Show filters
16,625 Total Results
Displaying 311-320 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2025-25148

Disclosure Date: February 07, 2025 (last updated February 27, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in ElbowRobo Read More Copy Link allows Stored XSS. This issue affects Read More Copy Link: from n/a through 1.0.2.
0
Attacker Value
Unknown

CVE-2025-25141

Disclosure Date: February 07, 2025 (last updated February 27, 2025)
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in zankover Fami Sales Popup allows PHP Local File Inclusion. This issue affects Fami Sales Popup: from n/a through 2.0.0.
0
Attacker Value
Unknown

CVE-2025-25136

Disclosure Date: February 07, 2025 (last updated February 27, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shujahat21 Optimate Ads allows Stored XSS. This issue affects Optimate Ads: from n/a through 1.0.3.
0
Attacker Value
Unknown

CVE-2025-25105

Disclosure Date: February 07, 2025 (last updated February 27, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in coffeestudios Pop Up allows Stored XSS. This issue affects Pop Up: from n/a through 0.1.
0
Attacker Value
Unknown

CVE-2025-0304

Disclosure Date: February 07, 2025 (last updated February 27, 2025)
in OpenHarmony v4.1.2 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through use after free.
Attacker Value
Unknown

CVE-2025-0303

Disclosure Date: February 07, 2025 (last updated February 27, 2025)
in OpenHarmony v4.1.2 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through buffer overflow.
Attacker Value
Unknown

CVE-2025-0302

Disclosure Date: February 07, 2025 (last updated February 27, 2025)
in OpenHarmony v4.1.2 and prior versions allow a local attacker cause DOS through integer overflow.
Attacker Value
Unknown

CVE-2024-13492

Disclosure Date: February 07, 2025 (last updated February 07, 2025)
The Guten Free Options WordPress plugin through 0.9.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
0
Attacker Value
Unknown

CVE-2024-57668

Disclosure Date: February 06, 2025 (last updated March 01, 2025)
In Code-projects Shopping Portal v1.0, the insert-product.php page has an arbitrary file upload vulnerability.
Attacker Value
Unknown

CVE-2025-0859

Disclosure Date: February 06, 2025 (last updated February 27, 2025)
The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.27.6 via the template_via_url() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.