Export limit exceeded: 12709 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (12709 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-3211 1 Dmparekh 1 Wordpress Database Administrator 2025-06-11 9.8 Critical
The WordPress Database Administrator WordPress plugin through 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
CVE-2024-48228 1 Funadmin 1 Funadmin 2025-06-10 6.1 Medium
An issue was found in funadmin 5.0.2. The selectfiles method in \backend\controller\sys\Attachh.php directly stores the passed parameters and values into the param parameter without filtering, resulting in Cross Site Scripting (XSS).
CVE-2024-8474 1 Openvpn 1 Connect 2025-06-10 7.5 High
OpenVPN Connect before version 3.5.0 can contain the configuration profile's clear-text private key which is logged in the application log, which an unauthorized actor can use to decrypt the VPN traffic
CVE-2024-12400 1 Goodlayers 1 Tour Master 2025-06-09 7.1 High
The tourmaster WordPress plugin before 5.3.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.
CVE-2024-12163 1 Goodlayers 1 Goodlayers Core 2025-06-09 6.5 Medium
The goodlayers-core WordPress plugin before 2.1.3 allows users with a subscriber role and above to upload SVGs containing malicious payloads.
CVE-2025-44148 1 Mailenable 1 Mailenable 2025-06-09 9.8 Critical
Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx component
CVE-2025-2917 1 1000mz 1 Chestnutcms 2025-06-09 4.3 Medium
A vulnerability, which was classified as problematic, was found in ChestnutCMS up to 1.5.3. Affected is the function readFile of the file /dev-api/cms/file/read. The manipulation of the argument filePath leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-23216 2 Argoproj, Redhat 2 Argo Cd, Openshift Gitops 2025-06-06 6.8 Medium
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vulnerability was discovered in Argo CD that exposed secret values in error messages and the diff view when an invalid Kubernetes Secret resource was synced from a repository. The vulnerability assumes the user has write access to the repository and can exploit it, either intentionally or unintentionally, by committing an invalid Secret to repository and triggering a Sync. Once exploited, any user with read access to Argo CD can view the exposed secret data. The vulnerability is fixed in v2.13.4, v2.12.10, and v2.11.13.
CVE-2024-55573 1 Centreon 1 Centreon Web 2025-06-06 9.1 Critical
An issue was discovered in Centreon centreon-web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x before 23.04.24. A user with high privileges is able to inject SQL into the form used to create virtual metrics.
CVE-2024-11356 1 Goodlayers 1 Tour Master 2025-06-05 6.1 Medium
The tourmaster WordPress plugin before 5.3.4 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated users to perform Cross-Site Scripting attacks.
CVE-2025-3597 1 Firelightwp 1 Firelight Lightbox 2025-06-05 5.9 Medium
The Firelight Lightbox WordPress plugin before 2.3.15 does not prevent users with post writing capabilities from executing arbitrary Javascript when the jQuery Metadata library is enabled. While this feature is meant to only be available to Pro version users, it can be activated in the free version too, making it theoretically exploitable there as well.
CVE-2025-3649 1 Lightpress 1 Lightbox 2025-06-05 6.8 Medium
The LightPress Lightbox WordPress plugin before 2.3.4 does not check download links point to valid, non-Javascript URLs, allowing users with at least the contributor role to conduct Stored XSS attacks.
CVE-2025-45387 1 Osticket 1 Osticket 2025-06-05 5.4 Medium
osTicket prior to v1.17.6 and v1.18.2 are vulnerable to Broken Access Control Vulnerability in /scp/ajax.php.
CVE-2024-40747 1 Joomla 1 Joomla\! 2025-06-04 6.1 Medium
Various module chromes didn't properly process inputs, leading to XSS vectors.
CVE-2024-40748 1 Joomla 1 Joomla\! 2025-06-04 7.5 High
Lack of output escaping in the id attribute of menu lists.
CVE-2024-40749 1 Joomla 1 Joomla\! 2025-06-04 7.5 High
Improper Access Controls allows access to protected views.
CVE-2024-48905 1 Sematell 1 Replyone 2025-06-04 9.1 Critical
Sematell ReplyOne 7.4.3.0 has Insecure Permissions for the /rest/sessions endpoint.
CVE-2024-48906 1 Sematell 1 Replyone 2025-06-04 6.1 Medium
Sematell ReplyOne 7.4.3.0 allows XSS via a ReplyDesk e-mail attachment name.
CVE-2024-48907 1 Sematell 1 Replyone 2025-06-04 7.5 High
Sematell ReplyOne 7.4.3.0 allows SSRF via the application server API.
CVE-2023-42866 1 Apple 6 Ipados, Iphone Os, Macos and 3 more 2025-06-03 8.8 High
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, tvOS 16.6, Safari 16.6, watchOS 9.6. Processing web content may lead to arbitrary code execution.