7.3

CVSS4.0

CVE-2025-25175 -

A vulnerability has been identified in Simcenter Femap V2401 (All versions < V2401.0003), Simcenter Femap V2406 (All versions < V2406.0002). The affected application contains a memory corruption vulnerability while parsing specially crafted .NEU files. This could allow an attacker to execute code …

πŸ“… Published: March 13, 2025, 9:07 a.m. πŸ”„ Last Modified: March 13, 2025, 9:15 a.m.

5.4

CVSS3.1

CVE-2025-1785 - Download Manager <= 3.3.08 - Authenticated (Author+) Path Traversal to Limited File Overwrite

The Download Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.08 via the 'wpdm_newfile' action. This makes it possible for authenticated attackers, with Author-level access and above, to overwrite select file types outside of the originally…

πŸ“… Published: March 13, 2025, 7:31 a.m. πŸ”„ Last Modified: March 13, 2025, 8:15 a.m.

7.3

CVSS3.1

CVE-2025-1119 - Appointment Booking Calendar β€” Simply Schedule Appointments Booking Plugin <= 1.6.8.5 - Unauthentic…

The Appointment Booking Calendar β€” Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.6.8.5. This is due to the software allowing users to execute an action that does not properly validate a value b…

πŸ“… Published: March 13, 2025, 6:56 a.m. πŸ”„ Last Modified: March 13, 2025, 7:15 a.m.

7.7

CVSS3.1

CVE-2025-2271 - IDOR in Issuetrak NewAuditID parameter via Inv_PopTrakXShow.asp

A vulnerability exists in Issuetrak v17.2.2 and prior that allows a low-privileged user to access audit results of other users by exploiting an Insecure Direct Object Reference (IDOR) vulnerability in the Issuetrak audit component. The vulnerability enables unauthorized access to sensitive informat…

πŸ“… Published: March 13, 2025, 6:30 a.m. πŸ”„ Last Modified: March 13, 2025, 7:15 a.m.

2.7

CVSS3.1

CVE-2024-7296 - Incorrect Authorization in GitLab

An issue was discovered in GitLab EE affecting all versions from 16.5 prior to 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2 which allowed a user with a custom permission to approve pending membership requests beyond the maximum number of allowed users.

πŸ“… Published: March 13, 2025, 6 a.m. πŸ”„ Last Modified: March 13, 2025, 6:15 a.m.

6.5

CVSS3.1

CVE-2025-1257 - Allocation of Resources Without Limits or Throttling in GitLab

An issue was discovered in GitLab EE affecting all versions starting with 12.3 before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. A vulnerability in certain GitLab instances could allow an attacker to cause a denial of service condition by manipulating specific API inputs.

πŸ“… Published: March 13, 2025, 6 a.m. πŸ”„ Last Modified: March 13, 2025, 6:15 a.m.

0.0

CVE-2025-1487 - WoWPth <= 2.0 - Reflected XSS

The WoWPth WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

πŸ“… Published: March 13, 2025, 6 a.m. πŸ”„ Last Modified: March 13, 2025, 6:15 a.m.

0.0

CVE-2025-1486 - WoWPth <= 2.0 - Reflected XSS

The WoWPth WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

πŸ“… Published: March 13, 2025, 6 a.m. πŸ”„ Last Modified: March 13, 2025, 6:15 a.m.

0.0

CVE-2025-1436 - Limit Bio <= 1.0 - Stored XSS via CSRF

The Limit Bio WordPress plugin through 1.0 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

πŸ“… Published: March 13, 2025, 6 a.m. πŸ”„ Last Modified: March 13, 2025, 6:15 a.m.

0.0

CVE-2025-1401 - WP Click Info <= 2.7.4 - Reflected XSS

The WP Click Info WordPress plugin through 2.7.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

πŸ“… Published: March 13, 2025, 6 a.m. πŸ”„ Last Modified: March 13, 2025, 6:15 a.m.
Total resulsts: 285147
Page 1 of 28,515
Β» next page
Filters