Total
309433 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2023-7307 | 2025-08-29 | N/A | ||
Sangfor Behavior Management System (also referred to as DC Management System in Chinese-language documentation) contains an XML external entity (XXE) injection vulnerability in the /src/sangforindex endpoint. A remote unauthenticated attacker can submit crafted XML data containing external entity definitions, leading to potential disclosure of internal files, server-side request forgery (SSRF), or other impacts depending on parser behavior. The vulnerability is due to improper configuration of the XML parser, which allows resolution of external entities without restriction. This product is now integrated into their IAM (Internet Access Management) platform and an affected version range is undefined. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-09-06 UTC. | ||||
CVE-2025-46409 | 2025-08-29 | N/A | ||
Inadequate encryption strength issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier). If this vulnerability is exploited, a function that requires authentication may be accessed by a remote unauthenticated attacker. | ||||
CVE-2025-48305 | 1 Wordpress | 1 Wordpress | 2025-08-29 | 5.9 Medium |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vikingjs Goal Tracker for Patreon allows Stored XSS. This issue affects Goal Tracker for Patreon: from n/a through 0.4.6. | ||||
CVE-2025-48307 | 1 Wordpress | 1 Wordpress | 2025-08-29 | 7.1 High |
Cross-Site Request Forgery (CSRF) vulnerability in kasonzhao SEO For Images allows Stored XSS. This issue affects SEO For Images: from n/a through 1.0.0. | ||||
CVE-2025-48308 | 2025-08-29 | 7.1 High | ||
Cross-Site Request Forgery (CSRF) vulnerability in nonletter Newsletter subscription optin module allows Stored XSS. This issue affects Newsletter subscription optin module: from n/a through 1.2.9. | ||||
CVE-2025-48310 | 2 Wordpress, Wptableeditor | 2 Wordpress, Table Editor | 2025-08-29 | 4.3 Medium |
Cross-Site Request Forgery (CSRF) vulnerability in wptableeditor Table Editor allows Cross Site Request Forgery. This issue affects Table Editor: from n/a through 1.6.4. | ||||
CVE-2025-48312 | 1 Wordpress | 1 Wordpress | 2025-08-29 | 6.5 Medium |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 文派翻译(WP Chinese Translation) WPAvatar allows Stored XSS. This issue affects WPAvatar: from n/a through 1.9.3. | ||||
CVE-2025-48319 | 1 Wordpress | 1 Wordpress | 2025-08-29 | 5.9 Medium |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gslauraspeck Mesa Mesa Reservation Widget allows Stored XSS. This issue affects Mesa Mesa Reservation Widget: from n/a through 1.0.0. | ||||
CVE-2025-48322 | 1 Wordpress | 1 Wordpress | 2025-08-29 | 6.5 Medium |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Finn Dohrn Statify Widget allows Stored XSS. This issue affects Statify Widget: from n/a through 1.4.6. | ||||
CVE-2025-48323 | 1 Wordpress | 1 Wordpress | 2025-08-29 | 5.9 Medium |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Md Abunaser Khan Advance Food Menu allows Stored XSS. This issue affects Advance Food Menu: from n/a through 1.0. | ||||
CVE-2025-48327 | 1 Wordpress | 1 Wordpress | 2025-08-29 | 5.3 Medium |
Missing Authorization vulnerability in inkthemes WP Mailgun SMTP allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WP Mailgun SMTP: from n/a through 1.0.7. | ||||
CVE-2025-48343 | 1 Wordpress | 1 Wordpress | 2025-08-29 | 7.1 High |
Cross-Site Request Forgery (CSRF) vulnerability in Aaron Axelsen WPMU Ldap Authentication allows Stored XSS. This issue affects WPMU Ldap Authentication: from n/a through 5.0.1. | ||||
CVE-2025-48348 | 1 Wordpress | 1 Wordpress | 2025-08-29 | 4.3 Medium |
Incorrect Privilege Assignment vulnerability in chandrashekharsahu Site Offline allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Site Offline: from n/a through 1.5.7. | ||||
CVE-2025-48353 | 2025-08-29 | 7.1 High | ||
Cross-Site Request Forgery (CSRF) vulnerability in dactum Clickbank WordPress Plugin (Niche Storefront) allows Stored XSS. This issue affects Clickbank WordPress Plugin (Niche Storefront): from n/a through 1.3.5. | ||||
CVE-2025-48304 | 2025-08-29 | 7.1 High | ||
Cross-Site Request Forgery (CSRF) vulnerability in Gary Illyes Google XML News Sitemap plugin allows Stored XSS. This issue affects Google XML News Sitemap plugin: from n/a through 0.02. | ||||
CVE-2025-30036 | 1 Cgm | 1 Clininet | 2025-08-29 | N/A |
Stored XSS vulnerability exists in the "Oddział" (Ward) module, in the death diagnosis description field, and allows the execution of arbitrary JavaScript code. This can lead to session hijacking of other users and potentially to privilege escalation up to full administrative rights. | ||||
CVE-2025-30048 | 1 Cgm | 1 Clininet | 2025-08-29 | N/A |
The "serverConfig" endpoint, which returns the module configuration including credentials, is accessible without authentication. | ||||
CVE-2025-30056 | 1 Cgm | 1 Clininet | 2025-08-29 | N/A |
The RunCommand function accepts any parameter, which is then passed for execution in the shell. This allows an attacker to execute arbitrary code on the system. | ||||
CVE-2025-30059 | 1 Cgm | 1 Cgm Clininet | 2025-08-29 | N/A |
In the PrepareCDExportJSON.pl service, the "getPerfServiceIds" function is vulnerable to SQL injection. | ||||
CVE-2025-30063 | 2025-08-29 | N/A | ||
The configuration file containing database logins and passwords is readable by any local user. |