CVE Feed

    Dashboard / CVE

    6.4
    Medium

    CVE-2024-13401

    Last Modified: 15 Apr 2026

    The Payment Button for PayPal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_paypal_checkout' shortcode in all versions up to, and including, 1.2.3.35 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 17 Jan 2025
    4
    Medium

    CVE-2024-51462

    Last Modified: 14 Aug 2025

    IBM QRadar WinCollect Agent 10.0.0 through 10.1.12 could allow a remote attacker to inject XML data into parameter values due to improper input validation of assumed immutable data.

    Published: 17 Jan 2025
    6.5
    Medium

    CVE-2024-52363

    Last Modified: 11 Mar 2025

    IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.

    Published: 17 Jan 2025
    7.5
    High

    CVE-2024-13333

    Last Modified: 5 Jun 2025

    The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fma_local_file_system' function in versions 5.2.12 to 5.2.13. This makes it possible for authenticated attackers, with Subscriber-level access and above and upload permissions granted by an administrator, to upload arbitrary files on the affected site's server which may make remote code execution possible. The function can be exploited only if the "Display .htaccess?" setting is enabled.

    Published: 17 Jan 2025
    7.8
    High

    CVE-2025-21325

    Last Modified: 13 Feb 2026

    Windows Secure Kernel Mode Elevation of Privilege Vulnerability

    Published: 17 Jan 2025
    8.5
    High

    CVE-2024-34579

    Last Modified: 15 Apr 2026

    Fuji Electric Alpha5 SMART is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.

    Published: 17 Jan 2025
    6.5
    Medium

    CVE-2024-50967

    Last Modified: 15 Apr 2026

    The /rest/rights/ REST API endpoint in Becon DATAGerry through 2.2.0 contains an Incorrect Access Control vulnerability. An attacker can remotely access this endpoint without authentication, leading to unauthorized disclosure of sensitive information.

    Published: 17 Jan 2025
    6.1
    Medium

    CVE-2024-45336

    Last Modified: 15 Apr 2026

    The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

    Published: 17 Jan 2025
    6.1
    Medium

    CVE-2024-57372

    Last Modified: 15 Apr 2026

    Cross Site Scripting vulnerability in InformationPush master version allows a remote attacker to obtain sensitive information via the title, time and msg parameters

    Published: 17 Jan 2025
    6.1
    Medium

    CVE-2024-57370

    Last Modified: 15 Apr 2026

    Cross Site Scripting vulnerability in sunnygkp10 Online Exam System master version allows a remote attacker to obtain sensitive information via the w parameter.

    Published: 17 Jan 2025
    6.4
    Medium

    CVE-2024-57369

    Last Modified: 23 Apr 2025

    Clickjacking vulnerability in typecho v1.2.1.

    Published: 17 Jan 2025
    6.1
    Medium

    CVE-2024-45341

    Last Modified: 15 Apr 2026

    A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.

    Published: 17 Jan 2025
    7.1
    High

    CVE-2024-52870

    Last Modified: 15 Apr 2026

    Teradata Vantage Editor 1.0.1 is mostly intended for SQL database access and docs.teradata.com access, but provides unintended functionality (including Chromium Developer Tools) that can result in a client user accessing arbitrary remote websites.

    Published: 17 Jan 2025
    9.8
    Critical

    CVE-2024-57035

    Last Modified: 18 Mar 2025

    WeGIA v3.2.0 is vulnerable to SQL Injection viathe nextPage parameter in /controle/control.php.

    Published: 17 Jan 2025
    8.1
    High

    CVE-2024-57030

    Last Modified: 9 Apr 2025

    Wegia < 3.2.0 is vulnerable to Cross Site Scripting (XSS) in /geral/documentos_funcionario.php via the id parameter.

    Published: 17 Jan 2025
    9.8
    Critical

    CVE-2024-57031

    Last Modified: 24 Mar 2025

    WeGIA < 3.2.0 is vulnerable to SQL Injection in /funcionario/remuneracao.php via the id_funcionario parameter.

    Published: 17 Jan 2025
    9.8
    Critical

    CVE-2024-57032

    Last Modified: 19 Mar 2025

    WeGIA < 3.2.0 is vulnerable to Incorrect Access Control in controle/control.php. The application does not validate the value of the old password, so it is possible to change the password by placing any value in the senha_antiga field.

