Medium · CVSS 4.4
In ccu, there is a possible out of bounds read due to a logic error. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07570864; Issue ID: ALPS07570864.
Published Feb 6, 2023 · Updated Mar 26, 2025
Medium · CVSS 5.4
The Event Manager and Tickets Selling Plugin for WooCommerce WordPress plugin before 3.8.0 does not validate and escape some of its post meta before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Published Feb 6, 2023 · Updated Mar 26, 2025
Medium · CVSS 5.4
The GamiPress WordPress plugin before 1.0.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Published Feb 6, 2023 · Updated Mar 25, 2025
Medium · CVSS 5.3
A vulnerability was found in BDCOM 1704-WGL 2.0.6314. It has been classified as critical. This affects an unknown part of the file /param.file.tgz of the component Backup File Handler. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The identifier VDB-220101 was assigned to this vulnerability.
Published Feb 3, 2023 · Updated Mar 25, 2025
Medium · CVSS 6.5
Improper access control in Devolutions Server allows an authenticated user to access unauthorized sensitive data.
Published Feb 3, 2023 · Updated Mar 25, 2025
Medium · CVSS 5.4
The ResponsiveVoice Text To Speech WordPress plugin before 1.7.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Published Feb 6, 2023 · Updated Mar 25, 2025
Medium · CVSS 5.4
The WP VR WordPress plugin before 8.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Published Feb 6, 2023 · Updated Mar 25, 2025
Medium · CVSS 5.4
The Send PDF for Contact Form 7 WordPress plugin before 0.9.9.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
Published Feb 6, 2023 · Updated Mar 25, 2025
Medium · CVSS 5.4
The ExactMetrics WordPress plugin before 7.12.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Published Feb 6, 2023 · Updated Mar 25, 2025
Medium · CVSS 5.4
The WordPrezi WordPress plugin before 0.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Published Feb 6, 2023 · Updated Mar 25, 2025
High · CVSS 7.5
EMC NetWorker may potentially be vulnerable to an unauthenticated remote code execution vulnerability in the NetWorker Client execution service (nsrexecd) irrespective of any auth used.
Published Feb 3, 2023 · Updated Mar 25, 2025
High · CVSS 7.5
hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.
Published Feb 4, 2023 · Updated Mar 25, 2025
Critical · CVSS 9.8
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the host_time parameter in the NTPSyncWithHost function.
Published Feb 3, 2023 · Updated Mar 25, 2025
Critical · CVSS 9.9
Code Injection in GitHub repository froxlor/froxlor prior to 2.0.10.
Published Feb 4, 2023 · Updated Mar 25, 2025
Medium · CVSS 5.4
The Flexible Captcha WordPress plugin through 4.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Published Feb 6, 2023 · Updated Mar 25, 2025
Medium · CVSS 5.4
The jQuery T(-) Countdown Widget WordPress plugin before 2.3.24 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Published Feb 6, 2023 · Updated Mar 25, 2025
Medium · CVSS 5.4
The Vimeo Video Autoplay Automute WordPress plugin through 1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Published Feb 6, 2023 · Updated Mar 25, 2025
High · CVSS 8.1
IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects. IBM X-Force ID: 245513.
Published Feb 3, 2023 · Updated Mar 25, 2025
Medium · CVSS 6.1
Rapid7 Metasploit Pro versions 4.21.2 and lower suffer from a stored cross site scripting vulnerability, due to a lack of JavaScript request string sanitization. Using this vulnerability, an authenticated attacker can execute arbitrary HTML and script code in the target browser against another Metasploit Pro user using a specially crafted request. Note that in most deployments, all Metasploit Pro users tend to enjoy privileges equivalent to local administrator.
Published Feb 1, 2023 · Updated Mar 25, 2025
Medium · CVSS 5.5
A memory leak flaw and potential divide by zero and Integer overflow was found in the Linux kernel V4L2 and vivid test code functionality. This issue occurs when a user triggers ioctls, such as VIDIOC_S_DV_TIMINGS ioctl. This could allow a local user to crash the system if vivid test code enabled.
Published Feb 6, 2023 · Updated Mar 25, 2025
High · CVSS 7.5
On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.0 before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a BIG-IP Advanced WAF or BIG-IP ASM security policy is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published Feb 1, 2023 · Updated Mar 25, 2025
High · CVSS 8.1
Versions of Coverity Connect prior to 2022.12.0 are vulnerable to an unauthenticated Cross-Site Scripting vulnerability. Any web service hosted on the same sub domain can set a cookie for the whole subdomain which can be used to bypass other mitigations in place for malicious purposes. CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/RL:O/RC:C
Published Feb 6, 2023 · Updated Mar 25, 2025
Medium · CVSS 6.1
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.4 and prior may allow an authenticated remote attacker to perform a reflected cross-site scripting (XSS) attack in multiple features.
