ID | Summary | Flags | Max Score |
---|---|---|---|
CVE-2025-31000 | WordPress Payment QR WooCommerce <= 1.1.6 - Broken Access Control Vulnerability | | |
CVE-2025-31001 | WordPress GTM Kit plugin <= 2.3.1 - Sensitive Data Exposure vulnerability | | |
CVE-2025-31002 | WordPress Squeeze plugin <= 1.6 - Arbitrary File Upload vulnerability | S | |
CVE-2025-31003 | WordPress Squeeze plugin <= 1.6 - Full Path Disclosure (FPD) vulnerability | S | |
CVE-2025-31004 | WordPress Rich Table of Contents plugin <= 1.4.0 - Broken Access Control vulnerability | | |
CVE-2025-31005 | WordPress Easyfonts plugin <= 1.1.2 - Cross Site Request Forgery (CSRF) vulnerability | | |
CVE-2025-31006 | WordPress Activity Reactions For Buddypress plugin <= 1.0.22 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31008 | WordPress YouTube Embed <= 5.3.1 - Cross Site Scripting (XSS) Vulnerability | | |
CVE-2025-31009 | WordPress IndieBlocks <= 0.13.1 - Server Side Request Forgery (SSRF) Vulnerability | S | |
CVE-2025-31010 | WordPress SimplyRETS Real Estate IDX plugin <= 3.0.3 - CSRF to Multiple Admin Actions vulnerability | | |
CVE-2025-31011 | WordPress SimplyRETS Real Estate IDX plugin <= 3.0.3 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31012 | WordPress Age Gate <= 3.5.4 - Broken Access Control Vulnerability | S | |
CVE-2025-31014 | WordPress Material Dashboard <= 1.4.5 - Local File Inclusion Vulnerability | S | |
CVE-2025-31015 | WordPress WordPress SMTP Service, Email Delivery Solved! — MailHawk <= 1.3.1 - Local File Inclusion Vulnerability | | |
CVE-2025-31016 | WordPress JetWooBuilder plugin <= 2.1.18 - Local File Inclusion vulnerability | S | |
CVE-2025-31017 | WordPress Nav Menu Manager <= 3.2.5 - Cross Site Scripting (XSS) Vulnerability | S | |
CVE-2025-31018 | WordPress FireDrum Email Marketing plugin <= 1.64 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31019 | WordPress Password Policy Manager plugin <= 2.0.4 - Account Takeover vulnerability | S | |
CVE-2025-31020 | WordPress Simple Spoiler <= 1.4 - Cross Site Scripting (XSS) Vulnerability | | |
CVE-2025-31021 | WordPress Mobile Smart plugin <= v1.3.16 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31022 | WordPress PayU India plugin < 3.8.8 - Account Takeover vulnerability | S | |
CVE-2025-31023 | WordPress Seo Meta Tags plugin <= 1.4 - CSRF to Privilege Escalation vulnerability | | |
CVE-2025-31024 | WordPress RJ Quickcharts plugin <= 0.6.1 - SQL Injection vulnerability | | |
CVE-2025-31025 | WordPress Image Hover Effects Block <= 1.4.5 - Cross Site Scripting (XSS) Vulnerability | | |
CVE-2025-31026 | WordPress Comment Validation Reloaded plugin <= 0.5 - CSRF to Stored XSS vulnerability | | |
CVE-2025-31027 | WordPress Tiger theme <= 2.0 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31028 | WordPress WP Hide Categories <= 1.0 - Cross Site Scripting (XSS) Vulnerability | | |
CVE-2025-31030 | WordPress Ray Enterprise Translation <= 1.7.0 - Local File Inclusion Vulnerability | S | |
CVE-2025-31031 | WordPress Job Colors for WP Job Manager plugin <= 1.0.4 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31032 | WordPress Pagopar – WooCommerce Gateway plugin <= 2.7.1 - CSRF to Stored XSS vulnerability | | |
CVE-2025-31033 | WordPress Buddypress Humanity plugin <= 1.2 - CSRF to Privilege Escalation vulnerability | | |
CVE-2025-31034 | WordPress Customize Login Page plugin <= 1.1 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability | | |
CVE-2025-31035 | WordPress WP Editor.md – The Perfect WordPress Markdown Editor <= 10.2.1 - Cross Site Scripting (XSS) Vulnerability | | |
CVE-2025-31036 | WordPress WPSolr plugin <= 24.0 - CSRF to Privilege Escalation vulnerability | | |
CVE-2025-31037 | WordPress Homey theme <= 2.4.5 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31038 | WordPress Essential Breadcrumbs plugin <= 1.1.1 - CSRF to Privilege Escalation vulnerability | | |
CVE-2025-31039 | WordPress Category Icon plugin <= 1.0.2 - XML External Entity (XXE) vulnerability | | |
CVE-2025-31040 | WordPress WP Food ordering and Restaurant Menu <= 1.1 - Local File Inclusion Vulnerability | | |
CVE-2025-31041 | WordPress AnyTrack Affiliate Link Manager <= 1.0.4 - Broken Access Control Vulnerability | | |
CVE-2025-31042 | WordPress Sandwich Adsense <= 4.0.2 - Broken Access Control Vulnerability | | |
CVE-2025-31043 | WordPress JetSearch plugin <= 3.5.7 - Cross Site Scripting (XSS) vulnerability | S | |
CVE-2025-31045 | WordPress elfsight Contact Form widget <= 2.3.1 - Sensitive Data Exposure Vulnerability | | |
CVE-2025-31049 | WordPress Dash <= 1.3 - PHP Object Injection Vulnerability | | |
CVE-2025-31050 | WordPress Apptha Slider Gallery plugin <= 2.5 - Arbitrary File Read vulnerability | | |
CVE-2025-31052 | WordPress The Fashion - Model Agency One Page Beauty Theme <= 1.4.4 - Deserialization of untrusted data Vulnerability | | |
CVE-2025-31053 | WordPress KBx Pro Ultimate < 8.0.5 - Arbitrary File Deletion Vulnerability | S | |
CVE-2025-31056 | WordPress WhatsCart plugin <= 1.1.0 - SQL Injection vulnerability | | |
CVE-2025-31057 | WordPress Universal Video Player plugin <= 1.4.0 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31058 | WordPress Revolution Video Player plugin <= 2.9.2 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31059 | WordPress WBW Product Table PRO <= 2.1.3 - SQL Injection Vulnerability | | |
CVE-2025-31060 | WordPress Capie <= 1.0.40 - Local File Inclusion Vulnerability | | |
CVE-2025-31061 | WordPress Wishlist plugin <= 2.1.0 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31062 | WordPress Wishlist <= 2.1.0 - Sensitive Data Exposure Vulnerability | | |
CVE-2025-31063 | WordPress Wishlist <= 2.1.0 - Broken Access Control Vulnerability | | |
CVE-2025-31064 | WordPress Vizeon - Business Consulting <= 1.1.7 - Local File Inclusion Vulnerability | | |
CVE-2025-31065 | WordPress Rozario <= 1.4 - Broken Access Control Vulnerability | | |
CVE-2025-31066 | WordPress Acerola <= 1.6.5 - Broken Access Control Vulnerability | | |
CVE-2025-31067 | WordPress Seven Stars theme <= 1.4.4 - Cross Site Scripting (XSS) Vulnerability | | |
CVE-2025-31068 | WordPress Seven Stars <= 1.4.4 - Cross Site Request Forgery (CSRF) Vulnerability | | |
CVE-2025-31069 | WordPress HotStar – Multi-Purpose Business Theme <= 1.4 - PHP Object Injection Vulnerability | | |
CVE-2025-31071 | WordPress HotStar – Multi-Purpose Business Theme <= 1.4 - Broken Access Control Vulnerability | | |
CVE-2025-31073 | WordPress Unlimited <= 1.45 - Cross Site Scripting (XSS) Vulnerability | S | |
CVE-2025-31074 | WordPress MDJM Event Management plugin <= 1.7.5.2 - PHP Object Injection vulnerability | S | |
CVE-2025-31075 | WordPress MicroPayments plugin <= 2.9.29 - Cross Site Scripting (XSS) vulnerability | S | |
CVE-2025-31076 | WordPress WP Compress for MainWP plugin <= 6.30.03 - Server Side Request Forgery (SSRF) vulnerability | S | |
CVE-2025-31077 | WordPress Ultimate Blocks plugin <= 3.2.7 - Cross Site Scripting (XSS) vulnerability | S | |
