CVE-2025-31057 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Universal Video Player allows Reflected XSS. This issue affects Universal Video Player: from n/a through 1.4.0.
CVSS: HIGH (7.1) EPSS Score: 0.04%
June 9th, 2025 (14 days ago)
|
CVE-2025-31052 |
Description: Deserialization of Untrusted Data vulnerability in themeton The Fashion - Model Agency One Page Beauty Theme allows Object Injection. This issue affects The Fashion - Model Agency One Page Beauty Theme: from n/a through 1.4.4.
CVSS: CRITICAL (9.8) EPSS Score: 0.05%
June 9th, 2025 (14 days ago)
|
CVE-2025-31050 |
Description: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in appthaplugins Apptha Slider Gallery allows Path Traversal. This issue affects Apptha Slider Gallery: from n/a through 2.5.
CVSS: HIGH (7.5) EPSS Score: 0.06%
June 9th, 2025 (14 days ago)
|
CVE-2025-31045 |
Description: Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in elfsight elfsight Contact Form widget allows Retrieve Embedded Sensitive Data. This issue affects elfsight Contact Form widget: from n/a through 2.3.1.
CVSS: HIGH (7.5) EPSS Score: 0.04%
June 9th, 2025 (14 days ago)
|
CVE-2025-31039 |
Description: Improper Restriction of XML External Entity Reference vulnerability in pixelgrade Category Icon allows XML Entity Linking. This issue affects Category Icon: from n/a through 1.0.2.
CVSS: CRITICAL (9.1) EPSS Score: 0.05%
June 9th, 2025 (14 days ago)
|
CVE-2025-31022 |
Description: Authentication Bypass Using an Alternate Path or Channel vulnerability in PayU India PayU India allows Authentication Abuse. This issue affects PayU India: from n/a through 3.8.5.
CVSS: CRITICAL (9.8) EPSS Score: 0.07%
June 9th, 2025 (14 days ago)
|
CVE-2025-31019 |
Description: Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Password Policy Manager allows Authentication Abuse. This issue affects Password Policy Manager: from n/a through 2.0.4.
CVSS: HIGH (8.8) EPSS Score: 0.06%
June 9th, 2025 (14 days ago)
|
CVE-2025-28992 |
Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme SNS Anton allows PHP Local File Inclusion. This issue affects SNS Anton: from n/a through 4.1.
CVSS: HIGH (8.1) EPSS Score: 0.15%
June 9th, 2025 (14 days ago)
|
CVE-2025-28945 |
Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme Valen - Sport, Fashion WooCommerce WordPress Theme allows PHP Local File Inclusion. This issue affects Valen - Sport, Fashion WooCommerce WordPress Theme: from n/a through 2.4.
CVSS: HIGH (8.1) EPSS Score: 0.15%
June 9th, 2025 (14 days ago)
|
CVE-2025-28944 |
Description: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme Avaz allows PHP Local File Inclusion. This issue affects Avaz: from n/a through 2.8.
CVSS: HIGH (8.1) EPSS Score: 0.15%
June 9th, 2025 (14 days ago)
|