Aggregator
CVE-2025-2804 | Composer Plugin up to 5.3 on WordPress account_id/account_username cross site scripting
11 months 3 weeks ago
A vulnerability was found in Composer Plugin up to 5.3 on WordPress. It has been classified as problematic. Affected is an unknown function. The manipulation of the argument account_id/account_username leads to cross site scripting.
This vulnerability is traded as CVE-2025-2804. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-2878 | Kentico CMS up to 13.0.178 Additional Database Installation Wizard /CMSInstall/install.aspx new database cross site scripting
11 months 3 weeks ago
A vulnerability was found in Kentico CMS up to 13.0.178. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /CMSInstall/install.aspx of the component Additional Database Installation Wizard. The manipulation of the argument new database leads to cross site scripting.
This vulnerability is known as CVE-2025-2878. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-2074 | webfactory Advanced Google reCAPTCHA Plugin up to 1.29 on WordPress sSearch sql injection
11 months 3 weeks ago
A vulnerability, which was classified as critical, was found in webfactory Advanced Google reCAPTCHA Plugin up to 1.29 on WordPress. Affected is an unknown function. The manipulation of the argument sSearch leads to sql injection.
This vulnerability is traded as CVE-2025-2074. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-2578 | Booking for Appointments and Events Calendar – Amelia Plugin wpAmeliaApiCall information disclosure
11 months 3 weeks ago
A vulnerability was found in Booking for Appointments and Events Calendar – Amelia Plugin up to 1.2.19 on WordPress and classified as problematic. Affected by this issue is the function wpAmeliaApiCall. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2025-2578. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-1705 | tagDiv Composer Plugin up to 5.3 on WordPress td_ajax_get_views cross-site request forgery
11 months 3 weeks ago
A vulnerability was found in tagDiv Composer Plugin up to 5.3 on WordPress. It has been declared as problematic. This vulnerability affects the function td_ajax_get_views. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2025-1705. The attack can be initiated remotely. There is no exploit available.
vuldb.com
每周蓝军技术推送(2025.3.22-3.28)
11 months 3 weeks ago
关注高级攻防对抗技术热点,研究对手技术进行高级威胁模拟,研判攻击安全发展方向。
每周蓝军技术推送(2025.3.22-3.28)
11 months 3 weeks ago
关注高级攻防对抗技术热点,研究对手技术进行高级威胁模拟,研判攻击安全发展方向。
每周蓝军技术推送(2025.3.22-3.28)
11 months 3 weeks ago
关注高级攻防对抗技术热点,研究对手技术进行高级威胁模拟,研判攻击安全发展方向。
每周蓝军技术推送(2025.3.22-3.28)
11 months 3 weeks ago
关注高级攻防对抗技术热点,研究对手技术进行高级威胁模拟,研判攻击安全发展方向。
每周蓝军技术推送(2025.3.22-3.28)
11 months 3 weeks ago
关注高级攻防对抗技术热点,研究对手技术进行高级威胁模拟,研判攻击安全发展方向。
每周蓝军技术推送(2025.3.22-3.28)
11 months 3 weeks ago
关注高级攻防对抗技术热点,研究对手技术进行高级威胁模拟,研判攻击安全发展方向。
每周蓝军技术推送(2025.3.22-3.28)
11 months 3 weeks ago
关注高级攻防对抗技术热点,研究对手技术进行高级威胁模拟,研判攻击安全发展方向。
独立SyntaxFlow功能?IRify,启动!
11 months 3 weeks ago
使用独立的SyntaxFlow软件IRify,来一场全新的代码审计!
独立SyntaxFlow功能?IRify,启动!
11 months 3 weeks ago
使用独立的SyntaxFlow软件IRify,来一场全新的代码审计!
独立SyntaxFlow功能?IRify,启动!
11 months 3 weeks ago
使用独立的SyntaxFlow软件IRify,来一场全新的代码审计!
独立SyntaxFlow功能?IRify,启动!
11 months 3 weeks ago
使用独立的SyntaxFlow软件IRify,来一场全新的代码审计!
独立SyntaxFlow功能?IRify,启动!
11 months 3 weeks ago
使用独立的SyntaxFlow软件IRify,来一场全新的代码审计!
独立SyntaxFlow功能?IRify,启动!
11 months 3 weeks ago
使用独立的SyntaxFlow软件IRify,来一场全新的代码审计!
独立SyntaxFlow功能?IRify,启动!
11 months 3 weeks ago
使用独立的SyntaxFlow软件IRify,来一场全新的代码审计!