CVE-2025-31078 | WordPress Small Package Quotes – Worldwide Express Edition plugin <= 5.2.18 - Reflected Cross Site Scripting (XSS) vulnerability | S | |
CVE-2025-31079 | WordPress Usermaven plugin <= 1.2.1 - Cross Site Request Forgery (CSRF) vulnerability | S | |
CVE-2025-31080 | WordPress HTML Forms plugin <= 1.5.1 - Cross Site Scripting (XSS) vulnerability | S | |
CVE-2025-31081 | WordPress Enable Media Replace plugin <= 4.1.5 - Reflected Cross Site Scripting (XSS) vulnerability | S | |
CVE-2025-31082 | WordPress News & Blog Designer Pack plugin <= 4.0 - Local File Inclusion vulnerability | S | |
CVE-2025-31083 | WordPress Leaky Paywall <= 4.21.7 - Cross Site Scripting (XSS) Vulnerability | S | |
CVE-2025-31084 | WordPress Sunshine Photo Cart <= 3.4.10 - PHP Object Injection Vulnerability | S | |
CVE-2025-31085 | WordPress xili-language plugin <= 2.21.2 - Reflected Cross Site Scripting (XSS) vulnerability | S | |
CVE-2025-31086 | WordPress Product Table by WBW plugin <= 2.1.4 - Reflected Cross Site Scripting (XSS) vulnerability | S | |
CVE-2025-31087 | WordPress Multiple Shipping And Billing Address For Woocommerce <= 1.5 - PHP Object Injection Vulnerability | S | |
CVE-2025-31088 | WordPress Paid Member Subscriptions <= 2.14.3 - Cross Site Scripting (XSS) Vulnerability | S | |
CVE-2025-31089 | WordPress Order Splitter for WooCommerce <= 5.3.0 - SQL Injection Vulnerability | S | |
CVE-2025-31090 | WordPress Dropdown Multisite selector < 0.9.4 - Cross Site Scripting (XSS) Vulnerability | S | |
CVE-2025-31091 | WordPress CM Header and Footer <= 1.2.4 - Cross Site Scripting (XSS) Vulnerability | S | |
CVE-2025-31092 | WordPress Click to Chat – WP Support All-in-One Floating Widget plugin <= 2.3.4 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31093 | WordPress RPS Include Content <= 1.2.1 - Cross Site Scripting (XSS) Vulnerability | S | |
CVE-2025-31094 | WordPress WP Posts Carousel <= 1.3.8 - Cross Site Scripting (XSS) Vulnerability | S | |
CVE-2025-31095 | WordPress Material Dashboard <= 1.4.5 - Privilege Escalation Vulnerability | S | |
CVE-2025-31096 | WordPress PostX <= 4.1.25 - Cross Site Scripting (XSS) Vulnerability | S | |
CVE-2025-31097 | WordPress Material Dashboard <= 1.4.5 - Local File Inclusion Vulnerability | S | |
CVE-2025-31098 | WordPress DeBounce Email Validator <= 5.7 - Local File Inclusion Vulnerability | S | |
CVE-2025-31099 | WordPress Slider by BestWebSoft <= 1.1.0 - SQL Injection Vulnerability | S | |
CVE-2025-31101 | WordPress VaultRE Contact Form 7 plugin <= 1.0 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31102 | WordPress Hostel plugin <= 1.1.5.5 - Reflected Cross Site Scripting (XSS) vulnerability | S | |
CVE-2025-31103 | Untrusted data deserialization vulnerability exists in a-blog cms. Processing a specially crafted re... | | |
CVE-2025-31104 | An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner... | S | |
CVE-2025-31105 | Rejected reason: Not used... | R | |
CVE-2025-31106 | Rejected reason: Not used... | R | |
CVE-2025-31107 | Rejected reason: Not used... | R | |
CVE-2025-31108 | Rejected reason: Not used... | R | |
CVE-2025-31109 | Rejected reason: Not used... | R | |
CVE-2025-31110 | Rejected reason: Not used... | R | |
CVE-2025-31111 | Rejected reason: Not used... | R | |
CVE-2025-31112 | Rejected reason: Not used... | R | |
CVE-2025-31113 | Rejected reason: Not used... | R | |
CVE-2025-31115 | XZ has a heap-use-after-free bug in threaded .xz decoder | | |
CVE-2025-31116 | Mobile Security Framework (MobSF) has a SSRF Vulnerability fix bypass on assetlinks_check with DNS Rebinding | E S | |
CVE-2025-31117 | OpenEMR Out-of-Band Server-Side Request Forgery (OOB SSRF) Vulnerability | E S | |
CVE-2025-31118 | NamelessMC Has Forum Reply Submission Time Limit Bypass | E S | |
CVE-2025-31119 | CWE-470 in generator-jhipster-entity-audit when having Javers selected as Entity Audit Framework | | |
CVE-2025-31120 | NamelessMC Vulnerable to Cookie-Based View Count Manipulation | E S | |
CVE-2025-31121 | OpenEMR allows XSS in Patient Image feature | E | |
CVE-2025-31122 | scratch-coding-hut.github.io Login Links Generation vulnerability | | |
CVE-2025-31123 | Zitadel Expired JWT Keys Usable for Authorization Grants | | |
CVE-2025-31124 | Zitadel allows User Enumeration by loginname attribute normalization | | |
CVE-2025-31125 | Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query | E | |
CVE-2025-31126 | Element X iOS allows the entity in control of the well-known file to break the confidentiality of embedded Element Call | | |
CVE-2025-31127 | Element X Android allows the entity in control of the well-known file to break the confidentiality embedded Element Call | | |
CVE-2025-31128 | gifplayer XSS vulnerability | | |
CVE-2025-31129 | jooby-pac4j: deserialization of untrusted data | | |
CVE-2025-31130 | gitoxide does not detect SHA-1 collision attacks | E | |
CVE-2025-31131 | Path Traversal allowing arbitrary read of files in Yeswiki | E S | |
CVE-2025-31132 | Raven allows Remote Code Execution due to improper validation | | |
CVE-2025-31134 | FreshRSS vulnerable to directory enumeration via ext.php | E S | |
CVE-2025-31135 | Go-Guerrilla SMTP Daemon allows the PROXY command to be sent multiple times | | |
CVE-2025-31136 | FreshRSS vulnerable to Cross-site Scripting by | E S | |
CVE-2025-31137 | Remix and React Router allow URL manipulation via Host / X-Forwarded-Host headers | | |
CVE-2025-31138 | tarteaucitron.js allows UI manipulation via unrestricted CSS injection | | |
CVE-2025-31139 | In JetBrains TeamCity before 2025.03 base64 encoded password could be exposed in build log... | | |
CVE-2025-31140 | In JetBrains TeamCity before 2025.03 stored XSS was possible on Cloud Profiles page... | | |
CVE-2025-31141 | In JetBrains TeamCity before 2025.03 exception could lead to credential leakage on Cloud Profiles pa... | | |
CVE-2025-31144 | Quick Agent V3 and Quick Agent V2 contain an issue with improper restriction of communication channe... | | |
CVE-2025-31147 | Growatt Cloud portal Authorization Bypass Through User-Controlled Key | S | |
CVE-2025-31160 | atop through 2.11.0 allows local users to cause a denial of service (e.g., assertion failure and app... | | |
CVE-2025-31161 | CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crus... | KEV E M | |
CVE-2025-31162 | fig2dev float point exception | | |
CVE-2025-31163 | fig2dev segmentation fault | | |
CVE-2025-31164 | fig2dev heap-buffer overflow | | |
CVE-2025-31165 | Cross Site Scripting in NightWolf Penetration Platform | S | |
CVE-2025-31170 | Access control vulnerability in the security verification module Impact: Successful exploitation of ... | | |
CVE-2025-31171 | File read permission bypass vulnerability in the kernel file system module Impact: Successful exploi... | | |
CVE-2025-31172 | Memory write permission bypass vulnerability in the kernel futex module Impact: Successful exploitat... | | |
CVE-2025-31173 | Memory write permission bypass vulnerability in the kernel futex module Impact: Successful exploitat... | | |
CVE-2025-31174 | Path traversal vulnerability in the DFS module Impact: Successful exploitation of this vulnerability... | | |
