CVE-2025-23474 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mike Martel Live Dashboard allows Reflected XSS. This issue affects Live Dashboard: from n/a through 0.3.3.
CVSS: HIGH (7.1) EPSS Score: 0.04%
February 15th, 2025 (5 months ago)
|
CVE-2025-23431 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Envato Affiliater allows Reflected XSS. This issue affects Envato Affiliater: from n/a through 1.2.4.
CVSS: HIGH (7.1) EPSS Score: 0.04%
February 15th, 2025 (5 months ago)
|
CVE-2025-23428 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound QMean – WordPress Did You Mean allows Reflected XSS. This issue affects QMean – WordPress Did You Mean: from n/a through 2.0.
CVSS: HIGH (7.1) EPSS Score: 0.04%
February 15th, 2025 (5 months ago)
|
CVE-2025-22705 |
Description: Cross-Site Request Forgery (CSRF) vulnerability in godthor Disqus Popular Posts allows Reflected XSS. This issue affects Disqus Popular Posts: from n/a through 2.1.1.
CVSS: HIGH (7.1) EPSS Score: 0.04%
February 15th, 2025 (5 months ago)
|
CVE-2025-1053 |
Description: Under certain error conditions at time of SANnav installation or upgrade, the encryption key can be written into and obtained from a Brocade SANnav supportsave. An attacker with privileged access to the Brocade SANnav database could use the encryption key to obtain passwords used by Brocade SANnav.
CVSS: HIGH (8.6) EPSS Score: 0.04%
February 15th, 2025 (5 months ago)
|
CVE-2025-0593 |
Description: The vulnerability may allow a remote low priviledged attacker to run arbitrary shell commands by using lower-level functions to interact with the device.
CVSS: HIGH (8.8) EPSS Score: 0.04%
February 15th, 2025 (5 months ago)
|
CVE-2025-0592 |
Description: The vulnerability may allow a remote low priviledged attacker to run arbitrary shell commands by manipulating the firmware file and uploading it to the device.
CVSS: HIGH (8.8) EPSS Score: 0.04%
February 15th, 2025 (5 months ago)
|
CVE-2024-8893 |
Description: Use of Hard-coded Credentials vulnerability in GoodWe Technologies Co., Ltd. GW1500‑XS allows anyone in physical proximity to the device to fully access the web interface of the inverter via Wi‑Fi.This issue affects GW1500‑XS: 1.1.2.1.
CVSS: HIGH (7.3) EPSS Score: 0.04%
February 15th, 2025 (5 months ago)
|
CVE-2024-55904 |
Description: IBM DevOps Deploy 8.0 through 8.0.1.4, 8.1 through 8.1.0.0 / IBM UrbanCode Deploy 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.9 could allow a remote privileged authenticated attacker to execute arbitrary commands on the system by sending specially crafted input containing special elements.
CVSS: HIGH (7.2) EPSS Score: 0.05%
February 15th, 2025 (5 months ago)
|
CVE-2024-52500 |
Description: Missing Authorization vulnerability in monetagwp Monetag Official Plugin allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Monetag Official Plugin: from n/a through 1.1.3.
CVSS: HIGH (7.2) EPSS Score: 0.04%
February 15th, 2025 (5 months ago)
|