Show filters
2,231 Total Results
Displaying 51-60 of 2,231
Sort by:
Attacker Value
Unknown
CVE-2025-21387
Disclosure Date: February 11, 2025 (last updated February 20, 2025)
Microsoft Excel Remote Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2025-21386
Disclosure Date: February 11, 2025 (last updated February 20, 2025)
Microsoft Excel Remote Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2025-21381
Disclosure Date: February 11, 2025 (last updated February 20, 2025)
Microsoft Excel Remote Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2025-0862
Disclosure Date: February 11, 2025 (last updated February 11, 2025)
The SuperSaaS – online appointment scheduling plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘after’ parameter in all versions up to, and including, 2.1.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is limited to Chromium-based browsers (e.g. Chrome, Edge, Brave).
0
Attacker Value
Unknown
CVE-2025-1157
Disclosure Date: February 10, 2025 (last updated February 11, 2025)
A vulnerability was found in Allims lab.online up to 20250201 and classified as critical. This issue affects some unknown processing of the file /model/model_recuperar_senha.php. The manipulation of the argument recuperacao leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2024-11831
Disclosure Date: February 10, 2025 (last updated February 13, 2025)
A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript object types, allowing an attacker to inject malicious code. This code could be executed when deserialized by a web browser, causing Cross-site scripting (XSS) attacks. This issue is critical in environments where serialized data is sent to web clients, potentially compromising the security of the website or web application using this package.
0
Attacker Value
Unknown
CVE-2025-23747
Disclosure Date: February 03, 2025 (last updated February 04, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nitesh Singh Awesome Timeline allows Stored XSS. This issue affects Awesome Timeline: from n/a through 1.0.1.
0
Attacker Value
Unknown
CVE-2024-13415
Disclosure Date: January 31, 2025 (last updated January 31, 2025)
The Food Menu – Restaurant Menu & Online Ordering for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the response() function in all versions up to, and including, 5.1.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify the plugin's settings.
0
Attacker Value
Unknown
CVE-2025-0800
Disclosure Date: January 29, 2025 (last updated February 11, 2025)
A vulnerability classified as problematic has been found in SourceCodester Online Courseware 1.0. Affected is an unknown function of the file /pcci/admin/saveeditt.php of the component Edit Teacher. The manipulation of the argument fname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2025-24590
Disclosure Date: January 27, 2025 (last updated January 28, 2025)
Missing Authorization vulnerability in Haptiq picu – Online Photo Proofing Gallery allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects picu – Online Photo Proofing Gallery: from n/a through 2.4.0.
0