CVE-2025-31175 | Deserialization mismatch vulnerability in the DSoftBus module Impact: Successful exploitation of thi... | | |
CVE-2025-31176 | Gnuplot: gnuplot segmentation fault on plot3d_points | M | |
CVE-2025-31177 | Gnuplot: gnuplot heap-buffer overflow on utf8_copy_one | M | |
CVE-2025-31178 | Gnuplot: gnuplot segmentation fault on getannotatestring | M | |
CVE-2025-31179 | Gnuplot: gnuplot segmentation fault on xstrftime | M | |
CVE-2025-31180 | Gnuplot: gnuplot segmentation fault on canvas_text | M | |
CVE-2025-31181 | Gnuplot: gnuplot segmentation fault on x11_graphics | M | |
CVE-2025-31182 | This issue was addressed with improved handling of symlinks. This issue is fixed in visionOS 2.4, ma... | | |
CVE-2025-31183 | The issue was addressed with improved restriction of data container access. This issue is fixed in m... | | |
CVE-2025-31184 | This issue was addressed with improved permissions checking. This issue is fixed in Safari 18.4, vis... | | |
CVE-2025-31185 | A logic issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3. P... | | |
CVE-2025-31187 | This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.7.... | | |
CVE-2025-31188 | A race condition was addressed with additional validation. This issue is fixed in macOS Ventura 13.7... | | |
CVE-2025-31189 | A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Ventura ... | | |
CVE-2025-31191 | This issue was addressed through improved state management. This issue is fixed in macOS Ventura 13.... | | |
CVE-2025-31192 | The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadO... | | |
CVE-2025-31194 | An authentication issue was addressed with improved state management. This issue is fixed in macOS V... | | |
CVE-2025-31195 | The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.4. An ap... | | |
CVE-2025-31196 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in iPadOS 17... | | |
CVE-2025-31197 | The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, tvOS 18.4, ... | | |
CVE-2025-31198 | This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura ... | | |
CVE-2025-31199 | A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPad... | | |
CVE-2025-31200 | A memory corruption issue was addressed with improved bounds checking. This issue is fixed in tvOS 1... | KEV E | |
CVE-2025-31201 | This issue was addressed by removing the vulnerable code. This issue is fixed in tvOS 18.4.1, vision... | KEV | |
CVE-2025-31202 | A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS ... | | |
CVE-2025-31203 | An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequo... | | |
CVE-2025-31204 | The issue was addressed with improved memory handling. This issue is fixed in watchOS 11.5, tvOS 18.... | | |
CVE-2025-31205 | The issue was addressed with improved checks. This issue is fixed in watchOS 11.5, tvOS 18.5, iOS 18... | | |
CVE-2025-31206 | A type confusion issue was addressed with improved state handling. This issue is fixed in watchOS 11... | | |
CVE-2025-31207 | A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5. A... | | |
CVE-2025-31208 | The issue was addressed with improved checks. This issue is fixed in watchOS 11.5, macOS Sonoma 14.7... | | |
CVE-2025-31209 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in watchOS 11... | | |
CVE-2025-31210 | The issue was addressed with improved UI. This issue is fixed in iPadOS 17.7.7, iOS 18.5 and iPadOS ... | | |
CVE-2025-31212 | This issue was addressed through improved state management. This issue is fixed in watchOS 11.5, tvO... | | |
CVE-2025-31213 | A logging issue was addressed with improved data redaction. This issue is fixed in iPadOS 17.7.7, ma... | | |
CVE-2025-31214 | This issue was addressed through improved state management. This issue is fixed in iOS 18.5 and iPad... | | |
CVE-2025-31215 | The issue was addressed with improved checks. This issue is fixed in watchOS 11.5, tvOS 18.5, iPadOS... | | |
CVE-2025-31217 | The issue was addressed with improved input validation. This issue is fixed in watchOS 11.5, tvOS 18... | | |
CVE-2025-31218 | This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.5.... | | |
CVE-2025-31219 | The issue was addressed with improved memory handling. This issue is fixed in watchOS 11.5, macOS So... | | |
CVE-2025-31220 | A privacy issue was addressed by removing sensitive data. This issue is fixed in iPadOS 17.7.7, macO... | | |
CVE-2025-31221 | An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 11.... | | |
CVE-2025-31222 | A correctness issue was addressed with improved checks. This issue is fixed in watchOS 11.5, macOS S... | | |
CVE-2025-31223 | The issue was addressed with improved checks. This issue is fixed in watchOS 11.5, tvOS 18.5, iOS 18... | | |
CVE-2025-31224 | A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.6, macOS... | | |
CVE-2025-31225 | A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.5 and iPadOS... | | |
CVE-2025-31226 | A logic issue was addressed with improved checks. This issue is fixed in watchOS 11.5, tvOS 18.5, iP... | | |
CVE-2025-31227 | A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5. A... | | |
CVE-2025-31228 | The issue was addressed with improved authentication. This issue is fixed in iPadOS 17.7.7, iOS 18.5... | | |
CVE-2025-31231 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia... | | |
CVE-2025-31232 | A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.6, macOS... | | |
CVE-2025-31233 | The issue was addressed with improved input sanitization. This issue is fixed in watchOS 11.5, macOS... | | |
CVE-2025-31234 | The issue was addressed with improved input sanitization. This issue is fixed in visionOS 2.5, iOS 1... | | |
CVE-2025-31235 | A double free issue was addressed with improved memory management. This issue is fixed in iPadOS 17.... | | |
CVE-2025-31236 | An information disclosure issue was addressed with improved privacy controls. This issue is fixed in... | | |
CVE-2025-31237 | This issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.6, macOS Se... | | |
CVE-2025-31238 | The issue was addressed with improved checks. This issue is fixed in watchOS 11.5, tvOS 18.5, iOS 18... | | |
CVE-2025-31239 | A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS... | | |
CVE-2025-31240 | This issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.6, macOS Se... | | |
CVE-2025-31241 | A double free issue was addressed with improved memory management. This issue is fixed in watchOS 11... | | |
CVE-2025-31242 | A privacy issue was addressed with improved private data redaction for log entries. This issue is fi... | | |
CVE-2025-31244 | A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia ... | | |
CVE-2025-31245 | The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.7.6, tvOS 18.5,... | | |
CVE-2025-31246 | The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.5, ma... | | |
CVE-2025-31247 | A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.... | | |
CVE-2025-31249 | A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5. An app ... | | |
