Export limit exceeded: 370024 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (370024 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2024-28458 | 1 Swftools | 1 Swftools | 2025-06-10 | 7.5 High |
| Null Pointer Dereference vulnerability in swfdump in swftools 0.9.2 allows attackers to crash the appliation via the function compileSWFActionCode in action/actioncompiler.c. | ||||
| CVE-2024-24272 | 1 Itopvpn | 1 Dualsafe Password Manager | 2025-06-10 | 7.1 High |
| An issue in iTop DualSafe Password Manager & Digital Vault before 1.4.24 allows a local attacker to obtain sensitive information via leaked credentials as plaintext in a log file that can be accessed by the local user without knowledge of the master secret. | ||||
| CVE-2024-1526 | 1 Devpups | 1 Social Pug | 2025-06-10 | 5.3 Medium |
| The Hubbub Lite WordPress plugin before 1.33.1 does not ensure that user have access to password protected post before displaying its content in a meta tag. | ||||
| CVE-2024-25187 | 1 Xiaocheng-keji | 1 71cms | 2025-06-10 | 8.6 High |
| Server Side Request Forgery (SSRF) vulnerability in 71cms v1.0.0, allows remote unauthenticated attackers to obtain sensitive information via getweather.html. | ||||
| CVE-2024-9021 | 2 Mikkosaari, Relevanssi | 2 Relevanssi, Relevanssi | 2025-06-09 | 5.4 Medium |
| In the process of testing the Relevanssi WordPress plugin before 4.23.1, a vulnerability was found that allows you to implement Stored XSS on behalf of the Contributor+ by embedding malicious script, which entails account takeover backdoor | ||||
| CVE-2024-5081 | 2 Tipsandtricks-hq, Wp Emember | 2 Wp Emember, Wp Emember | 2025-06-09 | 6.1 Medium |
| The wp-eMember WordPress plugin before v10.7.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack | ||||
| CVE-2024-6496 | 1 Dmytropopov | 1 Light Poll | 2025-06-09 | 6.5 Medium |
| The Light Poll WordPress plugin through 1.0.0 does not have CSRF checks when deleting polls, which could allow attackers to make logged in users perform such action via a CSRF attack | ||||
| CVE-2024-12400 | 1 Goodlayers | 1 Tour Master | 2025-06-09 | 7.1 High |
| The tourmaster WordPress plugin before 5.3.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting. | ||||
| CVE-2024-12163 | 1 Goodlayers | 1 Goodlayers Core | 2025-06-09 | 6.5 Medium |
| The goodlayers-core WordPress plugin before 2.1.3 allows users with a subscriber role and above to upload SVGs containing malicious payloads. | ||||
| CVE-2024-10510 | 2 Adbuddy Plus Wordpress, Netfunkdesign | 2 Adbuddy Plus Wordpress, Adbuddy\+ \(adblocker Detection\) | 2025-06-09 | 4.8 Medium |
| The adBuddy+ (AdBlocker Detection) by NetfunkDesign WordPress plugin through 1.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | ||||
| CVE-2024-22818 | 1 Flycms Project | 1 Flycms | 2025-06-09 | 8.8 High |
| FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerbility via /system/site/filterKeyword_save | ||||
| CVE-2023-6163 | 1 Themeum | 1 Wp Crowdfunding | 2025-06-09 | 4.8 Medium |
| The WP Crowdfunding WordPress plugin before 2.1.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | ||||
| CVE-2023-5956 | 1 Markusbegerow | 1 Wp-adv-quiz | 2025-06-09 | 4.8 Medium |
| The Wp-Adv-Quiz WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | ||||
| CVE-2024-24869 | 1 Boldgrid | 1 Total Upkeep | 2025-06-09 | 7.5 High |
| Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in BoldGrid Total Upkeep allows Relative Path Traversal.This issue affects Total Upkeep: from n/a through 1.15.8. | ||||
| CVE-2023-41954 | 1 Properfraction | 1 Profilepress | 2025-06-09 | 8.6 High |
| Improper Privilege Management vulnerability in ProfilePress Membership Team ProfilePress allows Privilege Escalation.This issue affects ProfilePress: from n/a through 4.13.1. | ||||
| CVE-2025-3951 | 1 Updraftplus | 1 Wp-optimize | 2025-06-09 | 4.1 Medium |
| The WP-Optimize WordPress plugin before 4.2.0 does not properly escape user input when checking image compression statuses, which could allow users with the administrator role to conduct SQL Injection attacks in the context of Multi-Site WordPress configurations. | ||||
| CVE-2024-0721 | 1 Jspxcms | 1 Jspxcms | 2025-06-09 | 3.5 Low |
| A vulnerability has been found in Jspxcms 10.2.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Survey Label Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-251545 was assigned to this vulnerability. | ||||
| CVE-2025-1485 | 1 Devowl | 1 Wordpress Real Cookie Banner | 2025-06-09 | 4.8 Medium |
| The Real Cookie Banner: GDPR & ePrivacy Cookie Consent WordPress plugin before 5.1.6, real-cookie-banner-pro WordPress plugin before 5.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | ||||
| CVE-2023-31037 | 1 Nvidia | 4 Bluefield 2 Ga, Bluefield 2 Lts, Bluefield 3 Ga and 1 more | 2025-06-09 | 7.2 High |
| NVIDIA Bluefield 2 and Bluefield 3 DPU BMC contains a vulnerability in ipmitool, where a root user may cause code injection by a network call. A successful exploit of this vulnerability may lead to code execution on the OS. | ||||
| CVE-2024-1026 | 1 Cogites | 1 Ereserv | 2025-06-09 | 3.5 Low |
| A vulnerability was found in Cogites eReserv 7.7.58 and classified as problematic. This issue affects some unknown processing of the file front/admin/config.php. The manipulation of the argument id with the input %22%3E%3Cscript%3Ealert(%27XSS%27)%3C/script%3E leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-252293 was assigned to this vulnerability. | ||||