7.1

CVSS3.1

CVE-2025-22795 - WordPress Multilang Contact Form Plugin <= 1.5 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in digitaldonkey Multilang Contact Form multilang-contact-form allows Reflected XSS.This issue affects Multilang Contact Form: from n/a through <= 1.5.

πŸ“… Published: Jan. 15, 2025, 3:23 p.m. πŸ”„ Last Modified: April 23, 2026, 3:23 p.m.

6.5

CVSS3.1

CVE-2025-22797 - WordPress Gallery and Lightbox plugin <= 1.0.14 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oğulcan Γ–zΓΌgenΓ§ Gallery and Lightbox gallery-and-lightbox allows Stored XSS.This issue affects Gallery and Lightbox: from n/a through <= 1.0.14.

πŸ“… Published: Jan. 15, 2025, 3:23 p.m. πŸ”„ Last Modified: April 23, 2026, 3:23 p.m.

6.5

CVSS3.1

CVE-2025-22798 - WordPress Responsive jQuery Slider plugin <= 1.1.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CHR Designer Responsive jQuery Slider responsive-jquery-slider allows Stored XSS.This issue affects Responsive jQuery Slider: from n/a through <= 1.1.1.

πŸ“… Published: Jan. 15, 2025, 3:23 p.m. πŸ”„ Last Modified: April 23, 2026, 3:23 p.m.

8.5

CVSS3.1

CVE-2025-22799 - WordPress Neon Product Designer Plugin <= 2.2.0 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in vertim Neon Product Designer neon-product-designer-for-woocommerce allows SQL Injection.This issue affects Neon Product Designer: from n/a through <= 2.2.0.

πŸ“… Published: Jan. 15, 2025, 3:23 p.m. πŸ”„ Last Modified: April 23, 2026, 3:23 p.m.

8.7

CVSS3.1

CVE-2024-47140 -

A cross-site scripting (xss) vulnerability exists in the add_alert_check page of Observium CE 24.4.13528. A specially crafted HTTP request can lead to a arbitrary javascript code execution. An authenticated user would need to click a malicious link provided by the attacker.

πŸ“… Published: Jan. 15, 2025, 2:59 p.m. πŸ”„ Last Modified: Aug. 22, 2025, 4:19 p.m.

8.7

CVSS3.1

CVE-2024-47002 -

A html code injection vulnerability exists in the vlan management part of Observium CE 24.4.13528. A specially crafted HTTP request can lead to an arbitrary html code. An authenticated user would need to click a malicious link provided by the attacker.

πŸ“… Published: Jan. 15, 2025, 2:59 p.m. πŸ”„ Last Modified: Aug. 22, 2025, 4:22 p.m.

8.7

CVSS3.1

CVE-2024-45061 -

A cross-site scripting (xss) vulnerability exists in the weather map editor functionality of Observium CE 24.4.13528. A specially crafted HTTP request can lead to a arbitrary javascript code execution. An authenticated user would need to click a malicious link provided by the attacker.

πŸ“… Published: Jan. 15, 2025, 2:59 p.m. πŸ”„ Last Modified: Aug. 22, 2025, 4:25 p.m.

7.5

CVSS3.1

CVE-2024-11322 - CyberPower PowerPanel Business Unauthenticated Restart DoS

A denial-of-service vulnerability exists in CyberPower PowerPanel Business (PPB) 4.11.0. An unauthenticated remote attacker can restart the ppbd.exe process via the PowerPanel Business Service Watchdog service listening on TCP port 2003. The attacker can repeatedly restart ppbd.exe to render it un…

πŸ“… Published: Jan. 15, 2025, 2:03 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.3

CVSS3.1

CVE-2024-5198 -

OpenVPN ovpn-dco for Windows version 1.1.1 allows an unprivileged local attacker to send I/O control messages with invalid data to the driver resulting in a NULL pointer dereference leading to a system halt.

πŸ“… Published: Jan. 15, 2025, 12:57 p.m. πŸ”„ Last Modified: June 10, 2025, 4:12 p.m.

4.3

CVSS3.1

CVE-2024-13215 - Elementor Addon Elements <= 1.13.10 - Authenticated (Contributor+) Sensitive Information Exposure v…

The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.10 via the 'render' function in modules/modal-popup/widgets/modal-popup.php. This makes it possible for authenticated attackers, with Contributor-level access…

πŸ“… Published: Jan. 15, 2025, 12:44 p.m. πŸ”„ Last Modified: April 8, 2026, 4:52 p.m.
Total resulsts: 347946
Page 6980 of 34,795
Β« previous page Β» next page
Filters