1961
|
- |
|
-
|
-
|
A vulnerability, which was classified as problematic, has been found in code-projects Online Book Shop 1.0. Affected by this issue is some unknown functionality of the file /subcat.php. The manipulat…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2025-0301
|
2025-01-8 03:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1962
|
- |
|
-
|
-
|
In versions 1.0.67 and lower of the Splunk App for SOAR, the Splunk documentation for that app recommended adding the `admin_all_objects` capability to the `splunk_app_soar` role. This addition could…
|
-
|
CVE-2025-22621
|
2025-01-8 02:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1963
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ali Ali Alpha Price Table For Elementor allows DOM-Based XSS.This issue affects Alpha Price Table…
|
CWE-79
Cross-site Scripting
|
CVE-2025-22500
|
2025-01-8 02:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1964
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eric McNiece EMC2 Alert Boxes allows Stored XSS.This issue affects EMC2 Alert Boxes: from n/a thr…
|
CWE-79
Cross-site Scripting
|
CVE-2025-22365
|
2025-01-8 02:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1965
|
- |
|
-
|
-
|
Missing Authorization vulnerability in ORION Allada T-shirt Designer for Woocommerce.This issue affects Allada T-shirt Designer for Woocommerce: from n/a through 1.1.
|
CWE-862
Missing Authorization
|
CVE-2025-22363
|
2025-01-8 02:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1966
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Code Themes Digi Store allows DOM-Based XSS.This issue affects Digi Store: from n/a through 1.1.4.
|
CWE-79
Cross-site Scripting
|
CVE-2025-22354
|
2025-01-8 02:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1967
|
- |
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WpIndeed Ultimate Learning Pro allows SQL Injection.This issue affects Ultimate Learning Pro: fro…
|
CWE-89
SQL Injection
|
CVE-2025-22350
|
2025-01-8 02:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1968
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FilaThemes Education LMS allows Stored XSS.This issue affects Education LMS: from n/a through 0.0…
|
CWE-79
Cross-site Scripting
|
CVE-2025-22334
|
2025-01-8 02:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1969
|
- |
|
-
|
-
|
Missing Authorization vulnerability in DearHive Social Media Share Buttons | MashShare.This issue affects Social Media Share Buttons | MashShare: from n/a through 4.0.47.
|
CWE-862
Missing Authorization
|
CVE-2025-22319
|
2025-01-8 02:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1970
|
- |
|
-
|
-
|
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Link Whisper Link Whisper Free.This issue affects Link Whisper Free: from n/a through 0.7.7.
|
CWE-538
File and Directory Information Exposure
|
CVE-2025-22306
|
2025-01-8 02:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|