7.1

CVSS3.1

CVE-2025-23523 - WordPress HSS Embed Streaming Video plugin <= 3.23 - Reflected Cross Site Scripting (XSS) vulnerabi…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hoststreamsell HSS Embed Streaming Video hss-embed-streaming-video allows Reflected XSS.This issue affects HSS Embed Streaming Video: from n/a through <= 3.23.

📅 Published: Feb. 14, 2025, 12:44 p.m. 🔄 Last Modified: April 23, 2026, 3:23 p.m.

7.1

CVSS3.1

CVE-2025-23492 - WordPress 淘宝客插件 plugin <= 1.1.2 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CantonBolo WordPress 淘宝客插件 taobaoke allows Reflected XSS.This issue affects WordPress 淘宝客插件: from n/a through <= 1.1.2.

📅 Published: Feb. 14, 2025, 12:44 p.m. 🔄 Last Modified: April 23, 2026, 3:23 p.m.

7.1

CVSS3.1

CVE-2025-23474 - WordPress Live Dashboard plugin <= 0.3.3 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mike Martel Live Dashboard live-dashboard allows Reflected XSS.This issue affects Live Dashboard: from n/a through <= 0.3.3.

📅 Published: Feb. 14, 2025, 12:44 p.m. 🔄 Last Modified: April 23, 2026, 3:23 p.m.

7.1

CVSS3.1

CVE-2025-23431 - WordPress Envato Affiliater plugin <= 1.2.4 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in khaninejad Envato Affiliater envato-affiliater allows Reflected XSS.This issue affects Envato Affiliater: from n/a through <= 1.2.4.

📅 Published: Feb. 14, 2025, 12:44 p.m. 🔄 Last Modified: April 23, 2026, 3:23 p.m.

7.1

CVSS3.1

CVE-2025-23428 - WordPress QMean plugin <= 2.0 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arash Safari QMean – WordPress Did You Mean qmean allows Reflected XSS.This issue affects QMean – WordPress Did You Mean: from n/a through <= 2.0.

📅 Published: Feb. 14, 2025, 12:44 p.m. 🔄 Last Modified: April 23, 2026, 3:23 p.m.

9.9

CVSS3.1

CVE-2025-0867 - Privilege Escalation in MEAC300

The standard user uses the run as function to start the MEAC applications with administrative privileges. To ensure that the system can startup on its own, the credentials of the administrator were stored. Consequently, the EPC2 user can execute any command with administrative privileges. This allo…

📅 Published: Feb. 14, 2025, 12:37 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-26524 - No Rate Limiting Vulnerability in RupeeWeb trading platform

This vulnerability exists in RupeeWeb trading platform due to missing rate limiting on OTP requests in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoints which could lead to the OTP bombing/ flood…

📅 Published: Feb. 14, 2025, 11:36 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.4

CVSS4.0

CVE-2025-26523 - Insufficient Authorization Vulnerability in RupeeWeb trading platform

This vulnerability exists in RupeeWeb trading platform due to insufficient authorization controls on certain API endpoints handling addition and deletion operations. Successful exploitation of this vulnerability could allow an authenticated remote attacker to modify information belonging to other u…

📅 Published: Feb. 14, 2025, 11:32 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS4.0

CVE-2025-26522 - Authentication Bypass Vulnerability in RupeeWeb trading platform

This vulnerability exists in RupeeWeb trading platform due to improper implementation of OTP validation mechanism in certain API endpoints. A remote attacker with valid credentials could exploit this vulnerability by manipulating API responses. Successful exploitation of this vulnerability could…

📅 Published: Feb. 14, 2025, 11:24 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-0821 - Bit Assist <= 1.5.2 - Authenticated (Subscriber+) SQL Injection via id Parameter

Bit Assist plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenti…

📅 Published: Feb. 14, 2025, 11:10 a.m. 🔄 Last Modified: April 21, 2026, 10:30 p.m.
Total resulsts: 346554
Page 6469 of 34,656
« previous page » next page
Filters