4.3

CVSS3.1

CVE-2025-22220 - VMware Aria Operations for Logs broken access control vulnerability (CVE-2025-22220)

VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor with non-administrative privileges and network access to Aria Operations for Logs API may be able to perform certain operations in the context of an admin user.

📅 Published: Jan. 30, 2025, 3:28 p.m. 🔄 Last Modified: Feb. 26, 2026, 7:08 p.m.

6.8

CVSS3.1

CVE-2025-22219 - VMware Aria Operations for Logs stored cross-site scripting vulnerability (CVE-2025-22219)

VMware Aria Operations for Logs contains a stored cross-site scripting vulnerability. A malicious actor with non-administrative privileges may be able to inject a malicious script that (can perform stored cross-site scripting) may lead to arbitrary operations as admin user.

📅 Published: Jan. 30, 2025, 3:26 p.m. 🔄 Last Modified: May 14, 2025, 4:46 p.m.

5.3

CVSS4.0

CVE-2025-0871 - Maybecms Add Article index.php cross site scripting

A vulnerability classified as problematic has been found in Maybecms 1.2. This affects an unknown part of the file /mb/admin/index.php?u=article-edit of the component Add Article. The manipulation of the argument data_info[content] leads to cross site scripting. It is possible to initiate the attac…

📅 Published: Jan. 30, 2025, 2:31 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS3.1

CVE-2025-22218 - VMware Aria Operations for Logs information disclosure vulnerability

VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor with View Only Admin permissions may be able to read the credentials of a VMware product integrated with VMware Aria Operations for Logs

📅 Published: Jan. 30, 2025, 2:23 p.m. 🔄 Last Modified: May 14, 2025, 4:45 p.m.

6.4

CVSS3.1

CVE-2024-13349 - Stockdio Historical Chart <= 2.8.18 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Stockdio Historical Chart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'stockdio-historical-chart' shortcode in all versions up to, and including, 2.8.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it p…

📅 Published: Jan. 30, 2025, 1:42 p.m. 🔄 Last Modified: April 8, 2026, 7:20 p.m.

6.4

CVSS3.1

CVE-2024-13400 - Kona Gallery Block <= 1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Kona Gallery Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Kona: Instagram for Gutenberg" Block, specifically in the "align" attribute, in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping. This makes it possible…

📅 Published: Jan. 30, 2025, 1:42 p.m. 🔄 Last Modified: April 8, 2026, 5:30 p.m.

4.3

CVSS3.1

CVE-2024-12102 - Typer Core <= 1.9.6 - Authenticated (Contributor+) Post Disclosure

The Typer Core plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.6 via the 'elementor-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level ac…

📅 Published: Jan. 30, 2025, 1:42 p.m. 🔄 Last Modified: April 8, 2026, 5:28 p.m.

8.8

CVSS3.1

CVE-2024-10591 - MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytic…

The MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytics plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the hubwoo_save_updates() function in all versi…

📅 Published: Jan. 30, 2025, 1:42 p.m. 🔄 Last Modified: April 8, 2026, 7:19 p.m.

6.4

CVSS3.1

CVE-2024-10847 - Storely <= 18 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Storely theme for WordPress is vulnerable to Stored Cross-Site Scripting via a malicious display name in all versions up to, and including, 18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,…

📅 Published: Jan. 30, 2025, 1:42 p.m. 🔄 Last Modified: April 8, 2026, 7:19 p.m.

6.4

CVSS3.1

CVE-2024-13664 - WP Post List Table <= 1.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

The WP Post List Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpb_post_list_table' shortcode in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for au…

📅 Published: Jan. 30, 2025, 1:42 p.m. 🔄 Last Modified: April 8, 2026, 5:16 p.m.
Total resulsts: 349182
Page 6907 of 34,919
« previous page » next page
Filters