Upgrade to Apache Sling App CMS >= 1.1.6
Published Feb 4, 2023 · Updated Mar 25, 2025
Medium · CVSS 6.4
In ccu, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07512839; Issue ID: ALPS07512839.
Published Feb 6, 2023 · Updated Mar 25, 2025
Critical · CVSS 9.1
Stack overflow vulnerability in the NFC module.Successful exploitation of this vulnerability may affect service availability and integrity.
Published Feb 18, 2024 · Updated Mar 25, 2025
Critical · CVSS 9.8
TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the country parameter at setting/delStaticDhcpRules.
Published Feb 6, 2023 · Updated Mar 25, 2025
High · CVSS 7.5
Couchbase Server before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2 exposes Sensitive Information to an Unauthorized Actor.
Published Feb 6, 2023 · Updated Mar 25, 2025
Medium · CVSS 6.1
The Tutor LMS WordPress plugin before 2.0.10 does not sanitise and escape the reset_key and user_id parameters before outputting then back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Published Feb 6, 2023 · Updated Mar 25, 2025
Medium · CVSS 5.4
The Gallery Factory Lite WordPress plugin through 2.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Published Feb 6, 2023 · Updated Mar 25, 2025
Medium · CVSS 5.4
The Page View Count WordPress plugin before 2.6.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Published Feb 6, 2023 · Updated Mar 25, 2025
Medium · CVSS 5.4
The Drag & Drop Sales Funnel Builder for WordPress plugin before 2.6.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Published Feb 6, 2023 · Updated Mar 25, 2025
High · CVSS 8.8
The SiteGround Security WordPress plugin before 1.3.1 does not properly sanitize user input before using it in an SQL query, leading to an authenticated SQL injection issue.
Published Feb 6, 2023 · Updated Mar 25, 2025
Medium · CVSS 5.4
The EAN for WooCommerce WordPress plugin before 4.4.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Published Feb 6, 2023 · Updated Mar 25, 2025
Medium · CVSS 5.4
The Html5 Audio Player WordPress plugin before 2.1.12 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Published Feb 6, 2023 · Updated Mar 25, 2025
Medium · CVSS 5.4
The Cloak Front End Email WordPress plugin before 1.9.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Published Feb 6, 2023 · Updated Mar 25, 2025
Medium · CVSS 5.4
The MonsterInsights WordPress plugin before 8.12.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Published Feb 6, 2023 · Updated Mar 25, 2025
Medium · CVSS 5.4
The Happyforms WordPress plugin before 1.22.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Published Feb 6, 2023 · Updated Mar 25, 2025
Medium · CVSS 5.4
The Giveaways and Contests by RafflePress WordPress plugin before 1.11.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Published Feb 6, 2023 · Updated Mar 25, 2025
Medium · CVSS 5.4
The WC Vendors Marketplace WordPress plugin before 2.4.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Published Feb 6, 2023 · Updated Mar 25, 2025
Medium · CVSS 5.4
The Naver Map WordPress plugin through 1.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Published Feb 6, 2023 · Updated Mar 25, 2025
Medium · CVSS 5.4
The Contextual Related Posts WordPress plugin before 3.3.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Published Feb 6, 2023 · Updated Mar 25, 2025
Medium · CVSS 6.1
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. XSS, with resultant session stealing, can occur via JavaScript code in a link (for a webmail redirection endpoint) within en email message, e.g., if a victim clicks on that link within Zimbra webmail.
Published Feb 13, 2024 · Updated Mar 25, 2025
High · CVSS 8.1
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in GitHub repository answerdev/answer prior to 1.0.4.
Published Feb 8, 2023 · Updated Mar 25, 2025
High · CVSS 7
Dell Command Intel vPro Out of Band, versions prior to 4.3.1, contain an Improper Authorization vulnerability. A locally authenticated malicious users could potentially exploit this vulnerability in order to write arbitrary files to the system.
Published Feb 7, 2023 · Updated Mar 25, 2025
High · CVSS 8.2
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4.
Published Feb 8, 2023 · Updated Mar 25, 2025
High · CVSS 8
Cross-site Scripting (XSS) - DOM in GitHub repository answerdev/answer prior to 1.0.4.
Published Feb 8, 2023 · Updated Mar 25, 2025
High · CVSS 8
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4.
Published Feb 8, 2023 · Updated Mar 25, 2025
High · CVSS 8.2
Cross-site Scripting (XSS) - Generic in GitHub repository answerdev/answer prior to 1.0.4.
Published Feb 8, 2023 · Updated Mar 25, 2025
Critical · CVSS 9.8
Improper Access Control in GitHub repository answerdev/answer prior to 1.0.4.
Published Feb 8, 2023 · Updated Mar 25, 2025
Medium · CVSS 6.5
Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.5.4.
Published Feb 7, 2023 · Updated Mar 25, 2025