601
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Faaiq Pretty Url allows Reflected XSS. This issue affects Pretty Url: from n/a through 1.5.4.
|
CWE-79
Cross-site Scripting
|
CVE-2025-22564
|
2025-01-31 18:15 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
602
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mohammad Hossein Aghanabi Hide Login+ allows Reflected XSS. This issue affects Hide Login+: from …
|
CWE-79
Cross-site Scripting
|
CVE-2025-22341
|
2025-01-31 18:15 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
603
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bryan Shanaver @ fiftyandfifty.org CloudFlare(R) Cache Purge allows Reflected XSS. This issue aff…
|
CWE-79
Cross-site Scripting
|
CVE-2025-22332
|
2025-01-31 18:15 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
604
|
- |
|
-
|
-
|
Missing Authorization vulnerability in mgplugin EMI Calculator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects EMI Calculator: from n/a through 1.1.
|
CWE-862
Missing Authorization
|
CVE-2025-22265
|
2025-01-31 18:15 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
605
|
- |
|
-
|
-
|
Server-Side Request Forgery (SSRF) vulnerability in NotFound Oshine Modules. This issue affects Oshine Modules: from n/a through n/a.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-44055
|
2025-01-31 18:15 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
606
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The WP DataTable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 0.2.6 due to insufficient input sanitization and output…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13566
|
2025-01-31 18:15 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
607
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Podcast RSS Feed in all versions up to, and including, 5.9.…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13157
|
2025-01-31 18:15 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
608
|
- |
|
-
|
-
|
Bentley Systems ProjectWise Integration Server before 10.00.03.288 allows unintended SQL query execution by an authenticated user via an API call.
|
-
|
CVE-2024-53007
|
2025-01-31 17:15 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
609
|
- |
|
-
|
-
|
An issue was discovered in GFI Kerio Control 9.2.5 through 9.4.5. The dest GET parameter passed to the /nonauth/addCertException.cs and /nonauth/guestConfirm.cs and /nonauth/expiration.cs pages is no…
|
-
|
CVE-2024-52875
|
2025-01-31 17:15 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
610
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Custom Login Page Styler – Limit Login Attempts – Restrict Content With Login – Redirect After Login – Change Login URL – Sign in , Sign out plugin for WordPress is vulnerable to unauthorized acc…
|
CWE-862
Missing Authorization
|
CVE-2024-13530
|
2025-01-31 17:15 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|