Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

CVE-2025-46537

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ctltwp Section Widget allows Reflected XSS. This issue affects Section Widget: from n/a through 3.3.1.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
May 23rd, 2025 (16 days ago)

CVE-2025-46527

Description: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in LikeCoin Web3Press allows Path Traversal. This issue affects Web3Press: from n/a through 3.2.0.

CVSS: MEDIUM (6.5)

EPSS Score: 0.05%

Source: CVE
May 23rd, 2025 (16 days ago)

CVE-2025-46526

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in janekniefeldt My Custom Widgets allows Reflected XSS. This issue affects My Custom Widgets: from n/a through 2.0.5.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
May 23rd, 2025 (16 days ago)

CVE-2025-46518

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in phpaddicted IGIT Related Posts With Thumb Image After Posts allows Stored XSS. This issue affects IGIT Related Posts With Thumb Image After Posts: from n/a through 4.5.3.

CVSS: MEDIUM (6.5)

EPSS Score: 0.03%

Source: CVE
May 23rd, 2025 (16 days ago)

CVE-2025-46515

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M A Vinoth Kumar Category Widget allows Reflected XSS. This issue affects Category Widget: from n/a through 2.0.2.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
May 23rd, 2025 (16 days ago)

CVE-2025-46493

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wordwebsoftware Crossword Compiler Puzzles allows Stored XSS. This issue affects Crossword Compiler Puzzles: from n/a through 5.3.

CVSS: MEDIUM (6.5)

EPSS Score: 0.03%

Source: CVE
May 23rd, 2025 (16 days ago)

CVE-2025-46490

Description: Unrestricted Upload of File with Dangerous Type vulnerability in wordwebsoftware Crossword Compiler Puzzles allows Upload a Web Shell to a Web Server. This issue affects Crossword Compiler Puzzles: from n/a through 5.2.

CVSS: CRITICAL (9.9)

EPSS Score: 0.05%

Source: CVE
May 23rd, 2025 (16 days ago)

CVE-2025-46488

Description: Missing Authorization vulnerability in dastan800 Visual Builder allows Reflected XSS. This issue affects Visual Builder: from n/a through 1.2.2.

CVSS: HIGH (7.1)

EPSS Score: 0.03%

Source: CVE
May 23rd, 2025 (16 days ago)

CVE-2025-46487

Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sftranna EC Authorize.net allows Reflected XSS. This issue affects EC Authorize.net: from n/a through 0.3.3.

CVSS: HIGH (7.1)

EPSS Score: 0.04%

Source: CVE
May 23rd, 2025 (16 days ago)

CVE-2025-46486

Description: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in totalprocessing Nomupay Payment Processing Gateway allows Path Traversal. This issue affects Nomupay Payment Processing Gateway: from n/a through 7.1.7.

CVSS: MEDIUM (4.9)

EPSS Score: 0.05%

Source: CVE
May 23rd, 2025 (16 days ago)