CVE-2025-31250 | An information disclosure issue was addressed with improved privacy controls. This issue is fixed in... | | |
CVE-2025-31251 | The issue was addressed with improved input sanitization. This issue is fixed in watchOS 11.5, macOS... | | |
CVE-2025-31253 | This issue was addressed through improved state management. This issue is fixed in iOS 18.5 and iPad... | | |
CVE-2025-31256 | The issue was addressed with improved handling of caches. This issue is fixed in macOS Sequoia 15.5.... | | |
CVE-2025-31257 | This issue was addressed with improved memory handling. This issue is fixed in watchOS 11.5, tvOS 18... | | |
CVE-2025-31258 | This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.5.... | | |
CVE-2025-31259 | The issue was addressed with improved input sanitization. This issue is fixed in macOS Sequoia 15.5.... | | |
CVE-2025-31260 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia... | | |
CVE-2025-31261 | A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS... | | |
CVE-2025-31262 | A permissions issue was addressed with additional restrictions. This issue is fixed in visionOS 2.3,... | | |
CVE-2025-31263 | The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4. An... | | |
CVE-2025-31264 | An authentication issue was addressed with improved state management. This issue is fixed in macOS V... | | |
CVE-2025-31267 | An authentication issue was addressed with improved state management. This issue is fixed in App Sto... | | |
CVE-2025-31282 | A broken access control vulnerability previously discovered in the Trend Vision One User Account com... | | |
CVE-2025-31283 | A broken access control vulnerability previously discovered in the Trend Vision One User Roles compo... | | |
CVE-2025-31284 | A broken access control vulnerability previously discovered in the Trend Vision One Status component... | | |
CVE-2025-31285 | A broken access control vulnerability previously discovered in the Trend Vision One Role Name compon... | | |
CVE-2025-31286 | An HTML injection vulnerability previously discovered in Trend Vision One could have allowed a malic... | | |
CVE-2025-31324 | Missing Authorization check in SAP NetWeaver (Visual Composer development server) | KEV | |
CVE-2025-31325 | Cross-Site Scripting (XSS) Vulnerability in SAP NetWeaver (ABAP Keyword Documentation) | | |
CVE-2025-31326 | HTML Injection vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence) | | |
CVE-2025-31327 | OData meta-data property entity tampering in SAP Field Logistics | | |
CVE-2025-31328 | Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4 HANA (Learning Solution) | | |
CVE-2025-31329 | Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform | | |
CVE-2025-31330 | Code Injection Vulnerability in SAP Landscape Transformation (Analysis Platform) | | |
CVE-2025-31331 | Authorization Bypass vulnerability in SAP NetWeaver | | |
CVE-2025-31332 | Insecure File permissions vulnerability in SAP BusinessObjects Business Intelligence Platform | | |
CVE-2025-31333 | Odata meta-data tampering in SAP S4CORE entity | | |
CVE-2025-31334 | Issue that bypasses the "Mark of the Web" security warning function for files when opening a symboli... | | |
CVE-2025-31335 | The OpenSAML C++ library before 3.3.1 allows forging of signed SAML messages via parameter manipulat... | | |
CVE-2025-31338 | Wisdom Master Pro - Missing Authorization | | |
CVE-2025-31339 | Wisdom Master Pro - Unrestricted Upload of File with Dangerous Type | | |
CVE-2025-31340 | Wisdom Master Pro - Improper Control of Filename for Include/Require Statement in PHP Program | | |
CVE-2025-31343 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec... | | |
CVE-2025-31344 | The giflib open-source component has a buffer overflow vulnerability | | |
CVE-2025-31349 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec... | | |
CVE-2025-31350 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec... | | |
CVE-2025-31351 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec... | | |
CVE-2025-31352 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec... | | |
CVE-2025-31353 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affec... | | |
CVE-2025-31354 | Subnet Solutions PowerSYSTEM Center Out-of-Bounds Read | S | |
CVE-2025-31357 | Growatt Cloud portal Authorization Bypass Through User-Controlled Key | S | |
CVE-2025-31359 | A directory traversal vulnerability exists in the PVMP package unpacking functionality of Parallels ... | E | |
CVE-2025-31360 | Growatt Cloud portal Authorization Bypass Through User-Controlled Key | S | |
CVE-2025-31362 | Use of hard-coded cryptographic key issue exists in BizRobo! all versions. Credentials inside robot ... | | |
CVE-2025-31363 | Data exfiltration via AI plugin Jira tool | S | |
CVE-2025-31367 | Rejected reason: Not used... | R | |
CVE-2025-31368 | Rejected reason: Not used... | R | |
CVE-2025-31369 | Rejected reason: Not used... | R | |
CVE-2025-31370 | Rejected reason: Not used... | R | |
CVE-2025-31371 | Rejected reason: Not used... | R | |
CVE-2025-31372 | Rejected reason: Not used... | R | |
CVE-2025-31373 | Rejected reason: Not used... | R | |
CVE-2025-31374 | Rejected reason: Not used... | R | |
CVE-2025-31375 | WordPress Scheduled plugin <= 1.0 - CSRF to Stored XSS vulnerability | | |
CVE-2025-31376 | WordPress NanoSupport plugin <= 0.6.0 - Broken Access Control vulnerability | | |
CVE-2025-31377 | WordPress Woo Product Feed For Marketing Channels <= 1.9.0 - Broken Access Control Vulnerability | | |
CVE-2025-31378 | WordPress Oppso Unit Converter plugin <= 1.1.1 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31379 | WordPress Insert HTML Here plugin <= 1.0 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31380 | WordPress Paid Videochat Turnkey Site plugin <= 7.3.11 - Broken Authentication Vulnerability | S | |
CVE-2025-31381 | WordPress Booking Calendar and Notification plugin <= 4.0.3 - Broken Authentication vulnerability | | |
CVE-2025-31382 | WordPress Language Field plugin <= 0.9 - CSRF to Stored XSS vulnerability | | |
CVE-2025-31383 | WordPress FrescoChat Live Chat plugin <= 3.2.6 - CSRF to Stored XSS vulnerability | | |
CVE-2025-31384 | WordPress Videos plugin <= 1.0.5 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31385 | WordPress Site Table of Contents plugin <= 0.3 - CSRF to Stored XSS vulnerability | | |
CVE-2025-31386 | WordPress Simple:Press plugin <= 6.10.11 - Broken Access Control vulnerability | | |
CVE-2025-31387 | WordPress InstaWP Connect plugin <= 0.1.0.82 - Local File Inclusion vulnerability | S | |
CVE-2025-31388 | WordPress The World plugin <= 0.4 - CSRF to Stored XSS vulnerability | | |
CVE-2025-31389 | WordPress Sequel plugin <= 1.0.11 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31390 | WordPress Social Crowd plugin <= 0.9.6.1 - CSRF to Stored XSS vulnerability | | |
CVE-2025-31391 | WordPress Script Compressor plugin <= 1.7.1 - CSRF to Stored XSS vulnerability | | |
CVE-2025-31392 | WordPress Smart Product Gallery Slider plugin <= 1.0.4 - CSRF to Stored XSS vulnerability | | |
