CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

CVE-2025-32134

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KaizenCoders URL Shortify allows Stored XSS. This issue affects URL Shortify: from n/a through 1.10.4.

CVSS: MEDIUM (5.9)

EPSS Score: 0.03%

Source: CVE
April 4th, 2025 (2 months ago)

CVE-2025-32133

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Secure Copy Content Protection and Content Locking allows Stored XSS. This issue affects Secure Copy Content Protection and Content Locking: from n/a through 4.5.1.

CVSS: MEDIUM (5.9)

EPSS Score: 0.03%

Source: CVE
April 4th, 2025 (2 months ago)

CVE-2025-32132

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FunnelCockpit FunnelCockpit allows Stored XSS. This issue affects FunnelCockpit: from n/a through 1.4.2.

CVSS: MEDIUM (5.9)

EPSS Score: 0.03%

Source: CVE
April 4th, 2025 (2 months ago)

CVE-2025-32131

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in socialintents Social Intents allows Stored XSS. This issue affects Social Intents: from n/a through 1.6.14.

CVSS: MEDIUM (5.9)

EPSS Score: 0.03%

Source: CVE
April 4th, 2025 (2 months ago)

CVE-2025-32130

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Data443 Risk Migitation, Inc. Posts Footer Manager allows Stored XSS. This issue affects Posts Footer Manager: from n/a through 2.2.0.

CVSS: MEDIUM (5.9)

EPSS Score: 0.03%

Source: CVE
April 4th, 2025 (2 months ago)

CVE-2025-32129

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Data443 Risk Migitation, Inc. Welcome Bar allows Stored XSS. This issue affects Welcome Bar: from n/a through 2.0.4.

CVSS: MEDIUM (5.9)

EPSS Score: 0.03%

Source: CVE
April 4th, 2025 (2 months ago)

CVE-2025-31407

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hutsixdigital Tiger allows Stored XSS.This issue affects Tiger: from n/a through 2.0.

CVSS: MEDIUM (6.5)

EPSS Score: 0.03%

SSVC Exploitation: none

Source: CVE
April 4th, 2025 (2 months ago)

CVE-2025-31381

Description: Missing Authorization vulnerability in shiptrack Booking Calendar and Notification allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking Calendar and Notification: from n/a through 4.0.3.

CVSS: MEDIUM (6.5)

EPSS Score: 0.05%

Source: CVE
April 4th, 2025 (2 months ago)

CVE-2025-22285

Description: Missing Authorization vulnerability in Eniture Technology Pallet Packaging for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pallet Packaging for WooCommerce: from n/a through 1.1.15.

CVSS: MEDIUM (6.5)

EPSS Score: 0.05%

Source: CVE
April 4th, 2025 (2 months ago)

CVE-2025-22281

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in joshix Simplish allows Stored XSS.This issue affects Simplish: from n/a through 2.6.4.

CVSS: MEDIUM (6.5)

EPSS Score: 0.03%

Source: CVE
April 4th, 2025 (2 months ago)