CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2025-23505

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pantho Bihosh Pit Login Welcome pit-login-welcome allows Reflected XSS.This issue affects Pit Login Welcome: from n/a through <= 1.1.5.

    Published: 3 Mar 2025
    7.1
    High

    CVE-2025-23502

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Ned Curated Search curated-search allows Stored XSS.This issue affects Curated Search: from n/a through <= 1.2.

    Published: 3 Mar 2025
    7.1
    High

    CVE-2025-23496

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in husani WP FPO wp-fpo allows Reflected XSS.This issue affects WP FPO: from n/a through <= 1.0.

    Published: 3 Mar 2025
    7.1
    High

    CVE-2025-23494

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in binnyva Quizzin quizzin allows Reflected XSS.This issue affects Quizzin: from n/a through <= 1.01.4.

    Published: 3 Mar 2025
    7.1
    High

    CVE-2025-23493

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in moallemi Google Transliteration google-transliteration allows Reflected XSS.This issue affects Google Transliteration: from n/a through <= 1.7.2.

    Published: 3 Mar 2025
    7.1
    High

    CVE-2025-23490

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Stursberg Browser-Update-Notify browser-update-notify allows Reflected XSS.This issue affects Browser-Update-Notify: from n/a through <= 0.2.1.

    Published: 3 Mar 2025
    7.1
    High

    CVE-2025-23488

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Abolfazl Sabagh rng-refresh rng-refresh allows Reflected XSS.This issue affects rng-refresh: from n/a through <= 1.0.

    Published: 3 Mar 2025
    7.1
    High

    CVE-2025-23487

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in odihost Easy Gallery simple-gallery-odihost allows Reflected XSS.This issue affects Easy Gallery: from n/a through <= 1.4.

    Published: 3 Mar 2025
    7.1
    High

    CVE-2025-23485

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in richestsoft RS Survey rs-survey allows Reflected XSS.This issue affects RS Survey: from n/a through <= 1.0.

    Published: 3 Mar 2025
    7.1
    High

    CVE-2025-23484

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cojecto Predict When predict-when allows Reflected XSS.This issue affects Predict When: from n/a through <= 1.3.

    Published: 3 Mar 2025
    7.1
    High

    CVE-2025-23482

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in azurecurve azurecurve Floating Featured Image azurecurve-floating-featured-image allows Reflected XSS.This issue affects azurecurve Floating Featured Image: from n/a through <= 2.2.0.

    Published: 3 Mar 2025
    7.1
    High

    CVE-2025-23481

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Anzar Ahmed Ni WooCommerce Sales Report Email ni-woocommerce-sales-report-email allows Reflected XSS.This issue affects Ni WooCommerce Sales Report Email: from n/a through <= 3.1.4.

    Published: 3 Mar 2025
    6.5
    Medium

    CVE-2025-23480

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MicahBlu RSVP ME rsvp-me allows Stored XSS.This issue affects RSVP ME: from n/a through <= 1.9.9.

    Published: 3 Mar 2025
    7.1
    High

    CVE-2025-23479

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in melascrivi melascrivi melascrivi allows Reflected XSS.This issue affects melascrivi: from n/a through <= 1.4.

    Published: 3 Mar 2025
    7.1
    High

    CVE-2025-23478

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cmsaccount Photo Video Store photo-video-store allows Reflected XSS.This issue affects Photo Video Store: from n/a through <= 21.07.

    Published: 3 Mar 2025
    7.1
    High

    CVE-2025-23473

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Punit Bhalodiya Killer Theme Options killer-theme-options allows Reflected XSS.This issue affects Killer Theme Options: from n/a through <= 2.0.

    Published: 3 Mar 2025
    7.1
    High

    CVE-2025-23472

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flexostudio Flexo Slider flexo-slider allows Reflected XSS.This issue affects Flexo Slider: from n/a through <= 1.0013.

    Published: 3 Mar 2025
    7.1
    High

    CVE-2025-23468

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wrenchpilot Essay Wizard (wpCRES) essay-wizard-wpcres allows Reflected XSS.This issue affects Essay Wizard (wpCRES): from n/a through <= 1.0.6.4.

