Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

CVE-2025-30962

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound FS Poster allows Reflected XSS. This issue affects FS Poster: from n/a through 6.5.8.

CVSS: HIGH (7.1)

EPSS Score: 0.03%

Source: CVE
April 15th, 2025 (5 days ago)

CVE-2025-26959

Description: Missing Authorization vulnerability in Quý Lê 91 Administrator Z allows Privilege Escalation. This issue affects Administrator Z: from n/a through 2025.03.24.

CVSS: HIGH (8.8)

EPSS Score: 0.04%

Source: CVE
April 15th, 2025 (5 days ago)

CVE-2025-26958

Description: Missing Authorization vulnerability in NotFound JetBlog allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects JetBlog: from n/a through 2.4.3.

CVSS: HIGH (7.5)

EPSS Score: 0.03%

Source: CVE
April 15th, 2025 (5 days ago)

CVE-2025-26954

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 1pluginjquery ZooEffect allows Reflected XSS. This issue affects ZooEffect: from n/a through 1.11.

CVSS: HIGH (7.1)

EPSS Score: 0.03%

Source: CVE
April 15th, 2025 (5 days ago)

CVE-2025-26944

Description: Missing Authorization vulnerability in NotFound JetPopup allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects JetPopup: from n/a through 2.0.11.

CVSS: HIGH (7.5)

EPSS Score: 0.03%

Source: CVE
April 15th, 2025 (5 days ago)

CVE-2025-26942

Description: Missing Authorization vulnerability in NotFound JetTricks allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects JetTricks: from n/a through 1.5.1.

CVSS: HIGH (7.5)

EPSS Score: 0.03%

Source: CVE
April 15th, 2025 (5 days ago)

CVE-2025-26894

Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NotFound Coming Soon, Maintenance Mode allows PHP Local File Inclusion. This issue affects Coming Soon, Maintenance Mode: from n/a through 1.1.1.

CVSS: HIGH (7.5)

EPSS Score: 0.11%

Source: CVE
April 15th, 2025 (5 days ago)

CVE-2025-26889

Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NotFound hockeydata LOS allows PHP Local File Inclusion. This issue affects hockeydata LOS: from n/a through 1.2.4.

CVSS: HIGH (7.5)

EPSS Score: 0.11%

Source: CVE
April 15th, 2025 (5 days ago)

CVE-2025-26743

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TC.K Advance WP Query Search Filter allows Reflected XSS. This issue affects Advance WP Query Search Filter: from n/a through 1.0.10.

CVSS: HIGH (7.1)

EPSS Score: 0.03%

Source: CVE
April 15th, 2025 (5 days ago)

CVE-2025-26741

Description: Missing Authorization vulnerability in AWEOS GmbH Email Notifications for Updates allows Privilege Escalation. This issue affects Email Notifications for Updates: from n/a through 1.1.6.

CVSS: HIGH (8.8)

EPSS Score: 0.04%

Source: CVE
April 15th, 2025 (5 days ago)