Vulnerabilities (CVE)

Total 299014 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-45514 1 Synacor 1 Zimbra Collaboration Suite 2025-06-11 N/A 5.4 MEDIUM
An issue was discovered in Zimbra Collaboration (ZCS) through v10.1. A Cross-Site Scripting (XSS) vulnerability exists in one of the endpoints of Zimbra Webmail due to insufficient sanitization of the packages parameter. Attackers can bypass the existing checks by using encoded characters, allowing the injection and execution of arbitrary JavaScript within a victim's session.
CVE-2024-45512 1 Synacor 1 Zimbra Collaboration Suite 2025-06-11 N/A 5.4 MEDIUM
An issue was discovered in webmail in Zimbra Collaboration (ZCS) through 10.1. An attacker can exploit this vulnerability by creating a folder in the Briefcase module with a malicious payload and sharing it with a victim. When the victim interacts with the folder share notification, the malicious script executes in their browser. This stored Cross-Site Scripting (XSS) vulnerability can lead to unauthorized actions within the victim's session.
CVE-2024-45511 1 Synacor 1 Zimbra Collaboration Suite 2025-06-11 N/A 5.4 MEDIUM
An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A reflected Cross-Site Scripting (XSS) issue exists through the Briefcase module due to improper sanitization of file content by the OnlyOffice formatter. This occurs when the victim opens a crafted URL pointing to a shared folder containing a malicious file uploaded by the attacker. The vulnerability allows the attacker to execute arbitrary JavaScript in the context of the victim's session.
CVE-2024-25722 1 Qanything 1 Qanything 2025-06-11 N/A 9.8 CRITICAL
qanything_kernel/connector/database/mysql/mysql_client.py in qanything.ai QAnything before 1.2.0 allows SQL Injection.
CVE-2023-44000 1 Linecorp 1 Line 2025-06-11 N/A 5.4 MEDIUM
An issue in Otakara lapis totuka mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
CVE-2025-24016 1 Wazuh 1 Wazuh 2025-06-11 N/A 9.9 CRITICAL
Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 and prior to version 4.9.1, an unsafe deserialization vulnerability allows for remote code execution on Wazuh servers. DistributedAPI parameters are a serialized as JSON and deserialized using `as_wazuh_object` (in `framework/wazuh/core/cluster/common.py`). If an attacker manages to inject an unsanitized dictionary in DAPI request/response, they can forge an unhandled exception (`__unhandled_exc__`) to evaluate arbitrary python code. The vulnerability can be triggered by anybody with API access (compromised dashboard or Wazuh servers in the cluster) or, in certain configurations, even by a compromised agent. Version 4.9.1 contains a fix.
CVE-2025-48757 2025-06-11 N/A 9.3 CRITICAL
An insufficient database Row-Level Security policy in Lovable through 2025-04-15 allows remote unauthenticated attackers to read or write to arbitrary database tables of generated sites.
CVE-2024-12716 1 Wpkube 1 Simple Basic Contact Form 2025-06-11 N/A 4.8 MEDIUM
The Simple Basic Contact Form WordPress plugin before 20250114 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2023-7174 1 Abitgone 1 Abitgone Commentsafe 2025-06-11 N/A 7.1 HIGH
The aBitGone CommentSafe WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
CVE-2023-7195 1 Ani2life 1 Wp-reply Notify 2025-06-11 N/A 4.3 MEDIUM
The WP-Reply Notify WordPress plugin through 1.1 does not have a CSRF check in place when updating its settings, which could allow attackers to make a logged-in admin change them via a CSRF attack.
CVE-2023-7196 1 Jonkemp 1 Ultimate Noindex Nofollow Tool 2025-06-11 N/A 4.3 MEDIUM
The Ultimate Noindex Nofollow Tool WordPress plugin through 1.1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CVE-2023-7197 1 Corbyboy 1 Marketing Twitter Bot 2025-06-11 N/A 7.1 HIGH
The Marketing Twitter Bot WordPress plugin through 1.11 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
CVE-2024-0852 1 Dev4press 1 Coreactivity 2025-06-11 N/A 6.1 MEDIUM
The coreActivity: Activity Logging for WordPress plugin before 1.8.1 does not escape some request data when outputting it back in the admin dashboard, allowing unauthenticated users to perform Stored XSS attack against high privilege users such as admin
CVE-2024-10009 1 Melapress 1 Melapress File Monitor 2025-06-11 N/A 4.1 MEDIUM
The Melapress File Monitor WordPress plugin before 2.1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
CVE-2023-2334 2 Gsheetconnector, Westerndeal 2 Edd Gsheetconnector, Easy Digital Downloads Google Sheet Connector 2025-06-11 N/A 5.4 MEDIUM
The edd-google-sheet-connector-pro WordPress plugin before 1.4, Easy Digital Downloads Google Sheet Connector WordPress plugin before 1.6.6 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack
CVE-2023-6030 1 Deryckoe 1 Logdash Activity Log 2025-06-11 N/A 5.4 MEDIUM
The LogDash Activity Log WordPress plugin before 1.1.4 hooks the wp_login_failed function (from src/Hooks/Users.php) in order to log failed login attempts to the database but it doesn't escape the username when it perform some SQL request leading to a SQL injection vulnerability which can be exploited using time-based technique by unauthenticated attacker
CVE-2023-6541 1 Wphelpline 1 Allow Svg 2025-06-11 N/A 6.1 MEDIUM
The Allow SVG WordPress plugin before 1.2.0 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.
CVE-2023-6783 1 Wolfnettech 1 Wolfnet Idx For Wordpress 2025-06-11 N/A 4.8 MEDIUM
The WolfNet IDX for WordPress plugin through 1.19.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2024-45510 1 Synacor 1 Zimbra Collaboration Suite 2025-06-11 N/A 5.4 MEDIUM
An issue was discovered in Zimbra Collaboration (ZCS) through 10.0. Zimbra Webmail (Modern UI) is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper sanitization of user input. This allows an attacker to inject malicious code into specific fields of an e-mail message. When the victim adds the attacker to their contacts, the malicious code is stored and executed when viewing the contact list. This can lead to unauthorized actions such as arbitrary mail sending, mailbox exfiltration, profile picture alteration, and other malicious actions. Proper sanitization and escaping of input fields are necessary to mitigate this vulnerability.
CVE-2023-6786 1 Hkdigitalagency 1 Payment Gateway For Telcell 2025-06-11 N/A 6.1 MEDIUM
The Payment Gateway for Telcell WordPress plugin through 2.0.1 does not validate the api_url parameter before redirecting the user to its value, leading to an Open Redirect issue