6.1

CVSS3.1

CVE-2024-13327 - Musicbox <= 2.0.3 - Reflected XSS

The Musicbox WordPress plugin through 2.0.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

๐Ÿ“… Published: Feb. 4, 2025, 6 a.m. ๐Ÿ”„ Last Modified: May 7, 2025, 5:49 p.m.

6.1

CVSS3.1

CVE-2024-13326 - iBuildApp <= 0.2.0 - Reflected XSS

The iBuildApp WordPress plugin through 0.2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

๐Ÿ“… Published: Feb. 4, 2025, 6 a.m. ๐Ÿ”„ Last Modified: May 7, 2025, 7:16 p.m.

6.1

CVSS3.1

CVE-2024-13325 - Glossy <= 2.3.5 - Reflected XSS

The Glossy WordPress plugin through 2.3.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

๐Ÿ“… Published: Feb. 4, 2025, 6 a.m. ๐Ÿ”„ Last Modified: July 25, 2025, 4:21 p.m.

6.1

CVSS3.1

CVE-2024-13115 - WP Projects Portfolio with Client Testimonials <= 3.0 - Stored XSS via CSRF

The WP Projects Portfolio with Client Testimonials WordPress plugin through 3.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

๐Ÿ“… Published: Feb. 4, 2025, 6 a.m. ๐Ÿ”„ Last Modified: May 7, 2025, 6:39 p.m.

6.1

CVSS3.1

CVE-2024-13114 - WP Projects Portfolio with Client Testimonials <= 3.0 - Reflected XSS

The WP Projects Portfolio with Client Testimonials WordPress plugin through 3.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

๐Ÿ“… Published: Feb. 4, 2025, 6 a.m. ๐Ÿ”„ Last Modified: May 7, 2025, 6:39 p.m.

4.3

CVSS3.0

CVE-2025-24982 -

Cross-site request forgery vulnerability exists in Activity Log WinterLock versions prior to 1.2.5. If a user views a malicious page while logged in, the log data may be deleted.

๐Ÿ“… Published: Feb. 4, 2025, 4:18 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2025-25049 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

๐Ÿ“… Published: Feb. 4, 2025, 4 a.m. ๐Ÿ”„ Last Modified: Feb. 13, 2026, 6:11 p.m.

0.0

CVE-2025-24492 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

๐Ÿ“… Published: Feb. 4, 2025, 4 a.m. ๐Ÿ”„ Last Modified: Feb. 13, 2026, 6:11 p.m.

0.0

CVE-2025-24321 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

๐Ÿ“… Published: Feb. 4, 2025, 4 a.m. ๐Ÿ”„ Last Modified: Feb. 13, 2026, 6:11 p.m.

3.7

CVSS3.1

CVE-2025-22475 -

Dell PowerProtect DD, versions prior to DDOS 8.3.0.0, 7.10.1.50, and 7.13.1.10 contains a use of a Cryptographic Primitive with a Risky Implementation vulnerability. A remote attacker could potentially exploit this vulnerability, leading to Information tampering.

๐Ÿ“… Published: Feb. 4, 2025, 2:19 a.m. ๐Ÿ”„ Last Modified: Feb. 7, 2025, 8:42 p.m.
Total resulsts: 349182
Page 6861 of 34,919
ยซ previous page ยป next page
Filters