5.1

CVSS4.0

CVE-2025-0178 - WatchGaurd Firebox Host Header Injection Vulnerability

Improper Input Validation vulnerability in WatchGuard Fireware OS allows an attacker to manipulate the value of the HTTP Host header in requests sent to the Web UI. An attacker could exploit this vulnerability to redirect users to malicious websites, poison the web cache, or inject malicious JavaSc…

πŸ“… Published: Feb. 14, 2025, 1:22 p.m. πŸ”„ Last Modified: March 2, 2026, 7:07 p.m.

4.8

CVSS4.0

CVE-2025-1239 - WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Blocked Sites List

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS allows Stored XSS via the Blocked Sites list. This vulnerability requires an authenticated administrator session to a locally managed Firebox.This issue affects Firewa…

πŸ“… Published: Feb. 14, 2025, 1:21 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-1071 - WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in spamBlocker Module

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS allows Stored XSS via the spamBlocker module. This vulnerability requires an authenticated administrator session to a locally managed Firebox.This issue affects Firewa…

πŸ“… Published: Feb. 14, 2025, 1:20 p.m. πŸ”„ Last Modified: March 2, 2026, 6:59 p.m.

10

CVSS3.1

CVE-2024-13152 - SQLi in BSS Software's Mobuy Online Machinery Monitoring Panel

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BSS Software Mobuy Online Machinery Monitoring Panel allows SQL Injection.This issue affects Mobuy Online Machinery Monitoring Panel: before 2.0.

πŸ“… Published: Feb. 14, 2025, 1:01 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS3.1

CVE-2025-23905 - WordPress Admin Options Pages plugin <= 0.9.7 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Johannes van Poelgeest Admin Options Pages admin-options-pages allows Reflected XSS.This issue affects Admin Options Pages: from n/a through <= 0.9.7.

πŸ“… Published: Feb. 14, 2025, 12:45 p.m. πŸ”„ Last Modified: April 23, 2026, 3:24 p.m.

7.1

CVSS3.1

CVE-2025-22705 - WordPress Disqus Popular Posts plugin <= 2.1.1 - CSRF to Reflected Cross Site Scripting (XSS) vulne…

Cross-Site Request Forgery (CSRF) vulnerability in godthor Disqus Popular Posts disqus-popular-posts allows Reflected XSS.This issue affects Disqus Popular Posts: from n/a through <= 2.1.1.

πŸ“… Published: Feb. 14, 2025, 12:45 p.m. πŸ”„ Last Modified: April 23, 2026, 3:23 p.m.

6.3

CVSS3.1

CVE-2025-22702 - WordPress Photography Theme <= 7.7.2 - Broken Access Control Vulnerability

Missing Authorization vulnerability in ThemeGoods Photography photography allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Photography: from n/a through <= 7.7.2.

πŸ“… Published: Feb. 14, 2025, 12:45 p.m. πŸ”„ Last Modified: April 23, 2026, 3:23 p.m.

0.0

CVE-2025-22698 - WordPress Accessibility Suite by Ability, Inc plugin <= 4.18 - Multiple Broken Access Control vulne…

Missing Authorization vulnerability in Ability, Inc Accessibility Suite online-accessibility allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accessibility Suite: from n/a through <= 4.18.

πŸ“… Published: Feb. 14, 2025, 12:45 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2024-52500 - WordPress Monetag Official Plugin plugin <= 1.1.3 - Broken Access Control vulnerability

Missing Authorization vulnerability in monetagwp Monetag Official Plugin monetag-official allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Monetag Official Plugin: from n/a through <= 1.1.3.

πŸ“… Published: Feb. 14, 2025, 12:45 p.m. πŸ”„ Last Modified: April 23, 2026, 3:21 p.m.

7.1

CVSS3.1

CVE-2025-24692 - WordPress Bulk Menu Edit plugin <= 1.3 - Broken Access Control vulnerability

Missing Authorization vulnerability in M.Code Bulk Menu Edit bulk-menu-edit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bulk Menu Edit: from n/a through <= 1.3.

πŸ“… Published: Feb. 14, 2025, 12:44 p.m. πŸ”„ Last Modified: April 23, 2026, 3:25 p.m.
Total resulsts: 346529
Page 6461 of 34,653
Β« previous page Β» next page
Filters