    Published: 3 Mar 2025
    7.1
    High

    CVE-2025-23465

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in magent Vampire Character Manager vampire-character allows Reflected XSS.This issue affects Vampire Character Manager: from n/a through <= 2.13.

    Published: 3 Mar 2025
    7.1
    High

    CVE-2025-23464

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Keir Whitaker Twitter News Feed twitter-news-feed allows Reflected XSS.This issue affects Twitter News Feed: from n/a through <= 1.1.1.

    Published: 3 Mar 2025
    7.1
    High

    CVE-2025-23451

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in titodevera Awesome Twitter Feeds awesome-twitter-feeds allows Reflected XSS.This issue affects Awesome Twitter Feeds: from n/a through <= 1.0.

    Published: 3 Mar 2025
    7.1
    High

    CVE-2025-23450

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in agenwebsite AW WooCommerce Kode Pembayaran aw-woocommerce-kode-pembayaran allows Reflected XSS.This issue affects AW WooCommerce Kode Pembayaran: from n/a through <= 1.1.4.

    Published: 3 Mar 2025
    7.1
    High

    CVE-2025-23447

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kundan Yevale Smooth Dynamic Slider smooth-dynamic-slider allows Reflected XSS.This issue affects Smooth Dynamic Slider: from n/a through <= 1.0.

    Published: 3 Mar 2025
    7.1
    High

    CVE-2025-23446

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in KokoenDE WP SpaceContent wp-spacecontent allows Stored XSS.This issue affects WP SpaceContent: from n/a through <= 0.4.5.

    Published: 3 Mar 2025
    7.1
    High

    CVE-2025-23441

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dkukral Attach Gallery Posts attach-gallery-posts allows Reflected XSS.This issue affects Attach Gallery Posts: from n/a through <= 1.6.

    Published: 3 Mar 2025
    6.3
    Medium

    CVE-2025-23440

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in radicaldesigns radSLIDE radslide allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects radSLIDE: from n/a through <= 2.1.

    Published: 3 Mar 2025
    7.1
    High

    CVE-2025-23439

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in willshouse TinyMCE Extended Config tinymce-extended-config allows Reflected XSS.This issue affects TinyMCE Extended Config: from n/a through <= 0.1.0.

    Published: 3 Mar 2025
    7.1
    High

    CVE-2025-23437

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nord_tramper ntp-header-images header-images-rotator allows Reflected XSS.This issue affects ntp-header-images: from n/a through <= 1.2.

    Published: 3 Mar 2025
    7.1
    High

    CVE-2025-23433

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jnwry vcOS vcos allows Reflected XSS.This issue affects vcOS: from n/a through <= 1.4.0.

    Published: 3 Mar 2025
    7.1
    High

    CVE-2025-23425

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in marekki Marekkis Watermark marekkis-watermark allows Reflected XSS.This issue affects Marekkis Watermark: from n/a through <= 0.9.4.

    Published: 3 Mar 2025
    8.8
    High

    CVE-2025-26999

    Last Modified: 23 Apr 2026

    Deserialization of Untrusted Data vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Object Injection.This issue affects ProfileGrid : from n/a through <= 5.9.4.3.

    Published: 3 Mar 2025
    9.3
    Critical

    CVE-2025-1875

    Last Modified: 7 Mar 2025

    SQL injection vulnerability have been found in 101news affecting version 1.0 through the "searchtitle" parameter in search.php.

    Published: 3 Mar 2025
    9.3
    Critical

    CVE-2025-1874

    Last Modified: 7 Mar 2025

    SQL injection vulnerability have been found in 101news affecting version 1.0 through the "description" parameter in admin/add-category.php.

    Published: 3 Mar 2025
    9.3
    Critical

    CVE-2025-1873

    Last Modified: 7 Mar 2025

    SQL injection vulnerability have been found in 101news affecting version 1.0 through the "pagetitle" and "pagedescription" parameters in admin/contactus.php.

