Show filters
1,508 Total Results
Displaying 21-30 of 1,508
Sort by:
Attacker Value
Unknown
CVE-2025-23599
Disclosure Date: February 03, 2025 (last updated February 04, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound eMarksheet allows Reflected XSS. This issue affects eMarksheet: from n/a through 5.0.
0
Attacker Value
Unknown
CVE-2025-0493
Disclosure Date: January 31, 2025 (last updated January 31, 2025)
The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Limited Local File Inclusion in all versions up to, and including, 4.2.14 via the tabname parameter. This makes it possible for unauthenticated attackers to include PHP files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where PHP files can be uploaded and included
0
Attacker Value
Unknown
CVE-2025-0142
Disclosure Date: January 30, 2025 (last updated January 31, 2025)
Cleartext storage of sensitive information in the Zoom Jenkins Marketplace plugin before version 1.4 may allow an authenticated user to conduct a disclosure of information via network access.
0
Attacker Value
Unknown
CVE-2025-24600
Disclosure Date: January 27, 2025 (last updated January 28, 2025)
Missing Authorization vulnerability in David F. Carr RSVPMarker . This issue affects RSVPMarker : from n/a through 11.4.5.
0
Attacker Value
Unknown
CVE-2025-24706
Disclosure Date: January 24, 2025 (last updated January 25, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MultiVendorX WC Marketplace allows Stored XSS. This issue affects WC Marketplace: from n/a through 4.2.13.
0
Attacker Value
Unknown
CVE-2024-13519
Disclosure Date: January 18, 2025 (last updated January 18, 2025)
The MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin's settings in all versions up to, and including, 1.9.80 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Shop Manager-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
0
Attacker Value
Unknown
CVE-2025-23963
Disclosure Date: January 16, 2025 (last updated January 17, 2025)
Missing Authorization vulnerability in Sven Hofmann & Michael Schoenrock Mark Posts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mark Posts: from n/a through 2.2.3.
0
Attacker Value
Unknown
CVE-2025-23930
Disclosure Date: January 16, 2025 (last updated January 17, 2025)
Missing Authorization vulnerability in iTechArt-Group PayPal Marketing Solutions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PayPal Marketing Solutions: from n/a through 1.2.
0
Attacker Value
Unknown
CVE-2025-0394
Disclosure Date: January 14, 2025 (last updated January 14, 2025)
The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the gh_big_file_upload() function in all versions up to, and including, 3.7.3.5. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
0
Attacker Value
Unknown
CVE-2025-21380
Disclosure Date: January 09, 2025 (last updated February 06, 2025)
Improper access control in Azure SaaS Resources allows an authorized attacker to disclose information over a network.
0