0.0

CVE-2025-46779 -

Not used

πŸ“… Published: April 29, 2025, 8:42 a.m. πŸ”„ Last Modified: April 30, 2025, 3:15 a.m.

0.0

CVE-2025-46782 -

Not used

πŸ“… Published: April 29, 2025, 8:42 a.m. πŸ”„ Last Modified: April 30, 2025, 3:15 a.m.

0.0

CVE-2025-46781 -

Not used

πŸ“… Published: April 29, 2025, 8:42 a.m. πŸ”„ Last Modified: April 30, 2025, 3:15 a.m.

0.0

CVE-2025-46780 -

Not used

πŸ“… Published: April 29, 2025, 8:42 a.m. πŸ”„ Last Modified: April 30, 2025, 3:15 a.m.

0.0

CVE-2025-46778 -

Not used

πŸ“… Published: April 29, 2025, 8:42 a.m. πŸ”„ Last Modified: April 30, 2025, 3:15 a.m.

4.3

CVSS3.1

CVE-2025-3452 - SecuPress Free <= 2.3.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Ins…

The SecuPress Free β€” WordPress Security plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'secupress_reinstall_plugins_admin_ajax_cb' function in all versions up to, and including, 2.3.9. This makes it possible for authenticated attacke…

πŸ“… Published: April 29, 2025, 8:21 a.m. πŸ”„ Last Modified: April 29, 2025, 1:52 p.m.

6.4

CVSS3.1

CVE-2025-2893 - Gutenverse <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via countdown Block

The Gutenverse – Ultimate Block Addons and Page Builder for Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's countdown Block in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping on user supplied attribut…

πŸ“… Published: April 29, 2025, 6:37 a.m. πŸ”„ Last Modified: April 29, 2025, 1:52 p.m.

3.5

CVSS3.1

CVE-2024-12273 - Calculated Fields Form < 5.2.62 - Admin+ Stored XSS

The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

πŸ“… Published: April 29, 2025, 6 a.m. πŸ”„ Last Modified: April 29, 2025, 9:05 p.m.

3.3

CVSS3.1

CVE-2025-46329 - Snowflake Connector for C/C++ inserts client-side encryption key in DEBUG logs

libsnowflakeclient is the Snowflake Connector for C/C++. Versions starting from 0.5.0 to before 2.2.0, are vulnerable to local logging of sensitive information. When the logging level was set to DEBUG, the Connector would log locally the client-side encryption master key of the target stage during …

πŸ“… Published: April 29, 2025, 4:35 a.m. πŸ”„ Last Modified: April 29, 2025, 1:52 p.m.

5

CVSS3.1

CVE-2025-46343 - n8n Vulnerable to Stored XSS through Attachments View Endpoint

n8n is a workflow automation platform. Prior to version 1.90.0, n8n is vulnerable to stored cross-site scripting (XSS) through the attachments view endpoint. n8n workflows can store and serve binary files, which are accessible to authenticated users. However, there is no restriction on the MIME typ…

πŸ“… Published: April 29, 2025, 4:35 a.m. πŸ”„ Last Modified: April 29, 2025, 1:52 p.m.
Total resulsts: 291780
Page 9 of 29,178
Β« previous page Β» next page
Filters