6.1

CVSS3.1

CVE-2025-5301 - Reflected Cross-Site Scripting in ONLYOFFICE Docs (DocumentServer)

ONLYOFFICE Docs (DocumentServer) in versions equal and below 8.3.1 are affected by a reflected cross-site scripting (XSS) issue when opening files via the WOPI protocol. Attackers could inject malicious scripts via crafted HTTP POST requests, which are then reflected in the server's HTML response.

πŸ“… Published: June 12, 2025, 7:59 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2025-6022 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: June 12, 2025, 6:05 a.m. πŸ”„ Last Modified: July 5, 2025, 11:15 p.m.

6.9

CVSS4.0

CVE-2025-35978 -

Improper restriction of communication channel to intended endpoints issue exists in UpdateNavi V1.4 L10 to L33 and UpdateNaviInstallService Service 1.2.0091 to 1.2.0125. If a local authenticated attacker send malicious data, an arbitrary registry value may be modified or arbitrary code may be execu…

πŸ“… Published: June 12, 2025, 6:05 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-4973 - Workreap <= 3.3.1 - Authentication Bypass via 'workreap_verify_user_account'

The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to authentication bypass in all versions up to, and including, 3.3.1. This is due to the plugin not properly verifying a user's identity prior to logging them in when verifying an account …

πŸ“… Published: June 12, 2025, 5:23 a.m. πŸ”„ Last Modified: April 22, 2026, 1:30 a.m.

8.8

CVSS3.1

CVE-2025-5012 - Workreap <= 3.3.2 - Authenticated (Subscriber+) Arbitrary File Upload via 'workreap_temp_upload_to_…

The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to arbitrary file uploads due to missing file type validation in the 'workreap_temp_upload_to_media' function in all versions up to, and including, 3.3.2. This makes it possible for authen…

πŸ“… Published: June 12, 2025, 5:23 a.m. πŸ”„ Last Modified: April 8, 2026, 4:37 p.m.

5.1

CVSS4.0

CVE-2025-6009 - kiCode111 like-girl ipAddPost.php sql injection

A vulnerability was found in kiCode111 like-girl 5.2.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/ipAddPost.php. The manipulation of the argument bz/ipdz leads to sql injection. The attack may be launched remotely. The exploit has been disclo…

πŸ“… Published: June 12, 2025, 2:31 a.m. πŸ”„ Last Modified: June 19, 2025, 1:25 a.m.

5.1

CVSS4.0

CVE-2025-6008 - kiCode111 like-girl ImgAddPost.php sql injection

A vulnerability has been found in kiCode111 like-girl 5.2.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/ImgAddPost.php. The manipulation of the argument imgDatd/imgText/imgUrl leads to sql injection. The attack can be launched remotely. …

πŸ“… Published: June 12, 2025, 2 a.m. πŸ”„ Last Modified: June 19, 2025, 1:26 a.m.

5.1

CVSS4.0

CVE-2025-6007 - kiCode111 like-girl CopyadminPost.php sql injection

A vulnerability, which was classified as critical, was found in kiCode111 like-girl 5.2.0. Affected is an unknown function of the file /admin/CopyadminPost.php. The manipulation of the argument icp/Copyright leads to sql injection. It is possible to launch the attack remotely. The exploit has been …

πŸ“… Published: June 12, 2025, 2 a.m. πŸ”„ Last Modified: June 19, 2025, 1:26 a.m.

5.1

CVSS4.0

CVE-2025-6006 - kiCode111 like-girl ImgUpdaPost.php sql injection

A vulnerability, which was classified as critical, has been found in kiCode111 like-girl 5.2.0. This issue affects some unknown processing of the file /admin/ImgUpdaPost.php. The manipulation of the argument id/imgText/imgDatd/imgUrl leads to sql injection. The attack may be initiated remotely. The…

πŸ“… Published: June 12, 2025, 1 a.m. πŸ”„ Last Modified: June 20, 2025, 12:46 p.m.

5.1

CVSS4.0

CVE-2025-6005 - kiCode111 like-girl aboutPost.php sql injection

A vulnerability classified as critical was found in kiCode111 like-girl 5.2.0. This vulnerability affects unknown code of the file /admin/aboutPost.php. The manipulation of the argument title/aboutimg/info1/info2/info3/btn1/btn2/infox1/infox2/infox3/infox4/infox5/infox6/btnx2/infof1/infof2/infof3/i…

πŸ“… Published: June 12, 2025, 1 a.m. πŸ”„ Last Modified: June 20, 2025, 12:48 p.m.
Total resulsts: 346099
Page 4738 of 34,610
Β« previous page Β» next page
Filters