6.4

CVSS3.1

CVE-2024-13443 - Easypromos Plugin <= 1.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Easypromos Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Easypromos shortcode in all versions up to, and including, 1.3.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated โ€ฆ

๐Ÿ“… Published: Feb. 19, 2025, 3:21 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2024-11582 - Subscribe2 โ€“ Form, Email Subscribers & Newsletters <= 10.43 - Unauthenticated Stored Cross-Site Scrโ€ฆ

The Subscribe2 โ€“ Form, Email Subscribers & Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ip parameter in all versions up to, and including, 10.43 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers โ€ฆ

๐Ÿ“… Published: Feb. 19, 2025, 3:21 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-1448 - Synway SMG Gateway Management Software 9-12ping.php command injection

A vulnerability was found in Synway SMG Gateway Management Software up to 20250204. It has been rated as critical. This issue affects some unknown processing of the file 9-12ping.php. The manipulation of the argument retry leads to command injection. The attack may be initiated remotely. The exploiโ€ฆ

๐Ÿ“… Published: Feb. 19, 2025, 1:31 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-1447 - kasuganosoras Pigeon index.php server-side request forgery

A vulnerability was found in kasuganosoras Pigeon 1.0.177. It has been declared as critical. This vulnerability affects unknown code of the file /pigeon/imgproxy/index.php. The manipulation of the argument url leads to server-side request forgery. The attack can be initiated remotely. Upgrading to โ€ฆ

๐Ÿ“… Published: Feb. 19, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2023-51297 -

A lack of rate limiting in the 'Email Settings' feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.

๐Ÿ“… Published: Feb. 19, 2025, midnight ๐Ÿ”„ Last Modified: April 22, 2025, 8:03 p.m.

7.5

CVSS3.1

CVE-2023-51293 -

A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Event Booking Calendar v4.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.

๐Ÿ“… Published: Feb. 19, 2025, midnight ๐Ÿ”„ Last Modified: May 20, 2025, 2:35 p.m.

6.1

CVSS3.1

CVE-2023-51299 -

PHPJabbers Hotel Booking System v4.0 is vulnerable to HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters.

๐Ÿ“… Published: Feb. 19, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 4, 2025, 7:16 p.m.

4.7

CVSS3.1

CVE-2023-51298 -

PHPJabbers Event Booking Calendar v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.

๐Ÿ“… Published: Feb. 19, 2025, midnight ๐Ÿ”„ Last Modified: April 22, 2025, 8:01 p.m.

6.5

CVSS3.1

CVE-2025-25945 -

An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the Mp4Fragment.cpp and in AP4_DescriptorFactory::CreateDescriptorFromStream at Ap4DescriptorFactory.cpp.

๐Ÿ“… Published: Feb. 19, 2025, midnight ๐Ÿ”„ Last Modified: May 13, 2025, 2:02 p.m.

7.3

CVSS3.1

CVE-2025-25944 -

Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the Ap4RtpAtom.cpp, specifically in AP4_RtpAtom::AP4_RtpAtom, during the execution of mp4fragment with a crafted MP4 input file.

๐Ÿ“… Published: Feb. 19, 2025, midnight ๐Ÿ”„ Last Modified: May 13, 2025, 2:02 p.m.
Total resulsts: 349182
Page 6691 of 34,919
ยซ previous page ยป next page
Filters