CVE-2025-31393 | WordPress Social Bookmarking RELOADED plugin <= 3.18 - CSRF to Stored XSS vulnerability | | |
CVE-2025-31394 | WordPress More Mime Type Filters plugin <= 0.3 - CSRF to Stored XSS vulnerability | | |
CVE-2025-31395 | WordPress Easy Custom CSS plugin <= 1.0 - CSRF to Stored XSS vulnerability | | |
CVE-2025-31396 | WordPress FLAP - Business WordPress Theme <= 1.5 - PHP Object Injection Vulnerability | | |
CVE-2025-31397 | WordPress Bus Ticket Booking with Seat Reservation for WooCommerce plugin <= 1.7 - SQL Injection vulnerability | | |
CVE-2025-31398 | WordPress PIMP - Creative MultiPurpose <= 1.7 - Deserialization of untrusted data Vulnerability | | |
CVE-2025-31399 | WordPress CG Scroll To Top plugin <= 3.5 - CSRF to Stored XSS vulnerability | | |
CVE-2025-31400 | WordPress WS Audio Player plugin <= 1.1.8 - CSRF to Stored XSS vulnerability | | |
CVE-2025-31401 | WordPress MMX – Make Me Christmas plugin <= 1.0.0 - CSRF to Stored XSS vulnerability | | |
CVE-2025-31402 | WordPress NewsBoard Post and RSS Scroller plugin <= 1.2.12 - CSRF to Stored XSS vulnerability | | |
CVE-2025-31403 | WordPress Booking Calendar and Notification plugin <= 4.0.3 - SQL Injection vulnerability | | |
CVE-2025-31404 | WordPress AF Tell a Friend plugin <= 1.4 - CSRF to Stored XSS vulnerability | | |
CVE-2025-31405 | WordPress Fami WooCommerce Compare plugin <= 1.0.5 - Local File Inclusion vulnerability | | |
CVE-2025-31406 | WordPress ELEX WooCommerce Request a Quote plugin <= 2.3.3 - Broken Access Control vulnerability | | |
CVE-2025-31407 | WordPress Tiger theme <= 2.0 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31408 | WordPress Zoho Flow plugin <= 2.13.3 - Broken Access Control vulnerability | | |
CVE-2025-31409 | WordPress Bridge Core plugin < 3.3.1 - Cross Site Scripting (XSS) vulnerability | S | |
CVE-2025-31410 | WordPress WP Church Donation plugin <= 1.7 - Cross Site Request Forgery (CSRF) vulnerability | | |
CVE-2025-31411 | WordPress Linet ERP-Woocommerce Integration plugin <= 3.5.12 - Arbitrary File Read/Deletion vulnerability | | |
CVE-2025-31412 | WordPress JetProductGallery plugin <= 2.1.22 - Cross Site Scripting (XSS) vulnerability | S | |
CVE-2025-31414 | WordPress Cost Calculator Builder plugin <= 3.2.65 - Cross Site Scripting (XSS) vulnerability | S | |
CVE-2025-31415 | WordPress YayExtra <= 1.5.2 - Broken Access Control Vulnerability | S | |
CVE-2025-31416 | WordPress Awesome Event Booking plugin <= 2.8.4 - Reflected Cross Site Scripting (XSS) vulnerability | S | |
CVE-2025-31417 | WordPress WP Docs plugin < 2.2.7 - Broken Access Control vulnerability | S | |
CVE-2025-31418 | WordPress Gravel theme <= 1.6 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31419 | WordPress Churel plugin <= 1.0.8 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31420 | WordPress wpForo Forum plugin <= 2.4.2 - Privilege Escalation vulnerability | S | |
CVE-2025-31421 | WordPress Srbtranslatin plugin <= 3.2.0 - Sensitive Data Exposure vulnerability | | |
CVE-2025-31423 | WordPress Umberto <= 1.2.8 - PHP Object Injection Vulnerability | | |
CVE-2025-31424 | WordPress WP Lead Capturing Pages plugin <= 2.3 - SQL Injection vulnerability | | |
CVE-2025-31426 | WordPress Sticky Radio Player plugin <= 3.4 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31428 | WordPress HYDRO theme <= 2.8 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31429 | WordPress PressGrid - Frontend Publish Reaction & Multimedia Theme <= 1.3.1 - Deserialization of untrusted data Vulnerability | | |
CVE-2025-31430 | WordPress The Business <= 1.6.1 - PHP Object Injection Vulnerability | | |
CVE-2025-31431 | WordPress WP Bookmarks plugin <= 1.1 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31432 | WordPress Pop-Up Chop Chop <= 2.1.7 - Local File Inclusion Vulnerability | | |
CVE-2025-31433 | WordPress Magic Embeds <= 3.1.2 - Cross Site Scripting (XSS) Vulnerability | | |
CVE-2025-31434 | WordPress FormLift for Infusionsoft Web Forms <= 7.5.19 - Cross Site Scripting (XSS) Vulnerability | | |
CVE-2025-31435 | WordPress Microblog Poster plugin <= 2.1.6 - Cross Site Request Forgery (CSRF) to Stored XSS vulnerability | | |
CVE-2025-31436 | WordPress Blubrry PowerPress Podcasting plugin MultiSite add-on plugin <= 0.1.1 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31437 | WordPress WP-OGP <= 1.0.5 - Cross Site Scripting (XSS) Vulnerability | | |
CVE-2025-31438 | WordPress WP Supersized <= 3.1.6 - Cross Site Request Forgery (CSRF) Vulnerability | | |
CVE-2025-31439 | WordPress Browser Caching with .htaccess 1.2.1 - Cross Site Request Forgery (CSRF) Vulnerability | | |
CVE-2025-31440 | WordPress Terms of Use plugin <= 2.0 - Cross Site Request Forgery (CSRF) to Stored XSS vulnerability | | |
CVE-2025-31441 | WordPress WordPress Galleria plugin <= 1.4 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31442 | WordPress Search engine keywords highlighter plugin <= 0.1.3 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31443 | WordPress KK I Like It plugin <= 1.7.5.3 - CSRF to Stored XSS vulnerability | | |
CVE-2025-31444 | WordPress ShowTime Slideshow plugin <= 1.6 - Cross Site Request Forgery (CSRF) to Stored XSS vulnerability | | |
CVE-2025-31445 | WordPress Pages Order plugin <= 1.1.3 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31446 | WordPress WP Cleaner plugin <= 1.1.5 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31447 | WordPress NertWorks All in One Social Share Tools <=1.26 - Cross Site Request Forgery (CSRF) Vulnerability | | |
CVE-2025-31448 | WordPress Simple Trackback Disabler <= 1.4 - Cross Site Request Forgery (CSRF) Vulnerability | | |
CVE-2025-31449 | WordPress The Visitor Counter plugin <= 1.4.3 - Cross Site Request Forgery (CSRF) to Stored XSS vulnerability | | |
CVE-2025-31450 | WordPress Toggle Box <= 1.6 - Cross Site Scripting (XSS) Vulnerability | | |
CVE-2025-31451 | WordPress wBounce <= 1.8.1 - Cross Site Scripting (XSS) Vulnerability | | |
CVE-2025-31452 | WordPress WP Ultimate Search <= 2.0.3 - Cross Site Scripting (XSS) Vulnerability | | |
CVE-2025-31453 | WordPress YouTube SimpleGallery <= 2.0.6 - Cross Site Scripting (XSS) Vulnerability | | |
CVE-2025-31454 | WordPress Delete Post Revision plugin <= 1.1 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31455 | WordPress Limit Max IPs Per User plugin <= 1.5 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31456 | WordPress Ultimate Security Checker plugin <= 4.2 - Cross Site Request Forgery (CSRF) to Security Rescan vulnerability | | |
CVE-2025-31457 | WordPress LWS SMS <= 2.4.1 - Cross Site Request Forgery (CSRF) Vulnerability | | |
CVE-2025-31458 | WordPress Video Embedder plugin <= 1.7.1 - Cross Site Request Forgery (CSRF) to Stored XSS vulnerability | | |
CVE-2025-31459 | WordPress Login Alert plugin <= 0.2.1 - CSRF to Stored XSS vulnerability | | |
CVE-2025-31460 | WordPress OmniLeads Scripts and Tags Manager plugin <= 1.3 - CSRF to Stored XSS vulnerability | | |
CVE-2025-31461 | WordPress NanoSupport plugin <= 0.6.0 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31462 | WordPress CGM Event Calendar <= 0.8.5 - Cross Site Scripting (XSS) Vulnerability | | |
