Total
298205 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2024-11373 | 1 Floriansimunek | 1 Connexion Logs | 2025-06-09 | N/A | 4.3 MEDIUM |
The Connexion Logs WordPress plugin through 3.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |||||
CVE-2024-45094 | 1 Ibm | 6 Hardware Management Console R10.0, Hardware Management Console R10.0 Firmware, Hardware Management Console R9.3 and 3 more | 2025-06-09 | N/A | 5.5 MEDIUM |
IBM DS8900F and DS8A00 Hardware Management Console (HMC) is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |||||
CVE-2025-5252 | 1 Phpgurukul | 1 News Portal Project | 2025-06-09 | 7.5 HIGH | 7.3 HIGH |
A vulnerability was found in PHPGurukul News Portal Project 4.1. It has been declared as critical. This vulnerability affects unknown code of the file /admin/edit-subadmin.php. The manipulation of the argument emailid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | |||||
CVE-2025-48744 | 1 Sigb | 1 Pmb | 2025-06-09 | N/A | 6.4 MEDIUM |
In SIGB PMB before 8.0.1.2, attackers can achieve Local File Inclusion and remote code execution. | |||||
CVE-2025-48743 | 1 Sigb | 1 Pmb | 2025-06-09 | N/A | 5.3 MEDIUM |
SIGB PMB before 8.0.1.2 allows SQL injection. | |||||
CVE-2024-11502 | 1 Wpchurchteam | 1 Planning Center Online Giving | 2025-06-09 | N/A | 5.4 MEDIUM |
The Planning Center Online Giving WordPress plugin through 1.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |||||
CVE-2025-5220 | 1 Freefloat | 1 Ftp Server | 2025-06-09 | 7.5 HIGH | 7.3 HIGH |
A vulnerability was found in FreeFloat FTP Server 1.0.0 and classified as critical. Affected by this issue is some unknown functionality of the component GET Command Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | |||||
CVE-2025-33079 | 1 Ibm | 2 Cognos Controller, Controller | 2025-06-09 | N/A | 6.5 MEDIUM |
IBM Controller 11.0.0, 11.0.1, and 11.1.0 application could allow an authenticated user to obtain sensitive credentials that may be inadvertently included within the source code. | |||||
CVE-2025-5219 | 1 Freefloat | 1 Ftp Server | 2025-06-09 | 7.5 HIGH | 7.3 HIGH |
A vulnerability has been found in FreeFloat FTP Server 1.0.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the component ASCII Command Handler. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | |||||
CVE-2024-11718 | 1 Couleurcitron | 1 Tarteaucitron-wp | 2025-06-09 | N/A | 5.4 MEDIUM |
The tarteaucitron-wp WordPress plugin before 0.3.0 allows author level and above users to add HTML into a post/page, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |||||
CVE-2024-11719 | 1 Couleurcitron | 1 Tarteaucitron-wp | 2025-06-09 | N/A | 6.1 MEDIUM |
The tarteaucitron-wp WordPress plugin before 0.3.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack. | |||||
CVE-2024-11843 | 1 Projectpanorama | 1 Panorama | 2025-06-09 | N/A | 4.8 MEDIUM |
The Panorama WordPress plugin through 1.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |||||
CVE-2024-12301 | 1 Joomlaserviceprovider | 1 Jsp Store Locator | 2025-06-09 | N/A | 6.5 MEDIUM |
The JSP Store Locator WordPress plugin through 1.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks. | |||||
CVE-2024-12282 | 1 Smyx | 1 Wp-connect | 2025-06-09 | N/A | 6.1 MEDIUM |
The WordPress连接微博 WordPress plugin through 2.5.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack. | |||||
CVE-2023-7239 | 1 Jeroensormani | 1 Wp Dashboard Notes | 2025-06-09 | N/A | 7.5 HIGH |
The WP Dashboard Notes WordPress plugin before 1.0.11 does not validate that the user has access to the post_id parameter in its wpdn_update_note AJAX action. This allows users with a role of contributor and above to update notes created by other users. | |||||
CVE-2023-7297 | 1 Reneade | 1 Twitterposts | 2025-06-09 | N/A | 6.5 MEDIUM |
The TwitterPosts WordPress plugin through 1.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |||||
CVE-2024-0249 | 1 Hijiriworld | 1 Advanced Schedule Posts | 2025-06-09 | N/A | 6.1 MEDIUM |
The Advanced Schedule Posts WordPress plugin through 2.1.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admins. | |||||
CVE-2024-0970 | 1 Mooveagency | 1 User Activity Tracking And Log | 2025-06-09 | N/A | 7.5 HIGH |
This User Activity Tracking and Log WordPress plugin before 4.1.4 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. | |||||
CVE-2024-10098 | 1 Spiderteams | 1 Applyonline - Application Form Builder And Manager | 2025-06-09 | N/A | 2.7 LOW |
The ApplyOnline WordPress plugin before 2.6.3 does not protect uploaded files during the application process, allowing unauthenticated users to access them and any private information they contain | |||||
CVE-2024-10149 | 1 Cm-wp | 1 Social Slider Widget | 2025-06-09 | N/A | 4.8 MEDIUM |
The Social Slider Feed WordPress plugin before 2.2.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). |