5.3

CVSS4.0

CVE-2025-2753 - Open Asset Import Library Assimp LWS File LWSLoader.cpp MergeScenes out-of-bounds

A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as critical. Affected is the function SceneCombiner::MergeScenes of the file code/AssetLib/LWS/LWSLoader.cpp of the component LWS File Handler. The manipulation leads to out-of-bounds read. It is possible toโ€ฆ

๐Ÿ“… Published: March 25, 2025, 8:31 a.m. ๐Ÿ”„ Last Modified: July 17, 2025, 9:50 p.m.

8.8

CVSS3.1

CVE-2025-2319 - EZ SQL Reports Shortcode Widget and DB Backup 4.11.13 - 5.25.08 - Cross-Site Request Forgery to Remโ€ฆ

The EZ SQL Reports Shortcode Widget and DB Backup plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 4.11.13 to 5.25.08. This is due to missing or incorrect nonce validation on the 'ELISQLREPORTS_menu' function. This makes it possible for unauthenticated attackers to execuโ€ฆ

๐Ÿ“… Published: March 25, 2025, 8:22 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2024-13690 - WP Church Donation <= 1.7 - Unauthenticated Stored Cross-Site Scripting

The WP Church Donation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several donation form submission parameters in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to injeโ€ฆ

๐Ÿ“… Published: March 25, 2025, 8:22 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-13731 - Alert Box Block โ€“ Display notice/alerts in the front end <= 1.1.3 - Authenticated (Contributor+) Stโ€ฆ

The Alert Box Block โ€“ Display notice/alerts in the front end. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Alert Box block in all versions up to, and including, 1.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This mโ€ฆ

๐Ÿ“… Published: March 25, 2025, 8:22 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-13710 - Estatebud โ€“ Properties & Listings <= 5.5.0 - Cross-Site Request Forgery to Settings Update

The Estatebud โ€“ Properties & Listings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.5.0. This is due to missing or incorrect nonce validation on the 'estatebud_settings' page. This makes it possible for unauthenticated attackers to update tโ€ฆ

๐Ÿ“… Published: March 25, 2025, 8:22 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-2510 - Frndzk Expandable Bottom Bar <= 1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting viโ€ฆ

The Frndzk Expandable Bottom Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'text' parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level โ€ฆ

๐Ÿ“… Published: March 25, 2025, 8:22 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 9:45 p.m.

5.3

CVSS4.0

CVE-2025-2752 - Open Asset Import Library Assimp CSM File fast_atof.h fast_atoreal_move out-of-bounds

A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function fast_atoreal_move in the library include/assimp/fast_atof.h of the component CSM File Handler. The manipulation leads to out-of-bounds read. The attack may be initiatedโ€ฆ

๐Ÿ“… Published: March 25, 2025, 8 a.m. ๐Ÿ”„ Last Modified: July 17, 2025, 9:50 p.m.

5.3

CVSS4.0

CVE-2025-2751 - Open Asset Import Library Assimp CSM File CSMLoader.cpp InternReadFile out-of-bounds

A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerability affects the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. The manipulation of the argument na leadโ€ฆ

๐Ÿ“… Published: March 25, 2025, 7:31 a.m. ๐Ÿ”„ Last Modified: July 17, 2025, 9:51 p.m.

5.3

CVSS4.0

CVE-2025-2750 - Open Asset Import Library Assimp CSM File CSMLoader.cpp InternReadFile out-of-bounds write

A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. The manipulation leads to out-of-bounds write. It is pโ€ฆ

๐Ÿ“… Published: March 25, 2025, 7:31 a.m. ๐Ÿ”„ Last Modified: July 17, 2025, 9:51 p.m.

6.4

CVSS3.1

CVE-2024-12623 - DICOM Support <= 0.10.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

The DICOM Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dcm' shortcode in all versions up to, and including, 0.10.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackerโ€ฆ

๐Ÿ“… Published: March 25, 2025, 7:04 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 348478
Page 6150 of 34,848
ยซ previous page ยป next page
Filters