4.7

CVSS3.1

CVE-2020-6158 -

Opera Mini for Android before version 52.2 is vulnerable to an address bar spoofing attack. The vulnerability allows a malicious page to trick the browser into showing an address of a different page. This may allow the malicious page to impersonate another page and trick a user into providing sensiโ€ฆ

๐Ÿ“… Published: Feb. 21, 2025, 1:30 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-1535 - Baiyi Cloud Asset Management System admin.ticket.close.php sql injection

A vulnerability was found in Baiyi Cloud Asset Management System 8.142.100.161. It has been classified as critical. This affects an unknown part of the file /wuser/admin.ticket.close.php. The manipulation of the argument ticket_id leads to sql injection. It is possible to initiate the attack remoteโ€ฆ

๐Ÿ“… Published: Feb. 21, 2025, noon ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2024-9150 - Code Injection in Wyn Enterprise

Report generation functionality in Wyn Enterprise allows for code inclusion, but not sufficiently limits what code might be included. An attacker is able use a low privileges account in order to abuse this functionality and execute malicious code, load DLL libraries and executing OS commands on a hโ€ฆ

๐Ÿ“… Published: Feb. 21, 2025, 11:40 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.9

CVSS3.1

CVE-2024-13846 - Indeed Ultimate Learning Pro <= 3.9 - Authenticated (Administrator+) SQL Injection via post_id Paraโ€ฆ

The Indeed Ultimate Learning Pro plugin for WordPress is vulnerable to time-based SQL Injection via the โ€˜post_idโ€™ parameter in all versions up to, and including, 3.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makesโ€ฆ

๐Ÿ“… Published: Feb. 21, 2025, 11:09 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:30 p.m.

5.3

CVSS3.1

CVE-2025-1402 - Event Tickets and Registration <= 5.19.1.1 - Missing Authorization to Ticket Deletion

The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'ajax_ticket_delete' function in all versions up to, and including, 5.19.1.1. This makes it possible for authenticated attackers, with Contributor-level accessโ€ฆ

๐Ÿ“… Published: Feb. 21, 2025, 11:09 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 10:30 p.m.

6.4

CVSS3.1

CVE-2024-13455 - igumbi Online Booking <= 1.40 - Authenticated (Contributor+) Stored Cross-Site Scripting

The igumbi Online Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'igumbi_calendar' shortcode in all versions up to, and including, 1.40 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authโ€ฆ

๐Ÿ“… Published: Feb. 21, 2025, 11:09 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:16 p.m.

6.5

CVSS3.1

CVE-2024-13713 - WPExperts Square For GiveWP <= 1.3.1 - Authenticated (Subscriber+) SQL Injection

The WPExperts Square For GiveWP plugin for WordPress is vulnerable to SQL Injection via the 'post' parameter in all versions up to, and including, 1.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible โ€ฆ

๐Ÿ“… Published: Feb. 21, 2025, 11:09 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:01 p.m.

6.4

CVSS3.1

CVE-2025-1489 - WP-Appbox <= 4.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via appbox Shortcode

The WP-Appbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's appbox shortcode in all versions up to, and including, 4.5.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, wโ€ฆ

๐Ÿ“… Published: Feb. 21, 2025, 11:09 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 10:30 p.m.

4.1

CVSS3.1

CVE-2024-13900 - Head, Footer and Post Injections <= 3.3.0 - Authenticated (Administrator+) PHP Code Injection in Muโ€ฆ

The Head, Footer and Post Injections plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.3.0. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject PHP Code in multisite environments.

๐Ÿ“… Published: Feb. 21, 2025, 11:09 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:52 p.m.

7.1

CVSS4.0

CVE-2025-1471 - Eclipse OMR: Buffer overflow vulnerability

In Eclipse OMR versions 0.2.0 to 0.4.0, some of the z/OS atoe print functions use a constant length buffer for string conversion. If the input format string and arguments are larger than the buffer size then buffer overflow occurs. Beginning in version 0.5.0, the conversion buffers are sized correโ€ฆ

๐Ÿ“… Published: Feb. 21, 2025, 10:07 a.m. ๐Ÿ”„ Last Modified: March 5, 2025, 6:54 p.m.
Total resulsts: 349182
Page 6664 of 34,919
ยซ previous page ยป next page
Filters