6.4

CVSS4.0

CVE-2025-22599 - WeGIA has a Cross-Site Scripting (XSS) Reflected endpoint `home.php` parameter `msg_c`

WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the home.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in the msg_c parameter. This vulnerability is fixed in 3.2.8.

📅 Published: Jan. 10, 2025, 3:29 p.m. 🔄 Last Modified: April 9, 2025, 6:27 p.m.

8.3

CVSS3.1

CVE-2025-22598 - WeGIA has a Cross-Site Scripting (XSS) Stored endpoint 'cadastrarSocio.php' parameter 'nome'

WeGIA is a web manager for charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the cadastrarSocio.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts into the local_recepcao parameter. The injected scripts a…

📅 Published: Jan. 10, 2025, 3:29 p.m. 🔄 Last Modified: Oct. 2, 2025, 1:34 a.m.

8.3

CVSS3.1

CVE-2025-22597 - WeGIA has a Cross-Site Scripting (XSS) Stored endpoint 'CobrancaController.php' parameter 'local_re…

WeGIA is a web manager for charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the CobrancaController.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts into the local_recepcao parameter. The injected scrip…

📅 Published: Jan. 10, 2025, 3:28 p.m. 🔄 Last Modified: Oct. 2, 2025, 1:33 a.m.

6.4

CVSS4.0

CVE-2025-22596 - WeGIA has a Cross-Site Scripting (XSS) Reflected endpoint 'modulos_visiveis.php' parameter'msg_c'

WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the modulos_visiveis.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in the msg_c parameter. This vulnerability is fixed …

📅 Published: Jan. 10, 2025, 3:27 p.m. 🔄 Last Modified: April 9, 2025, 6:27 p.m.

9.4

CVSS4.0

CVE-2025-22152 - Improper Path Validation Enables Path Traversal in Multiple Components in Atheos

Atheos is a self-hosted browser-based cloud IDE. Prior to v600, the $path and $target parameters are not properly validated across multiple components, allowing an attacker to read, modify, or execute arbitrary files on the server. These vulnerabilities can be exploited through various attack vecto…

📅 Published: Jan. 10, 2025, 3:23 p.m. 🔄 Last Modified: July 12, 2025, 3:26 p.m.

9.3

CVSS4.0

CVE-2024-56511 - DataEase has an unauthorized vulnerability

DataEase is an open source data visualization analysis tool. Prior to 2.10.4, there is a flaw in the authentication in the io.dataease.auth.filter.TokenFilter class, which can be bypassed and cause the risk of unauthorized access. In the io.dataease.auth.filter.TokenFilter class, ”request.getReques…

📅 Published: Jan. 10, 2025, 3:19 p.m. 🔄 Last Modified: Feb. 20, 2025, 4:26 p.m.

9.8

CVSS3.1

CVE-2024-41787 - IBM Engineering Requirements Management DOORS Next code execution

IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 could allow a remote attacker to bypass security restrictions, caused by a race condition. By sending a specially crafted request, an attacker could exploit this vulnerability to remotely execute code.

📅 Published: Jan. 10, 2025, 1:18 p.m. 🔄 Last Modified: Aug. 20, 2025, 2:48 a.m.

5.3

CVSS3.1

CVE-2024-13318 - Essential WP Real Estate <= 1.1.3 - Missing Authorization to Arbitrary Post/Page Deletion

The Essential WP Real Estate plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the cl_delete_listing_func() function in all versions up to, and including, 1.1.3. This makes it possible for unauthenticated attackers to delete arbitrary pages and posts.

📅 Published: Jan. 10, 2025, 11:10 a.m. 🔄 Last Modified: April 8, 2026, 4:58 p.m.

6.4

CVSS3.1

CVE-2024-13183 - Orbit Fox by ThemeIsle <= 2.10.43 - Authenticated (Contributor+) Stored Cross-Site Scripting via ti…

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_tag’ parameter in all versions up to, and including, 2.10.43 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-l…

📅 Published: Jan. 10, 2025, 7:21 a.m. 🔄 Last Modified: April 8, 2026, 5:24 p.m.

6.4

CVSS3.1

CVE-2025-0311 - Orbit Fox by ThemeIsle <= 2.10.43 - Authenticated (Contributor+) Stored Cross-Site Scripting via Pr…

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Table widget in all versions up to, and including, 2.10.43 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authent…

📅 Published: Jan. 10, 2025, 6:43 a.m. 🔄 Last Modified: April 8, 2026, 5:11 p.m.
Total resulsts: 343744
Page 6646 of 34,375
« previous page » next page
Filters