CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

CVE-2025-30916

Description: Missing Authorization vulnerability in enituretechnology Residential Address Detection allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Residential Address Detection: from n/a through 2.5.4.

CVSS: MEDIUM (6.5)

EPSS Score: 0.05%

Source: CVE
April 3rd, 2025 (3 months ago)

CVE-2025-30915

Description: Missing Authorization vulnerability in enituretechnology Small Package Quotes – Worldwide Express Edition allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Small Package Quotes – Worldwide Express Edition: from n/a through 5.2.19.

CVSS: MEDIUM (6.5)

EPSS Score: 0.05%

Source: CVE
April 3rd, 2025 (3 months ago)

CVE-2025-30908

Description: Cross-Site Request Forgery (CSRF) vulnerability in Shamalli Web Directory Free allows Stored XSS. This issue affects Web Directory Free: from n/a through 1.7.6.

CVSS: HIGH (7.1)

EPSS Score: 0.02%

Source: CVE
April 3rd, 2025 (3 months ago)

CVE-2025-30889

Description: Deserialization of Untrusted Data vulnerability in PickPlugins Testimonial Slider allows Object Injection. This issue affects Testimonial Slider: from n/a through 2.0.13.

CVSS: HIGH (8.8)

EPSS Score: 0.05%

Source: CVE
April 3rd, 2025 (3 months ago)

CVE-2025-30858

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Software Snow Storm allows Reflected XSS. This issue affects Snow Storm: from n/a through 1.4.6.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
April 3rd, 2025 (3 months ago)

CVE-2025-30616

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Latest Custom Post Type Updates allows Reflected XSS. This issue affects Latest Custom Post Type Updates: from n/a through 1.3.0.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
April 3rd, 2025 (3 months ago)

CVE-2025-30611

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Wptobe-signinup allows Reflected XSS. This issue affects Wptobe-signinup: from n/a through 1.1.2.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
April 3rd, 2025 (3 months ago)

CVE-2025-30596

Description: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in NotFound include-file allows Path Traversal. This issue affects include-file: from n/a through 1.

CVSS: MEDIUM (6.5)

EPSS Score: 0.05%

Source: CVE
April 3rd, 2025 (3 months ago)

CVE-2024-9416

Description: The Modula Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions <= 5.0.36) due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS: MEDIUM (6.4)

EPSS Score: 0.03%

Source: CVE
April 3rd, 2025 (3 months ago)

CVE-2025-2299

Description: The LuckyWP Table of Contents plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.10. This is due to missing or incorrect nonce validation on the 'ajaxEdit' function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS: MEDIUM (6.1)

EPSS Score: 0.04%

Source: CVE
April 3rd, 2025 (3 months ago)