281
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Faaiq Ahmed, Technial Architect,faaiqsj@gmail.com Simple Custom post type custom field allows Ref…
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-23500
|
2025-01-23 00:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
282
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Translation.Pro allows Reflected XSS. This issue affects Translation.Pro: from n/a throu…
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-23498
|
2025-01-23 00:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
283
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WooCommerce Order Search allows Reflected XSS. This issue affects WooCommerce Order Sear…
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-23495
|
2025-01-23 00:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
284
|
- |
|
-
|
-
|
Missing Authorization vulnerability in NotFound Database Sync allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Database Sync: from n/a through 0.5.1.
New
|
CWE-862
Missing Authorization
|
CVE-2025-23486
|
2025-01-23 00:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
285
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound History timeline allows Reflected XSS. This issue affects History timeline: from n/a thr…
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-23475
|
2025-01-23 00:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
286
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound FWD Slider allows Reflected XSS. This issue affects FWD Slider: from n/a through 1.0.
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-23462
|
2025-01-23 00:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
287
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Simple shortcode buttons allows Reflected XSS. This issue affects Simple shortcode butto…
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-23449
|
2025-01-23 00:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
288
|
- |
|
-
|
-
|
A SQL Injection vulnerability exists in Senayan Library Management System SLiMS 9 Bulian 9.6.1 via the tempLoanID parameter in the loan form on /admin/modules/circulation/loan.php.
New
|
-
|
CVE-2025-22980
|
2025-01-23 00:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
289
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Mapbox for WP Advanced allows Reflected XSS. This issue affects Mapbox for WP Advanced: …
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-22772
|
2025-01-23 00:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
290
|
5.4 |
MEDIUM
Network
|
-
|
-
|
A flaw was found in Keycloak. When an Active Directory user resets their password, the system updates it without performing an LDAP bind to validate the new credentials against AD. This vulnerability…
New
|
CWE-287
Improper Authentication
|
CVE-2025-0604
|
2025-01-23 00:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|