821
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in Venugopal Show notice or message on admin area allows Stored XSS. This issue affects Show notice or message on admin area: from n/a through 2.0.
|
CWE-352
Origin Validation Error
|
CVE-2025-25075
|
2025-02-7 19:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
822
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in Nirmal Kumar Ram WP Social Stream allows Stored XSS. This issue affects WP Social Stream: from n/a through 1.1.
|
CWE-352
Origin Validation Error
|
CVE-2025-25074
|
2025-02-7 19:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
823
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vasilis Triantafyllou Easy WP Tiles allows Stored XSS. This issue affects Easy WP Tiles: from n/a…
|
CWE-79
Cross-site Scripting
|
CVE-2025-25073
|
2025-02-7 19:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
824
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in thunderbax WP Admin Custom Page allows Stored XSS. This issue affects WP Admin Custom Page: from n/a through 1.5.0.
|
CWE-352
Origin Validation Error
|
CVE-2025-25072
|
2025-02-7 19:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
825
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in topplugins Vignette Ads allows Stored XSS. This issue affects Vignette Ads: from n/a through 0.2.
|
CWE-352
Origin Validation Error
|
CVE-2025-25071
|
2025-02-7 19:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
826
|
- |
|
-
|
-
|
A security vulnerability has been identified in the IBL Software Engineering Visual Weather and derived products (NAMIS, Aero Weather, Satellite Weather). The vulnerability is present in the Product …
|
-
|
CVE-2025-1077
|
2025-02-7 18:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
827
|
- |
|
-
|
-
|
Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. If a target visits a malicious page or opens a malici…
|
-
|
CVE-2025-22880
|
2025-02-7 17:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
828
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Builder Shortcode Extras – WordPress Shortcodes Collection to Save You Time plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.0 via the 'bse-ele…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-13841
|
2025-02-7 16:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
829
|
- |
|
-
|
-
|
A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions starting from 7.14.1 prior to 17.3.7, 17.4 prior to 17.4.4, and 17.5 prior to 17.5.2. A denial of service co…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2025-1072
|
2025-02-7 13:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
830
|
- |
|
-
|
-
|
Dell Update Manager Plugin, version(s) 1.5.0 through 1.6.0, contain(s) an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability. A low privileged attacker with r…
|
CWE-80
Basic XSS
|
CVE-2025-22402
|
2025-02-7 12:15 |
2025-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|