CVE-2025-31463 | WordPress TGG WP Optimizer <= 1.22 - Cross Site Scripting (XSS) Vulnerability | | |
CVE-2025-31464 | WordPress Text Selection Color <= 1.6 - Cross Site Scripting (XSS) Vulnerability | | |
CVE-2025-31465 | WordPress Better Section Navigation Widget <= 1.6.1 - Cross Site Scripting (XSS) Vulnerability | | |
CVE-2025-31466 | WordPress Duplicate Page and Post <= 1.0 - SQL Injection Vulnerability | | |
CVE-2025-31467 | WordPress Flickr Photostream plugin <= 3.1.8 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31468 | WordPress WP_Identicon plugin <= 2.0 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31469 | WordPress Clear Sucuri Cache <= 1.4 - Broken Access Control Vulnerability | | |
CVE-2025-31470 | WordPress Page Takeover <= 1.1.6 - Cross Site Scripting (XSS) Vulnerability | | |
CVE-2025-31471 | WordPress Duplicate Page and Post <= 1.0 - Cross Site Scripting (XSS) Vulnerability | | |
CVE-2025-31472 | WordPress Flatty <= 2.0.0 - Cross Site Scripting (XSS) Vulnerability | | |
CVE-2025-31473 | WordPress WP Database Optimizer <= 1.2.1.3 - Cross Site Scripting (XSS) Vulnerability | | |
CVE-2025-31474 | WordPress WP Database Optimizer <= 1.2.1.3 - Cross Site Request Forgery (CSRF) Vulnerability | | |
CVE-2025-31475 | tarteaucitron.js allows prototype pollution via custom text injection | | |
CVE-2025-31476 | tarteaucitron.js allows url scheme injection via unfiltered inputs | | |
CVE-2025-31477 | Improper Scope Validation in the open Endpoint of tauri-plugin-shell | E S | |
CVE-2025-31478 | Zulip Authentication Backend Configuration Bypass | | |
CVE-2025-31479 | canonical/get-workflow-version-action can leak a partial GITHUB_TOKEN in exception output | | |
CVE-2025-31480 | aiven-extras allows PostgreSQL Privilege Escalation through format function | | |
CVE-2025-31481 | GraphQL query operations security can be bypassed | | |
CVE-2025-31482 | FreshRSS vulnerable to DoS by malicious feed entry loading logout URL | | |
CVE-2025-31483 | Stored XSS in Miniflux Media Proxy due to improper Content-Security-Policy configuration | | |
CVE-2025-31484 | conda-forge infrastructure uses a bad token for Azure's cf-staging access | | |
CVE-2025-31485 | GraphQL grant on a property might be cached with different objects | | |
CVE-2025-31486 | Vite allows server.fs.deny to be bypassed with .svg or relative paths | E | |
CVE-2025-31487 | The XWiki JIRA extension allows data leak through an XXE attack by using a fake JIRA server | | |
CVE-2025-31488 | Plain Craft Launcher's custom homepage can use Internet Explorer to load web pages with the help of controls such as WebBrowser | | |
CVE-2025-31489 | MinIO performs incomplete signature validation for unsigned-trailer uploads | | |
CVE-2025-31490 | AutoGPT allows SSRF due to DNS Rebinding in requests wrapper | E S | |
CVE-2025-31491 | AutoGPT allows leakage of cross-domain cookies and protected headers in requests redirect | E | |
CVE-2025-31492 | mod_auth_openidc allows OIDCProviderAuthRequestMethod POSTs to leak protected data | | |
CVE-2025-31493 | Path traversal of collection names during file system lookup | | |
CVE-2025-31494 | AutoGPT allows cross-user sharing of node execution results through WebSockets API | S | |
CVE-2025-31496 | apollo-compiler Named Fragment Processing Vulnerability | | |
CVE-2025-31497 | TEIGarage XML External Entity (XXE) Injection in Document Conversion Service | | |
CVE-2025-31498 | c-ares has a use-after-free in read_answers() | | |
CVE-2025-31499 | Jellyfin Vulnerable to Argument Injection in FFmpeg | | |
CVE-2025-31500 | Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an Asse... | | |
CVE-2025-31501 | Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an RT p... | | |
CVE-2025-31515 | Rejected reason: Not used... | R | |
CVE-2025-31516 | Rejected reason: Not used... | R | |
CVE-2025-31517 | Rejected reason: Not used... | R | |
CVE-2025-31518 | Rejected reason: Not used... | R | |
CVE-2025-31519 | Rejected reason: Not used... | R | |
CVE-2025-31520 | Rejected reason: Not used... | R | |
CVE-2025-31521 | Rejected reason: Not used... | R | |
CVE-2025-31522 | Rejected reason: Not used... | R | |
CVE-2025-31523 | Rejected reason: Not used... | R | |
CVE-2025-31524 | WordPress WP User Profiles plugin <= 2.6.2 - Privilege Escalation vulnerability | | |
CVE-2025-31525 | WordPress WP Mobile Bottom Menu plugin <= 1.2.9 - Broken Access Control vulnerability | | |
CVE-2025-31526 | WordPress Behance Portfolio Manager plugin <= 1.7.4 - SQL Injection vulnerability | | |
CVE-2025-31527 | WordPress WP Link Preview plugin <= 1.4.1 - Server Side Request Forgery (SSRF) vulnerability | | |
CVE-2025-31528 | WordPress StaticPress plugin <= 0.4.5 - Broken Access Control vulnerability | | |
CVE-2025-31529 | WordPress Slider Path for Elementor plugin <= 3.0.0 - Broken Access Control vulnerability | | |
CVE-2025-31530 | WordPress Google SEO Pressor Snippet plugin <= 2.0 - Broken Access Control vulnerability | | |
CVE-2025-31531 | WordPress History Log by click5 plugin <= 1.0.13 - SQL Injection vulnerability | | |
CVE-2025-31532 | WordPress AtomChat plugin <= 1.1.6 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31533 | WordPress Salesmate Add-On for Gravity Forms plugin <= 2.0.3 - Broken Access Control vulnerability | | |
CVE-2025-31534 | WordPress Shopper plugin <= 3.2.5 - SQL Injection vulnerability | | |
CVE-2025-31535 | WordPress Simple Owl Carousel plugin <= 1.1.1 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31536 | WordPress CF7 Spreadsheets plugin <= 2.3.2 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31537 | WordPress Bulk NoIndex & NoFollow Toolkit plugin <= 2.16 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31538 | WordPress Checklist plugin <= 1.1.9 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31539 | WordPress Cryptocurrency Widgets Pack plugin <= 2.0.1 - Broken Access Control vulnerability | | |
CVE-2025-31540 | WordPress ACME Divi Modules plugin <= 1.3.5 - Broken Access Control vulnerability | | |
CVE-2025-31541 | WordPress TuriTop Booking System plugin <= 1.0.10 - Broken Access Control vulnerability | | |
CVE-2025-31542 | WordPress My auctions allegro plugin <= 3.6.20 - SQL Injection vulnerability | | |
CVE-2025-31543 | WordPress Twice Commerce plugin <= 1.3.1 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31544 | WordPress Swiss Toolkit For WP plugin <= 1.3.0 - Broken Access Control vulnerability | | |
CVE-2025-31545 | WordPress Safe Ai Malware Protection for WP plugin <= 1.0.20 - Broken Access Control vulnerability | | |
CVE-2025-31546 | WordPress Swiss Toolkit For WP plugin <= 1.3.0 - Broken Access Control vulnerability | | |
CVE-2025-31547 | WordPress Uptime Robot Plugin for WordPress plugin <= 2.3 - SQL Injection vulnerability | | |
CVE-2025-31548 | WordPress Ultimate Push Notifications plugin <= 1.1.8 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31549 | WordPress Fusion plugin <= 1.6.3 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31550 | WordPress WP-LESS plugin <= 1.9.3-3 - Sensitive Data Exposure vulnerability | | |
