5.4

CVSS3.1

CVE-2025-24533 - WordPress MetaSlider plugin <= 3.92.0 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in MetaSlider Responsive Slider by MetaSlider ml-slider allows Cross Site Request Forgery.This issue affects Responsive Slider by MetaSlider: from n/a through <= 3.92.0.

📅 Published: Jan. 27, 2025, 1:59 p.m. 🔄 Last Modified: April 23, 2026, 3:24 p.m.

7.1

CVSS3.1

CVE-2025-23792 - WordPress Passwordless WP – Login with your glance or fingerprint Plugin <= 1.1.6 - Reflected Cross…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Busters Passwordless WP – Login with your glance or fingerprint passwordless-wp allows Reflected XSS.This issue affects Passwordless WP – Login with your glance or fingerprint: from n/a through …

📅 Published: Jan. 27, 2025, 1:59 p.m. 🔄 Last Modified: April 23, 2026, 3:24 p.m.

7.1

CVSS3.1

CVE-2025-23457 - WordPress Shipdeo plugin <= 1.2.8 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shipdeoplugin Shipdeo shipdeo-woo allows Reflected XSS.This issue affects Shipdeo: from n/a through <= 1.2.8.

📅 Published: Jan. 27, 2025, 1:59 p.m. 🔄 Last Modified: April 23, 2026, 3:23 p.m.

5.3

CVSS4.0

CVE-2024-11348 - Reflected XSS in Eura7 CMSmanager

Eura7 CMSmanager in version 4.6 and below is vulnerable to Reflected XSS attacks through manipulation of return GET request parameter sent to a specific endpoint. The vulnerability has been fixed by a patche patch 17012022 addressing all affected versions in use.

📅 Published: Jan. 27, 2025, 1:16 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-55931 - Token stored in session storage

Xerox Workplace Suite stores tokens in session storage, which may expose them to potential access if a user's session is compromised.  The patch for this vulnerability will be included in a future release of Workplace Suite, and customers will be notified through an update to the security bulletin.

📅 Published: Jan. 27, 2025, 11:28 a.m. 🔄 Last Modified: Jan. 30, 2026, 9:30 p.m.

5.3

CVSS3.1

CVE-2025-0696 -

A NULL Pointer Dereference vulnerability in Cesanta Frozen versions less than 1.7 allows an attacker to induce a crash of the component embedding the library by supplying a maliciously crafted JSON as input.

📅 Published: Jan. 27, 2025, 11:12 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-0695 -

An Allocation of Resources Without Limits or Throttling vulnerability in Cesanta Frozen versions less than 1.7 allows an attacker to induce a crash of the component embedding the library by supplying a maliciously crafted JSON as input.

📅 Published: Jan. 27, 2025, 11:11 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.7

CVSS4.0

CVE-2024-12345 - INW Krbyyyzo Daily Huddle Site gbo.aspx resource consumption

A vulnerability classified as problematic was found in INW Krbyyyzo 25.2002. Affected by this vulnerability is an unknown functionality of the file /gbo.aspx of the component Daily Huddle Site. The manipulation of the argument s leads to resource consumption. It is possible to launch the attack on …

📅 Published: Jan. 27, 2025, 11 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-24814 - Apache Solr: Core-creation with "trusted" configset can use arbitrary untrusted files

Core creation allows users to replace "trusted" configset files with arbitrary configuration Solr instances that (1) use the "FileSystemConfigSetService" component (the default in "standalone" or "user-managed" mode), and (2) are running without authentication and authorization are vulnerable to a…

📅 Published: Jan. 27, 2025, 8:58 a.m. 🔄 Last Modified: June 25, 2025, 4:41 p.m.

5.4

CVSS3.1

CVE-2024-52012 - Apache Solr: Configset upload on Windows allows arbitrary path write-access

Relative Path Traversal vulnerability in Apache Solr. Solr instances running on Windows are vulnerable to arbitrary filepath write-access, due to a lack of input-sanitation in the "configset upload" API.  Commonly known as a "zipslip", maliciously constructed ZIP files can use relative filepaths t…

📅 Published: Jan. 27, 2025, 8:54 a.m. 🔄 Last Modified: June 27, 2025, 7:32 p.m.
Total resulsts: 349182
Page 6949 of 34,919
« previous page » next page
Filters