    Published: 17 Jan 2025
    6.1
    Medium

    CVE-2024-57033

    Last Modified: 9 Apr 2025

    WeGIA < 3.2.0 is vulnerable to Cross Site Scripting (XSS) via the dados_addInfo parameter of documentos_funcionario.php.

    Published: 17 Jan 2025
    9.8
    Critical

    CVE-2024-57034

    Last Modified: 14 Mar 2025

    WeGIA < 3.2.0 is vulnerable to SQL Injection in query_geracao_auto.php via the query parameter.

    Published: 17 Jan 2025
    4.3
    Medium

    CVE-2024-57252

    Last Modified: 22 Apr 2025

    OtCMS <=V7.46 is vulnerable to Server-Side Request Forgery (SSRF) in /admin/read.php, which can Read system files arbitrarily.

    Published: 17 Jan 2025
    4.6
    Medium

    CVE-2024-56144

    Last Modified: 28 Apr 2025

    librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to a stored XSS on the parameters (Replace $DEVICE_ID with your specific $DEVICE_ID value):`/device/$DEVICE_ID/edit` -> param: display. Librenms versions up to 24.11.0 allow remote attackers to inject malicious scripts. When a user views or interacts with the page displaying the data, the malicious script executes immediately, leading to potential unauthorized actions or data exposure. This issue has been addressed in release version 24.12.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 16 Jan 2025
    4.6
    Medium

    CVE-2025-23198

    Last Modified: 28 Apr 2025

    librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to a stored XSS on the parameters (Replace $DEVICE_ID with your specific $DEVICE_ID value):`/device/$DEVICE_ID/edit` -> param: display. Librenms versions up to 24.10.1 allow remote attackers to inject malicious scripts. When a user views or interacts with the page displaying the data, the malicious script executes immediately, leading to potential unauthorized actions or data exposure. This issue has been addressed in release version 24.11.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 16 Jan 2025
    4.6
    Medium

    CVE-2025-23199

    Last Modified: 25 Mar 2025

    librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to a stored XSS on the parameter: `/ajax_form.php` -> param: descr. Librenms version up to 24.10.1 allow remote attackers to inject malicious scripts. When a user views or interacts with the page displaying the data, the malicious script executes immediately, leading to potential unauthorized actions or data exposure. This issue has been addressed in release version 24.11.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 16 Jan 2025
    4.6
    Medium

    CVE-2025-23200

    Last Modified: 25 Mar 2025

    librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to a stored XSS on the parameter: `ajax_form.php` -> param: state. Librenms versions up to 24.10.1 allow remote attackers to inject malicious scripts. When a user views or interacts with the page displaying the data, the malicious script executes immediately, leading to potential unauthorized actions or data exposure. This issue has been addressed in release version 24.11.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 16 Jan 2025
    5.4
    Medium

    CVE-2025-23201

    Last Modified: 25 Mar 2025

    librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to Cross-site Scripting (XSS) on the parameters:`/addhost` -> param: community. Librenms versions up to 24.10.1 allow remote attackers to inject malicious scripts. When a user views or interacts with the page displaying the data, the malicious script executes immediately, leading to potential unauthorized actions or data exposure. This issue has been addressed in release version 24.11.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published: 16 Jan 2025
    —
    Unknown

    CVE-2025-0524

    Last Modified: 15 Mar 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 16 Jan 2025
    6.5
    Medium

    CVE-2025-23907

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in closed SOCIAL.NINJA allows Stored XSS. This issue affects SOCIAL.NINJA: from n/a through 0.2.

    Published: 16 Jan 2025
    5.3
    Medium

    CVE-2025-23764

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in ujjavaljani Copy Move Posts copy-move-posts.This issue affects Copy Move Posts: from n/a through <= 1.6.

    Published: 16 Jan 2025
    6.5
    Medium

    CVE-2025-23816

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in metaphorcreations Metaphor Widgets allows Stored XSS. This issue affects Metaphor Widgets: from n/a through 2.4.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23815

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in linickx root Cookie allows Cross Site Request Forgery. This issue affects root Cookie: from n/a through 1.6.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23793

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Ciprian Turcu Auto FTP auto-ftp allows Stored XSS.This issue affects Auto FTP: from n/a through <= 1.0.1.

    Published: 16 Jan 2025
    5.4
    Medium

    CVE-2025-23761

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Alex Volkov Woo Tuner allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Woo Tuner: from n/a through 0.1.2.

