6.1

CVSS3.1

CVE-2025-1511 - User Registration & Membership – Custom Registration Form, Login Form, and User Profile <= 4.0.4 - …

The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 4.0.4 due to insufficient input sanitization and output escaping. This makes i…

πŸ“… Published: Feb. 28, 2025, 5:23 a.m. πŸ”„ Last Modified: April 22, 2026, 6 p.m.

4.3

CVSS3.1

CVE-2025-0801 - RateMyAgent Official <= 1.4.0 - Cross-Site Request Forgery to API Key Update

The RateMyAgent Official plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.0. This is due to missing or incorrect nonce validation on the 'rma-settings-wizard'. This makes it possible for unauthenticated attackers to update the plugin's API k…

πŸ“… Published: Feb. 28, 2025, 4:21 a.m. πŸ”„ Last Modified: April 22, 2026, 7:15 a.m.

6.1

CVSS3.1

CVE-2025-1505 - Advanced AJAX Product Filters <= 1.6.8.1 - Reflected Cross-Site Scripting

The Advanced AJAX Product Filters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nonce' parameter in all versions up to, and including, 1.6.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject a…

πŸ“… Published: Feb. 28, 2025, 4:21 a.m. πŸ”„ Last Modified: April 22, 2026, 2:15 a.m.

6.4

CVSS3.1

CVE-2025-1757 - WordPress Portfolio Builder – Portfolio Gallery <= 1.1.7 - Authenticated (Contributor+) Stored Cros…

The WordPress Portfolio Builder – Portfolio Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pfhub_portfolio' and 'pfhub_portfolio_portfolio' shortcodes in all versions up to, and including, 1.1.7 due to insufficient input sanitization and output escaping …

πŸ“… Published: Feb. 28, 2025, 4:21 a.m. πŸ”„ Last Modified: April 21, 2026, 10:15 p.m.

5.3

CVSS3.1

CVE-2024-13796 - Post Grid and Gutenberg Blocks – ComboBlocks <= 2.3.6 - Unauthenticated User Information Exposure

The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.3.6 via the /wp-json/post-grid/v2/get_users REST API This makes it possible for unauthenticated attackers to extract sensitive data including…

πŸ“… Published: Feb. 28, 2025, 4:21 a.m. πŸ”„ Last Modified: April 8, 2026, 4:33 p.m.

10

CVSS4.0

CVE-2025-1744 - Out-of-bounds Write in radare2

Out-of-bounds Write vulnerability in radareorg radare2 allows heap-based buffer over-read or buffer overflow.This issue affects radare2: before <5.9.9.

πŸ“… Published: Feb. 28, 2025, 3:24 a.m. πŸ”„ Last Modified: July 1, 2025, 2:54 p.m.

6.5

CVSS3.1

CVE-2024-56340 - IBM Cognos Analytics path traversal

IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 is vulnerable to local file inclusion vulnerability, allowing an attacker to access sensitive files by inserting path traversal payloads inside the deficon parameter.

πŸ“… Published: Feb. 28, 2025, 2:32 a.m. πŸ”„ Last Modified: Oct. 17, 2025, 4:15 p.m.

6.5

CVSS3.1

CVE-2025-0823 - IBM MQ path traversal

IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 and 12.0.0 through 12.0.4 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.

πŸ“… Published: Feb. 28, 2025, 2:31 a.m. πŸ”„ Last Modified: July 2, 2025, 3:59 p.m.

6.5

CVSS3.1

CVE-2025-23225 - IBM MQ denial of service

IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user to cause a denial of service due to the improper handling of invalid headers sent to the queue.

πŸ“… Published: Feb. 28, 2025, 2:23 a.m. πŸ”„ Last Modified: July 3, 2025, 8:25 p.m.

4.7

CVSS3.1

CVE-2024-54173 - IBM MQ information disclosure

IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD reveals potentially sensitive information in trace files that could be read by a local user when webconsole trace is enabled.

πŸ“… Published: Feb. 28, 2025, 2:22 a.m. πŸ”„ Last Modified: July 3, 2025, 8:44 p.m.
Total resulsts: 349182
Page 6517 of 34,919
Β« previous page Β» next page
Filters