CVE-2025-31551 | WordPress Salesmate Add-On for Gravity Forms plugin <= 2.0.3 - SQL Injection vulnerability | | |
CVE-2025-31552 | WordPress RSVPMarker plugin <= 11.4.8 - SQL Injection vulnerability | | |
CVE-2025-31553 | WordPress Advanced WooCommerce Product Sales Reporting plugin <= 3.1 - SQL Injection vulnerability | | |
CVE-2025-31554 | WordPress Docxpresso plugin <= 2.6 - Arbitrary File Download vulnerability | | |
CVE-2025-31555 | WordPress ContentMX Content Publisher plugin <= 1.0.6 - Broken Access Control vulnerability | | |
CVE-2025-31556 | WordPress IMPress for IDX Broker plugin <= 3.2.3 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31557 | WordPress OSM – OpenStreetMap plugin <= 6.1.6 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31558 | WordPress TailPress plugin <= 0.4.4 - Sensitive Data Exposure vulnerability | | |
CVE-2025-31559 | WordPress Custom Database Applications by Caspio plugin <= 2.1 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31560 | WordPress Salon booking system plugin <= 10.11 - Privilege Escalation vulnerability | | |
CVE-2025-31561 | WordPress Ultimate Push Notifications plugin <= 1.1.8 - SQL Injection vulnerability | | |
CVE-2025-31562 | WordPress Uptime Robot Plugin for WordPress plugin <= 2.3 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31563 | WordPress AI Search Bar plugin <= 1.3 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31564 | ChatGPT Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One plugin <= 2.1.7 - SQL Injection vulnerability | | |
CVE-2025-31565 | WordPress WPSmartContracts plugin <= 2.0.10 - SQL Injection vulnerability | | |
CVE-2025-31566 | WordPress Rio Video Gallery plugin <= 2.3.6 - CSRF to Stored XSS vulnerability | | |
CVE-2025-31567 | WordPress Themesflat Addons For Elementor plugin <= 2.2.5 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31568 | WordPress LeadLab by wiredminds plugin <= 1.3 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31569 | WordPress wordpress related Posts with thumbnails plugin <= 3.0.0.1 - CSRF to Stored XSS vulnerability | | |
CVE-2025-31570 | WordPress Related Posts Widget with Thumbnails plugin <= 1.2 - CSRF to Stored XSS vulnerability | | |
CVE-2025-31571 | WordPress The Logo Slider plugin <= 1.0.0 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31572 | WordPress Multi Days Events and Multi Events in One Day Calendar plugin <= 1.1.3 - Cross Site Request Forgery (CSRF) vulnerability | | |
CVE-2025-31573 | WordPress PeproDev CF7 Database plugin <= 2.0.0 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31574 | WordPress Custom Content Scrollbar plugin <= 1.3 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31575 | WordPress Flag Icons plugin <= 2.2 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31576 | WordPress PostmarkApp Email Integrator plugin <= 2.4 - Broken Access Control vulnerability | | |
CVE-2025-31577 | WordPress Appointify plugin <= 1.0.8 - Arbitrary File Upload vulnerability | | |
CVE-2025-31578 | WordPress Fonts Manager | Custom Fonts plugin <= 1.2 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31579 | WordPress WP AutoKeyword plugin <= 1.0 - SQL Injection vulnerability | | |
CVE-2025-31580 | WordPress Ni WooCommerce Product Enquiry plugin <= 4.1.8 - Broken Access Control vulnerability | | |
CVE-2025-31581 | WordPress WP Video Playlist plugin <= 1.1.2 - Settings Change vulnerability | | |
CVE-2025-31582 | WordPress Contact Form vCard Generator plugin <= 2.4 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31583 | WordPress WP Copy Media URL plugin <= 2.1 - CSRF to Stored XSS vulnerability | | |
CVE-2025-31584 | WordPress Elfsight Testimonials Slider plugin <= 1.0.1 - Broken Access Control vulnerability | | |
CVE-2025-31585 | WordPress Leadfox for WordPress plugin <= 2.1.8 - CSRF to Stored XSS vulnerability | | |
CVE-2025-31586 | WordPress Gallery – Photo Albums Plugin plugin <= 1.3.170 - Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31587 | WordPress Elfsight Testimonials Slider plugin <= 1.0.1 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31588 | WordPress Elfsight Testimonials Slider plugin <= 1.0.1 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability | | |
CVE-2025-31589 | WordPress Ethiopian Calendar plugin <= 1.1.1 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31590 | WordPress WP Date and Time Shortcode plugin <= 2.6.7 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31591 | WordPress Exit Popup Free plugin <= 1.0 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31592 | WordPress Send E-mail plugin <= 1.3 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31593 | WordPress OpenMenu plugin <= 3.5 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31594 | WordPress Auto scroll for reading plugin <= 1.1.4 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31595 | WordPress Timeline Event History plugin <= 3.2 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31596 | WordPress Chat by Chatwee plugin <= 2.1.3 - Broken Access Control vulnerability | | |
CVE-2025-31597 | WordPress Ultimate Live Cricket WordPress Lite plugin <= 1.4.2 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31598 | WordPress Quantity Dynamic Pricing & Bulk Discounts for WooCommerce plugin <= 4.0.0 - Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31599 | WordPress Bulk Product Sync plugin <= 8.6 - SQL Injection vulnerability | | |
CVE-2025-31600 | WordPress DesignO plugin <= 2.2.0 - Cross Site Request Forgery (CSRF) vulnerability | | |
CVE-2025-31601 | WordPress Appointy Appointment Scheduler plugin <= 4.2.1 - CSRF to Settings Change vulnerability | | |
CVE-2025-31602 | WordPress Apimo Connector plugin <= 2.6.3.1 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability | | |
CVE-2025-31603 | WordPress CF7 Spreadsheets plugin <= 2.3.2 - Settings Change vulnerability | | |
CVE-2025-31604 | WordPress Cal.com plugin <= 1.0.0 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31605 | WordPress Welcome Popup plugin <= 1.0.10 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31606 | WordPress SP Blog Designer plugin <= 1.0.0 - Arbitrary Shortcode Execution vulnerability | | |
CVE-2025-31607 | WordPress Simple-Audioplayer plugin <= 1.1 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31608 | WordPress CookieHint WP plugin <= 1.0.0 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31609 | WordPress WPCargo Track & Trace plugin <= 7.0.6 - Insecure Direct Object References (IDOR) vulnerability | | |
CVE-2025-31610 | WordPress Notification Bar, Sticky Notification Bar, Sticky Welcome Bar for any theme plugin <= 1.1 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31611 | WordPress Auto Post After Image Upload plugin <= 1.6 - Broken Access Control vulnerability | | |
CVE-2025-31612 | WordPress CBX Poll plugin <= 1.2.7 - PHP Object Injection vulnerability | | |
CVE-2025-31613 | WordPress AB Google Map Travel plugin <= 4.6 - CSRF to Stored XSS vulnerability | | |