    Published: 16 Jan 2025
    7.1
    High

    CVE-2025-23760

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alex Volkov Chatter allows Stored XSS. This issue affects Chatter: from n/a through 1.0.1.

    Published: 16 Jan 2025
    4.3
    Medium

    CVE-2025-23957

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in surdotly Sur.ly surly allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sur.ly: from n/a through <= 3.0.3.

    Published: 16 Jan 2025
    6.5
    Medium

    CVE-2025-23965

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kopatheme Kopa Nictitate Toolkit kopa-nictitate-toolkit allows Stored XSS.This issue affects Kopa Nictitate Toolkit: from n/a through <= 1.0.2.

    Published: 16 Jan 2025
    5.4
    Medium

    CVE-2025-23961

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in wptasker WordPress Graphs & Charts graph-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Graphs & Charts: from n/a through <= 2.0.8.

    Published: 16 Jan 2025
    4.3
    Medium

    CVE-2025-23955

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in xola Xola xola-bookings-for-tours-activities allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Xola: from n/a through <= 1.6.

    Published: 16 Jan 2025
    5.4
    Medium

    CVE-2025-23963

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in flymke Mark Posts mark-posts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mark Posts: from n/a through <= 2.2.4.

    Published: 16 Jan 2025
    4.3
    Medium

    CVE-2025-23962

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in jjtrabucco Goldstar goldstar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Goldstar: from n/a through <= 2.1.1.

    Published: 16 Jan 2025
    4.3
    Medium

    CVE-2025-23954

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in awcode Salvador – AI Image Generator salvador-ai-image-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Salvador – AI Image Generator: from n/a through <= 1.0.11.

    Published: 16 Jan 2025
    6.5
    Medium

    CVE-2025-23939

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KHAN-IT Image Switcher image-switcher allows Stored XSS.This issue affects Image Switcher: from n/a through <= 1.1.

    Published: 16 Jan 2025
    6.5
    Medium

    CVE-2025-23950

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ezmarketing EZPlayer ezplayer allows Stored XSS.This issue affects EZPlayer: from n/a through <= 1.0.10.

    Published: 16 Jan 2025
    6.5
    Medium

    CVE-2025-23943

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aruvi PDF.js Shortcode pdfjs-shortcode allows Stored XSS.This issue affects PDF.js Shortcode: from n/a through <= 1.0.

    Published: 16 Jan 2025
    6.5
    Medium

    CVE-2025-23946

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Le-Pixel-Solitaire Enhanced YouTube Shortcode enhanced-youtube-shortcode allows Stored XSS.This issue affects Enhanced YouTube Shortcode: from n/a through <= 2.0.1.

    Published: 16 Jan 2025
    6.5
    Medium

    CVE-2025-23941

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in meinturnierplan MeinTurnierplan.de Widget Viewer meinturnierplande-widget-viewer allows Stored XSS.This issue affects MeinTurnierplan.de Widget Viewer: from n/a through <= 1.1.

    Published: 16 Jan 2025
    6.5
    Medium

    CVE-2025-23951

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DIVENGINE Gallery: Hybrid – Advanced Visual Gallery hybrid-gallery allows Stored XSS.This issue affects Gallery: Hybrid – Advanced Visual Gallery: from n/a through <= 1.4.0.2.

    Published: 16 Jan 2025
    6.5
    Medium

    CVE-2025-23947

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M.J WP-Player wp-player allows Stored XSS.This issue affects WP-Player: from n/a through <= 2.6.1.

    Published: 16 Jan 2025
    6.5
    Medium

    CVE-2025-23934

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sam Brodie Giveaways and Contests by PromoSimple giveaways-contests-by-promosimple allows Stored XSS.This issue affects Giveaways and Contests by PromoSimple: from n/a through <= 1.24.

    Published: 16 Jan 2025
    6.5
    Medium

    CVE-2025-23940

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in horiyuki Image Switcher image-switcher allows Stored XSS.This issue affects Image Switcher: from n/a through <= 0.1.1.

    Published: 16 Jan 2025
    6.5
    Medium

    CVE-2025-23928

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aleksandar Arsovski Google Org Chart google-org-chart allows Stored XSS.This issue affects Google Org Chart: from n/a through <= 1.0.1.

    Published: 16 Jan 2025