Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

CVE-2025-23949

Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mihajlovic Nenad Improved Sale Badges – Free Version allows PHP Local File Inclusion. This issue affects Improved Sale Badges – Free Version: from n/a through 1.0.1.

CVSS: HIGH (8.1)

EPSS Score: 0.04%

Source: CVE
January 23rd, 2025 (3 months ago)

CVE-2025-23948

Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WebArea Background animation blocks allows PHP Local File Inclusion. This issue affects Background animation blocks: from n/a through 2.1.5.

CVSS: HIGH (8.1)

EPSS Score: 0.04%

Source: CVE
January 23rd, 2025 (3 months ago)

CVE-2025-23944

Description: Deserialization of Untrusted Data vulnerability in WOOEXIM.COM WOOEXIM allows Object Injection. This issue affects WOOEXIM: from n/a through 5.0.0.

CVSS: HIGH (8.8)

EPSS Score: 0.04%

Source: CVE
January 23rd, 2025 (3 months ago)

CVE-2025-23938

Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NotFound Image Gallery Box by CRUDLab allows PHP Local File Inclusion. This issue affects Image Gallery Box by CRUDLab: from n/a through 1.0.3.

CVSS: HIGH (7.5)

EPSS Score: 0.04%

Source: CVE
January 23rd, 2025 (3 months ago)

CVE-2025-23910

Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Menus Plus+ allows SQL Injection. This issue affects Menus Plus+: from n/a through 1.9.6.

CVSS: HIGH (8.5)

EPSS Score: 0.04%

Source: CVE
January 23rd, 2025 (3 months ago)

CVE-2025-23882

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Download Codes allows Reflected XSS. This issue affects WP Download Codes: from n/a through 2.5.4.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
January 23rd, 2025 (3 months ago)

CVE-2025-23874

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WP Block Pack allows Reflected XSS. This issue affects WP Block Pack: from n/a through 1.1.6.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
January 23rd, 2025 (3 months ago)

CVE-2025-23867

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WordPress File Search allows Reflected XSS. This issue affects WordPress File Search: from n/a through 1.2.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
January 23rd, 2025 (3 months ago)

CVE-2025-23866

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound EU DSGVO Helper allows Reflected XSS. This issue affects EU DSGVO Helper: from n/a through 1.0.6.1.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
January 23rd, 2025 (3 months ago)

CVE-2025-23846

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kolja Nolte Flexible Blogtitle allows Reflected XSS. This issue affects Flexible Blogtitle: from n/a through 0.1.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
January 23rd, 2025 (3 months ago)