    Published: 3 Mar 2025
    9.3
    Critical

    CVE-2025-1872

    Last Modified: 12 Mar 2025

    SQL injection vulnerability have been found in 101news affecting version 1.0 through the "sadminusername" parameter in admin/add-subadmins.php.

    Published: 3 Mar 2025
    9.3
    Critical

    CVE-2025-1871

    Last Modified: 7 Mar 2025

    SQL injection vulnerability have been found in 101news affecting version 1.0 through the "category" and "subcategory" parameters in admin/add-subcategory.php.

    Published: 3 Mar 2025
    9.3
    Critical

    CVE-2025-1870

    Last Modified: 7 Mar 2025

    SQL injection vulnerability have been found in 101news affecting version 1.0 through the "pagedescription" parameter in admin/aboutus.php.

    Published: 3 Mar 2025
    9.3
    Critical

    CVE-2025-1869

    Last Modified: 7 Mar 2025

    SQL injection vulnerability have been found in 101news affecting version 1.0 through the "username" parameter in admin/check_avalability.php.

    Published: 3 Mar 2025
    6.9
    Medium

    CVE-2025-1868

    Last Modified: 15 Apr 2026

    Vulnerability of unauthorized exposure of confidential information affecting Advanced IP Scanner and Advanced Port Scanner. It occurs when these applications initiate a network scan, inadvertently sending the NTLM hash of the user performing the scan. This vulnerability can be exploited by intercepting network traffic to a legitimate server or by setting up a fake server, in both local and remote scenarios. This exposure is relevant for both HTTP/HTTPS and SMB protocols.

    Published: 3 Mar 2025
    6.5
    Medium

    CVE-2024-24778

    Last Modified: 8 Jul 2025

    Improper privilege management in a REST interface allowed registered users to access unauthorized resources if the resource ID was know. This issue affects Apache StreamPipes: through 0.95.1. Users are recommended to upgrade to version 0.97.0 which fixes the issue.

    Published: 3 Mar 2025
    8.7
    High

    CVE-2025-0475

    Last Modified: 7 Mar 2025

    An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1. A proxy feature could potentially allow unintended content rendering leading to XSS under specific circumstances.

    Published: 3 Mar 2025
    7.8
    High

    CVE-2025-21424

    Last Modified: 26 Feb 2026

    Memory corruption while calling the NPU driver APIs concurrently.

    Published: 3 Mar 2025
    7.8
    High

    CVE-2024-53034

    Last Modified: 26 Feb 2026

    Memory corruption occurs during an Escape call if an invalid Kernel Mode CPU event and sync object handle are passed with the DriverKnownEscape flag reset.

    Published: 3 Mar 2025
    7.8
    High

    CVE-2024-53033

    Last Modified: 26 Feb 2026

    Memory corruption while doing Escape call when user provides valid kernel address in the place of valid user buffer address.

    Published: 3 Mar 2025
    7.8
    High

    CVE-2024-53032

    Last Modified: 26 Feb 2026

    Memory corruption may occur in keyboard virtual device due to guest VM interaction.

    Published: 3 Mar 2025
    7.8
    High

    CVE-2024-53031

    Last Modified: 26 Feb 2026

    Memory corruption while reading a type value from a buffer controlled by the Guest Virtual Machine.

    Published: 3 Mar 2025
    7.8
    High

    CVE-2024-53030

    Last Modified: 26 Feb 2026

    Memory corruption while processing input message passed from FE driver.

    Published: 3 Mar 2025
    7.8
    High

    CVE-2024-53029

    Last Modified: 26 Feb 2026

    Memory corruption while reading a value from a buffer controlled by the Guest Virtual Machine.

    Published: 3 Mar 2025
    7.8
    High

    CVE-2024-53028

    Last Modified: 26 Feb 2026

    Memory corruption may occur while processing message from frontend during allocation.

    Published: 3 Mar 2025
    7.5
    High

    CVE-2024-53027

    Last Modified: 11 Aug 2025

    Transient DOS may occur while processing the country IE.

    Published: 3 Mar 2025