Aggregator
GITEX GLOBAL 2025
1 week 2 days hence
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
1 hour 55 minutes ago
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
CVE-2025-10383 | Contest Gallery Plugin up to 27.0.2 on WordPress cross site scripting
2 hours 31 minutes ago
A vulnerability described as problematic has been identified in Contest Gallery Plugin up to 27.0.2 on WordPress. The impacted element is an unknown function. The manipulation results in cross site scripting.
This vulnerability is reported as CVE-2025-10383. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2025-9952 | Trinity Audio Plugin up to 5.20.2 on WordPress range-date cross site scripting
2 hours 32 minutes ago
A vulnerability marked as problematic has been reported in Trinity Audio Plugin up to 5.20.2 on WordPress. The affected element is an unknown function. The manipulation of the argument range-date leads to cross site scripting.
This vulnerability is documented as CVE-2025-9952. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2025-9030 | Majestic Before After Image Plugin up to 2.0.1/2.0.2 on WordPress before_label/after_label cross site scripting
2 hours 32 minutes ago
A vulnerability labeled as problematic has been found in Majestic Before After Image Plugin up to 2.0.1/2.0.2 on WordPress. Impacted is an unknown function. Executing manipulation of the argument before_label/after_label can lead to cross site scripting.
This vulnerability is registered as CVE-2025-9030. It is possible to launch the attack remotely. No exploit is available.
vuldb.com
CVE-2025-8726 | WP Photo Album Plus Plugin up to 9.0.11.006 on WordPress wppa_user_upload cross site scripting
2 hours 32 minutes ago
A vulnerability identified as problematic has been detected in WP Photo Album Plus Plugin up to 9.0.11.006 on WordPress. This issue affects the function wppa_user_upload. Performing manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2025-8726. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-11228 | GiveWP Plugin up to 4.10.0 on WordPress registerAssociateFormsWithCampaign authorization
2 hours 32 minutes ago
A vulnerability categorized as critical has been discovered in GiveWP Plugin up to 4.10.0 on WordPress. This vulnerability affects the function registerAssociateFormsWithCampaign. Such manipulation leads to missing authorization.
This vulnerability is listed as CVE-2025-11228. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2025-10746 | Integrate Dynamics 365 CRM Plugin up to 1.0.9 on WordPress Configuration authorization
2 hours 32 minutes ago
A vulnerability was found in Integrate Dynamics 365 CRM Plugin up to 1.0.9 on WordPress. It has been rated as critical. This affects an unknown part of the component Configuration Handler. This manipulation causes missing authorization.
This vulnerability is tracked as CVE-2025-10746. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
CVE-2025-9243 | Cost Calculator Builder Plugin up to 3.5.32 on WordPress get_cc_orders/update_order_status authorization
2 hours 32 minutes ago
A vulnerability was found in Cost Calculator Builder Plugin up to 3.5.32 on WordPress. It has been declared as critical. Affected by this issue is the function get_cc_orders/update_order_status. The manipulation results in missing authorization.
This vulnerability is identified as CVE-2025-9243. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2025-9029 | WDesignKit Plugin up to 1.2.16 on WordPress wdkit_handle_review_submission authorization
2 hours 33 minutes ago
A vulnerability was found in WDesignKit Plugin up to 1.2.16 on WordPress. It has been classified as critical. Affected by this vulnerability is the function wdkit_handle_review_submission. The manipulation leads to missing authorization.
This vulnerability is referenced as CVE-2025-9029. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2025-9485 | OAuth Single Sign On Plugin up to 6.26.12 on WordPress get_resource_owner_from_id_token improper authentication
2 hours 33 minutes ago
A vulnerability was found in OAuth Single Sign On Plugin up to 6.26.12 on WordPress and classified as critical. Affected is the function get_resource_owner_from_id_token. Executing manipulation can lead to improper authentication.
The identification of this vulnerability is CVE-2025-9485. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-11227 | GiveWP Plugin up to 4.10.0 on WordPress authorization
2 hours 33 minutes ago
A vulnerability has been found in GiveWP Plugin up to 4.10.0 on WordPress and classified as problematic. This impacts an unknown function. Performing manipulation results in missing authorization.
This vulnerability was named CVE-2025-11227. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2025-9886 | Trinity Audio Plugin up to 5.20.2 on WordPress post-management.php cross-site request forgery
2 hours 33 minutes ago
A vulnerability, which was classified as problematic, was found in Trinity Audio Plugin up to 5.20.2 on WordPress. This affects an unknown function of the file /admin/inc/post-management.php. Such manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2025-9886. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2021-42193 | nopCommerce 4.40.3 Product Name /Admin/Product/Edit/ cross site scripting
2 hours 35 minutes ago
A vulnerability, which was classified as problematic, has been found in nopCommerce 4.40.3. The impacted element is an unknown function of the file /Admin/Product/Edit/ of the component Product Name Handler. This manipulation causes cross site scripting.
This vulnerability is handled as CVE-2021-42193. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2025-52658 | HCL MyXalytics 6.6 privilege escalation (KB0124411)
2 hours 35 minutes ago
A vulnerability classified as problematic was found in HCL MyXalytics 6.6. The affected element is an unknown function. The manipulation results in privilege escalation.
This vulnerability is known as CVE-2025-52658. It is possible to launch the attack remotely. No exploit is available.
vuldb.com
CVE-2025-52654 | HCL MyXalytics 6.6 cross site scripting (KB0124411)
2 hours 35 minutes ago
A vulnerability classified as problematic has been found in HCL MyXalytics 6.6. Impacted is an unknown function. The manipulation leads to basic cross site scripting.
This vulnerability is traded as CVE-2025-52654. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-57714 | QNAP NetBak Replicator 4.5.12.1108 unquoted search path (qsa-25-39)
2 hours 35 minutes ago
A vulnerability described as problematic has been identified in QNAP NetBak Replicator 4.5.12.1108. This issue affects some unknown processing. Executing manipulation can lead to unquoted search path.
This vulnerability appears as CVE-2025-57714. The attack requires local access. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2025-52656 | HCL MyXalytics 6.6 sensitive dynamically-determined object attributes (KB0124411)
2 hours 36 minutes ago
A vulnerability marked as critical has been reported in HCL MyXalytics 6.6. This vulnerability affects unknown code. Performing manipulation of the argument sensitive results in dynamically-determined object attributes.
This vulnerability is reported as CVE-2025-52656. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
CVE-2025-56551 | DirectAdmin 1.680 Login Interface improper authorization
2 hours 36 minutes ago
A vulnerability labeled as critical has been found in DirectAdmin 1.680. This affects an unknown part of the component Login Interface. Such manipulation leads to improper authorization.
This vulnerability is documented as CVE-2025-56551. The attack can be executed remotely. There is not any exploit available.
vuldb.com