8.8

CVSS3.1

CVE-2025-0762 -

Use after free in DevTools in Google Chrome prior to 132.0.6834.159 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Medium)

πŸ“… Published: Jan. 29, 2025, 10:33 a.m. πŸ”„ Last Modified: April 21, 2025, 8:53 p.m.

5.9

CVSS3.1

CVE-2025-0617 -

An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to the HX console. The malicious detection would then trigger file parsing containing exponential entity expansions in the consumer process thus causing a Denial of Service.

πŸ“… Published: Jan. 29, 2025, 10:08 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2021-3978 - Improper Preservation of Permissions in github.com/cloudflare/cfrpki/cmd/octorpki

When copying files with rsync, octorpki uses the "-a" flag 0, which forces rsync to copy binaries with the suid bit set as root. Since the provided service definition defaults to root ( https://github.com/cloudflare/cfrpki/blob/master/package/octorpki.service ) this could allow for a vector, when c…

πŸ“… Published: Jan. 29, 2025, 10 a.m. πŸ”„ Last Modified: July 29, 2025, 11:40 p.m.

8.7

CVSS4.0

CVE-2024-7695 - Out-of-bounds Write Vulnerability

Multiple switches are affected by an out-of-bounds write vulnerability. This vulnerability is caused by insufficient input validation, which allows data to be written to memory outside the bounds of the buffer. Successful exploitation of this vulnerability could result in a denial-of-service attack.

πŸ“… Published: Jan. 29, 2025, 7:42 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2024-13696 - Flexible Wishlist for WooCommerce <= 1.2.25 - Unauthenticated Stored Cross-Site Scripting via wishl…

The Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜wishlist_name’ parameter in all versions up to, and including, 1.2.25 due to insufficient input sanitization and output escaping. This makes it poss…

πŸ“… Published: Jan. 29, 2025, 7:21 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS3.1

CVE-2024-12749 - Competition Form <= 2.0 - Reflected XSS

The Competition Form WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

πŸ“… Published: Jan. 29, 2025, 6 a.m. πŸ”„ Last Modified: May 11, 2025, 11:34 p.m.

6.4

CVSS3.1

CVE-2025-0804 - ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages <= 2.4…

The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via link titles in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. This makes it po…

πŸ“… Published: Jan. 29, 2025, 3:21 a.m. πŸ”„ Last Modified: April 21, 2026, 10:30 p.m.

6.9

CVSS4.0

CVE-2025-0806 - code-projects Job Recruitment _call_job_search_ajax.php cross site scripting

A vulnerability was found in code-projects Job Recruitment 1.0. It has been rated as problematic. This issue affects some unknown processing of the file _call_job_search_ajax.php. The manipulation of the argument job_type leads to cross site scripting. The attack may be initiated remotely. The expl…

πŸ“… Published: Jan. 29, 2025, 2:31 a.m. πŸ”„ Last Modified: Feb. 12, 2025, 7:51 p.m.

6.9

CVSS4.0

CVE-2025-0803 - Codezips Gym Management System submit_plan_new.php sql injection

A vulnerability, which was classified as critical, has been found in Codezips Gym Management System 1.0. Affected by this issue is some unknown functionality of the file /dashboard/admin/submit_plan_new.php. The manipulation of the argument planid leads to sql injection. The attack may be launched …

πŸ“… Published: Jan. 29, 2025, 2 a.m. πŸ”„ Last Modified: Feb. 12, 2025, 7:51 p.m.

6.9

CVSS4.0

CVE-2025-0802 - SourceCodester Best Employee Management System Administrative Endpoint View_user.php access control

A vulnerability classified as critical was found in SourceCodester Best Employee Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/View_user.php of the component Administrative Endpoint. The manipulation leads to improper access controls. The attac…

πŸ“… Published: Jan. 29, 2025, 2 a.m. πŸ”„ Last Modified: Feb. 12, 2025, 7:51 p.m.
Total resulsts: 349182
Page 6919 of 34,919
Β« previous page Β» next page
Filters