassing the Content-Security-Po…

📅 Published: Feb. 28, 2025, 12:33 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-22271 - IP Spoofing in CyberArk Endpoint Privilege Manager

The application or its infrastructure allows for IP address spoofing by providing its own value in the "X-Forwarded-For" header. Thus, the action logging mechanism in the application loses accountability This issue affects CyberArk Endpoint Privilege Manager in SaaS version 24.7.1. The status of …

📅 Published: Feb. 28, 2025, 12:32 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS4.0

CVE-2025-22270 - Stored XSS in CyberArk Endpoint Privilege Manager

An attacker with access to the Administration panel, specifically the "Role Management" tab, can inject code by adding a new role in the "name" field. It should be noted, however, that the risk of exploiting vulnerability is reduced due to the required additional error that allows bypassing the Con…

📅 Published: Feb. 28, 2025, 12:32 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-10860 - NextMove Lite – Thank You Page for WooCommerce <= 2.19.0 - Missing Authorization to Authenticated (…

The NextMove Lite – Thank You Page for WooCommerce plugin for WordPress is vulnerable to unauthorized submission of data due to a missing capability check on the _submit_uninstall_reason_action() function in all versions up to, and including, 2.19.0. This makes it possible for authenticated attacke…

📅 Published: Feb. 28, 2025, 9:22 a.m. 🔄 Last Modified: April 8, 2026, 4:55 p.m.

6.3

CVSS3.1

CVE-2025-22492 - Insecure storage of connection strings in FRS

The connection string visible to users with access to FRSCore database on Foreseer Reporting Software (FRS) VM, this string can be used for gaining administrative access to the 4crXref database. This vulnerability has been resolved in the latest version 1.5.100 of FRS.

📅 Published: Feb. 28, 2025, 8:29 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.4

CVSS4.0

CVE-2025-1413 - Dylib Hijacking in DaVinci Resolve

DaVinci Resolve on MacOS was found to be installed with incorrect file permissions (rwxrwxrwx). This is inconsistent with standard macOS security practices, where applications should have drwxr-xr-x permissions. Incorrect permissions allow for Dylib Hijacking. Guest account, other users and applica…

📅 Published: Feb. 28, 2025, 8:25 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.7

CVSS3.1

CVE-2025-22491 - Improper Input Validation in Foreseer Reporting Software (FRS)

The user input was not sanitized on Reporting Hierarchy Management page of Foreseer Reporting Software (FRS) application which could lead into execution of arbitrary JavaScript in a browser context for all the interacting users. This security issue has been patched in the latest version 1.5.100 of …

📅 Published: Feb. 28, 2025, 8:24 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-8420 - DHVC Form <= 2.4.7 - Unauthenticated Privilege Escalation

The DHVC Form plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.7. This is due to the plugin allowing a user to supply the 'role' field when registering. This makes it possible for unauthenticated attackers to register as an administrator on sites.

📅 Published: Feb. 28, 2025, 8:23 a.m. 🔄 Last Modified: April 8, 2026, 5:29 p.m.

5.5

CVSS3.1

CVE-2024-13851 - Modal Portfolio <= 1.7.4.2 - Authenticated (Administrator+) Stored Cross-Site Scripting

The Modal Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.7.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject ar…

📅 Published: Feb. 28, 2025, 8:23 a.m. 🔄 Last Modified: April 8, 2026, 5:27 p.m.
Total resulsts: 349182
Page 6514 of 34,919
« previous page » next page
Filters