CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

CVE-2025-23634

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Youtube Video Grid allows Reflected XSS. This issue affects Youtube Video Grid: from n/a through 1.9.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
January 24th, 2025 (5 months ago)

CVE-2025-23629

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Subhasis Laha Gallerio allows Reflected XSS. This issue affects Gallerio: from n/a through 1.0.1.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
January 24th, 2025 (5 months ago)

CVE-2025-23628

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in New Media One GeoDigs allows Reflected XSS. This issue affects GeoDigs: from n/a through 3.4.1.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
January 24th, 2025 (5 months ago)

CVE-2025-23626

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hidetoshi Fukushima Kumihimo allows Reflected XSS. This issue affects Kumihimo: from n/a through 1.0.2.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
January 24th, 2025 (5 months ago)

CVE-2025-23624

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alessandro Benoit WpDevTool allows Reflected XSS. This issue affects WpDevTool: from n/a through 0.1.1.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
January 24th, 2025 (5 months ago)

CVE-2025-23545

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Navnish Bhardwaj WP Social Broadcast allows Reflected XSS. This issue affects WP Social Broadcast: from n/a through 1.0.0.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
January 24th, 2025 (5 months ago)

CVE-2025-23544

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in heart5 StatPressCN allows Reflected XSS. This issue affects StatPressCN: from n/a through 1.9.1.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
January 24th, 2025 (5 months ago)

CVE-2025-23541

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in edmon Download, Downloads allows Reflected XSS. This issue affects Download, Downloads : from n/a through 1.4.2.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
January 24th, 2025 (5 months ago)

CVE-2025-23540

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mohsin khan WP Front-end login and register allows Reflected XSS. This issue affects WP Front-end login and register: from n/a through 2.1.0.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
January 24th, 2025 (5 months ago)

CVE-2025-22768

Description: Cross-Site Request Forgery (CSRF) vulnerability in Qwerty23 Rocket Media Library Mime Type allows Stored XSS. This issue affects Rocket Media Library Mime Type: from n/a through 2.1.0.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
January 24th, 2025 (5 months ago)