CVE-2025-39381 |
Description: Cross-Site Request Forgery (CSRF) vulnerability in Kiotviet KiotViet Sync allows Stored XSS. This issue affects KiotViet Sync: from n/a through 1.8.4.
CVSS: HIGH (7.1) EPSS Score: 0.02%
April 24th, 2025 (about 2 months ago)
|
CVE-2025-39379 |
Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Capturly Capturly allows PHP Local File Inclusion. This issue affects Capturly: from n/a through 2.0.1.
CVSS: HIGH (7.5) EPSS Score: 0.11%
April 24th, 2025 (about 2 months ago)
|
CVE-2025-39378 |
Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light allows PHP Local File Inclusion. This issue affects Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light: from n/a through 2.4.37.
CVSS: HIGH (7.5) EPSS Score: 0.11%
April 24th, 2025 (about 2 months ago)
|
CVE-2025-39377 |
Description: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs Appsero Helper allows SQL Injection. This issue affects Appsero Helper: from n/a through 1.3.4.
CVSS: HIGH (8.5) EPSS Score: 0.03%
April 24th, 2025 (about 2 months ago)
|
CVE-2025-39360 |
Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in everestthemes Grace Mag allows PHP Local File Inclusion. This issue affects Grace Mag: from n/a through 1.1.5.
CVSS: HIGH (7.5) EPSS Score: 0.11%
April 24th, 2025 (about 2 months ago)
|
CVE-2025-39359 |
Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Code Work Web CWW Portfolio allows PHP Local File Inclusion. This issue affects CWW Portfolio: from n/a through 1.3.1.
CVSS: HIGH (7.5) EPSS Score: 0.11%
April 24th, 2025 (about 2 months ago)
|
CVE-2025-32921 |
Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WPoperation Arrival allows PHP Local File Inclusion. This issue affects Arrival: from n/a through 1.4.5.
CVSS: HIGH (7.5) EPSS Score: 0.11%
April 24th, 2025 (about 2 months ago)
|
CVE-2024-24932 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Djo VK Poster Group allows Reflected XSS.This issue affects VK Poster Group: from n/a through 2.0.3.
CVSS: HIGH (7.1) EPSS Score: 0.06% SSVC Exploitation: none
April 24th, 2025 (about 2 months ago)
|
CVE-2024-24926 |
Description: Deserialization of Untrusted Data vulnerability in UnitedThemes Brooklyn | Creative Multi-Purpose Responsive WordPress Theme.This issue affects Brooklyn | Creative Multi-Purpose Responsive WordPress Theme: from n/a through 4.9.7.6.
CVSS: HIGH (7.5) EPSS Score: 33.93% SSVC Exploitation: none
April 24th, 2025 (about 2 months ago)
|
CVE-2024-24884 |
Description: Cross-Site Request Forgery (CSRF) vulnerability in ARI Soft Contact Form 7 Connector.This issue affects Contact Form 7 Connector: from n/a through 1.2.2.
CVSS: MEDIUM (4.3) EPSS Score: 0.08% SSVC Exploitation: none
April 24th, 2025 (about 2 months ago)
|