6.4

CVSS3.1

CVE-2025-2893 - Gutenverse <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via countdown Block

The Gutenverse – Ultimate Block Addons and Page Builder for Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's countdown Block in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping on user supplied attribut…

πŸ“… Published: April 29, 2025, 6:37 a.m. πŸ”„ Last Modified: April 29, 2025, 1:52 p.m.

3.5

CVSS3.1

CVE-2024-12273 - Calculated Fields Form < 5.2.62 - Admin+ Stored XSS

The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

πŸ“… Published: April 29, 2025, 6 a.m. πŸ”„ Last Modified: April 29, 2025, 9:05 p.m.

3.3

CVSS3.1

CVE-2025-46329 - Snowflake Connector for C/C++ inserts client-side encryption key in DEBUG logs

libsnowflakeclient is the Snowflake Connector for C/C++. Versions starting from 0.5.0 to before 2.2.0, are vulnerable to local logging of sensitive information. When the logging level was set to DEBUG, the Connector would log locally the client-side encryption master key of the target stage during …

πŸ“… Published: April 29, 2025, 4:35 a.m. πŸ”„ Last Modified: April 29, 2025, 1:52 p.m.

5

CVSS3.1

CVE-2025-46343 - n8n Vulnerable to Stored XSS through Attachments View Endpoint

n8n is a workflow automation platform. Prior to version 1.90.0, n8n is vulnerable to stored cross-site scripting (XSS) through the attachments view endpoint. n8n workflows can store and serve binary files, which are accessible to authenticated users. However, there is no restriction on the MIME typ…

πŸ“… Published: April 29, 2025, 4:35 a.m. πŸ”„ Last Modified: April 29, 2025, 1:52 p.m.

6.9

CVSS4.0

CVE-2025-46338 - Audiobookshelf Vulnerable to Cross-Site-Scripting Reflected via POST Request in /api/upload

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to version 2.21.0, an improper input handling vulnerability in the `/api/upload` endpoint allows an attacker to perform a reflected cross-site scripting (XSS) attack by submitting malicious payloads in the `libraryId` field. The un…

πŸ“… Published: April 29, 2025, 4:34 a.m. πŸ”„ Last Modified: April 29, 2025, 1:52 p.m.

3.3

CVSS3.1

CVE-2025-46330 - Snowflake Connector for C/C++ retries malformed requests

libsnowflakeclient is the Snowflake Connector for C/C++. Versions starting from 0.5.0 to before 2.2.0, incorrectly treat malformed requests that caused the HTTP response status code 400, as able to be retried. This could hang the application until SF_CON_MAX_RETRY requests were sent. This issue has…

πŸ“… Published: April 29, 2025, 4:34 a.m. πŸ”„ Last Modified: April 29, 2025, 1:52 p.m.

9.8

CVSS3.1

CVE-2025-24252 -

A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.4, tvOS 18.4, macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, visionOS 2.4. An attacker on the local network may be able to corrupt process memory.

πŸ“… Published: April 29, 2025, 2:05 a.m. πŸ”„ Last Modified: April 29, 2025, 8:10 p.m.

5.5

CVSS3.1

CVE-2025-31197 -

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, tvOS 18.4, macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, visionOS 2.4. An attacker on the local network may cause an unexpected app termination.

πŸ“… Published: April 29, 2025, 2:05 a.m. πŸ”„ Last Modified: April 29, 2025, 8:11 p.m.

5.5

CVSS3.1

CVE-2025-24179 -

A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.3 and iPadOS 18.3, visionOS 2.3, macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sonoma 14.7.5, macOS Sequoia 15.3, tvOS 18.3. An attacker on the local network may be able to cause a denial-of-service.

πŸ“… Published: April 29, 2025, 2:05 a.m. πŸ”„ Last Modified: April 29, 2025, 8:09 p.m.

5.5

CVSS3.1

CVE-2025-24270 -

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4, tvOS 18.4, macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, visionOS 2.4. An attacker on the local network may be able to leak sensitive user information.

πŸ“… Published: April 29, 2025, 2:05 a.m. πŸ”„ Last Modified: April 29, 2025, 8:11 p.m.
Total resulsts: 291774
Page 9 of 29,178
Β« previous page Β» next page
Filters