CVE-2025-31614 | WordPress Terms Before Download plugin <= 1.0.4 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31615 | WordPress Simple Contact Forms plugin <= 1.6.4 - CSRF to Stored XSS vulnerability | | |
CVE-2025-31616 | WordPress Varnish WordPress plugin <= 1.7 - CSRF to Stored XSS vulnerability | | |
CVE-2025-31617 | WordPress PostmarkApp Email Integrator plugin <= 2.4 - CSRF to Stored XSS vulnerability | | |
CVE-2025-31618 | WordPress Connector to CiviCRM with CiviMcRestFace plugin <= 1.0.9 - Broken Access Control vulnerability | | |
CVE-2025-31619 | WordPress Actionwear products sync plugin <= 2.3.3 - SQL Injection vulnerability | | |
CVE-2025-31620 | WordPress CoverManager plugin <= 0.0.1 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31621 | WordPress byBrick Accordion plugin <= 1.0 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31622 | WordPress Advanced Typekit plugin <= 1.0.1 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31623 | WordPress Rich Text Editor plugin <= 1.0.1 - CSRF to Stored XSS vulnerability | | |
CVE-2025-31624 | WordPress Processing Projects plugin <= 1.0.2 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31625 | WordPress Useinfluence plugin <= 1.0.8 - Cross Site Request Forgery (CSRF) vulnerability | | |
CVE-2025-31626 | WordPress Support Helpdesk Ticket System Lite plugin <= 4.5.2 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31627 | WordPress Media Library Assistant plugin <= 3.24 - Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31628 | WordPress Sliced Invoices plugin <= 3.9.4 - Broken Access Control vulnerability | | |
CVE-2025-31629 | WordPress Infusionsoft Web Form JavaScript plugin <= 1.1.1 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31630 | WordPress The Business <= 1.6.1 - Broken Access Control Vulnerability | | |
CVE-2025-31631 | WordPress Fish House <= 1.2.7 - PHP Object Injection Vulnerability | | |
CVE-2025-31632 | WordPress La Boom <= 2.7 - Local File Inclusion Vulnerability | | |
CVE-2025-31633 | WordPress Kiamo - Responsive Business Service WordPress Theme <= 1.3.3 - Local File Inclusion Vulnerability | | |
CVE-2025-31635 | WordPress CLEVER <= 2.6 - Arbitrary File Download Vulnerability | | |
CVE-2025-31636 | WordPress WP Post Modules for Elementor plugin <= 2.5.0 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31637 | WordPress SHOUT <= 3.5.3 - SQL Injection Vulnerability | | |
CVE-2025-31638 | WordPress Spare <= 1.7 - Cross Site Scripting (XSS) Vulnerability | | |
CVE-2025-31639 | WordPress Spare <= 1.7 - Cross Site Request Forgery (CSRF) Vulnerability | | |
CVE-2025-31640 | WordPress Magic Responsive Slider and Carousel WordPress <= 1.4 - SQL Injection Vulnerability | | |
CVE-2025-31641 | WordPress UberSlider <= 2.3 - SQL Injection Vulnerability | | |
CVE-2025-31644 | Appliance mode BIG-IP iControl REST and tmsh vulnerability | | |
CVE-2025-31650 | Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame | | |
CVE-2025-31651 | Apache Tomcat: Bypass of rules in Rewrite Valve | | |
CVE-2025-31654 | Growatt Cloud portal Authorization Bypass Through User-Controlled Key | S | |
CVE-2025-31672 | Apache POI: parsing OOXML based files (xlsx, docx, etc.), poi-ooxml could read unexpected data if underlying zip has duplicate zip entry names | | |
CVE-2025-31673 | Drupal core - Moderately critical - Access bypass - SA-CORE-2025-002 | | |
CVE-2025-31674 | Drupal core - Moderately critical - Gadget Chain - SA-CORE-2025-003 | | |
CVE-2025-31675 | Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2025-004 | | |
CVE-2025-31676 | Email TFA - Moderately critical - Access bypass - SA-CONTRIB-2025-001 | | |
CVE-2025-31677 | AI (Artificial Intelligence) - Critical - Cross Site Request Forgery - SA-CONTRIB-2025-003 | | |
CVE-2025-31678 | AI (Artificial Intelligence) - Moderately critical - Access bypass, Information Disclosure - SA-CONTRIB-2025-004 | | |
CVE-2025-31679 | Ignition Error Pages - Critical - Cross Site Scripting - SA-CONTRIB-2025-007 | | |
CVE-2025-31680 | Matomo Analytics - Moderately critical - Cross site request forgery - SA-CONTRIB-2025-008 | | |
CVE-2025-31681 | Authenticator Login - Critical - Access bypass - SA-CONTRIB-2025-009 | | |
CVE-2025-31682 | Google Tag - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-011 | | |
CVE-2025-31683 | Google Tag - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2025-012 | | |
CVE-2025-31684 | OAuth2 Client - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2025-013 | | |
CVE-2025-31685 | Open Social - Moderately critical - Access bypass - SA-CONTRIB-2025-014 | | |
CVE-2025-31686 | Open Social - Less critical - Access bypass, Information Disclosure - SA-CONTRIB-2025-015 | | |
CVE-2025-31687 | SpamSpan filter - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-016 | | |
CVE-2025-31688 | Configuration Split - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2025-017 | | |
CVE-2025-31689 | General Data Protection Regulation - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2025-018 | | |
CVE-2025-31690 | Cache Utility - Moderately critical - Cross Site Request Forgery - SA-CONTRIB-2025-019 | | |
CVE-2025-31691 | OAuth2 Server - Moderately critical - Access bypass - SA-CONTRIB-2025-020 | | |
CVE-2025-31692 | AI (Artificial Intelligence) - Critical - Remote Code Execution - SA-CONTRIB-2025-021 | | |
CVE-2025-31693 | AI (Artificial Intelligence) - Moderately critical - Gadget Chain - SA-CONTRIB-2025-022 | | |
CVE-2025-31694 | Two-factor Authentication (TFA) - Moderately critical - Access bypass - SA-CONTRIB-2025-023 | | |
CVE-2025-31695 | Link field display mode formatter - Moderately critical - Cross site scripting - SA-CONTRIB-2025-024 | | |
CVE-2025-31696 | RapiDoc OAS Field Formatter - Moderately critical - Cross site scripting - SA-CONTRIB-2025-025 | | |
CVE-2025-31697 | Formatter Suite - Moderately critical - Cross site scripting - SA-CONTRIB-2025-026 | | |
CVE-2025-31698 | Apache Traffic Server: Client IP address from PROXY protocol is not used for ACL | | |
CVE-2025-31710 | In engineermode service, there is a possible command injection due to improper input validation. Thi... | | |
CVE-2025-31711 | In cplog service, there is a possible system crash due to null pointer dereference. This could lead ... | | |
CVE-2025-31712 | In cplog service, there is a possible out of bounds write due to a missing bounds check. This could ... | | |
CVE-2025-31720 | A missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers wi... | | |
CVE-2025-31721 | A missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers wi... | | |
CVE-2025-31722 | In Jenkins Templating Engine Plugin 2.5.3 and earlier, libraries defined in folders are not subject ... | | |
CVE-2025-31723 | A cross-site request forgery (CSRF) vulnerability in Jenkins Simple Queue Plugin 1.4.6 and earlier a... | | |
CVE-2025-31724 | Jenkins Cadence vManager Plugin 4.0.0-282.v5096a_c2db_275 and earlier stores Verisium Manager vAPI k... | | |
CVE-2025-31725 | Jenkins monitor-remote-job Plugin 1.0 stores passwords unencrypted in job config.xml files on the Je... | | |
CVE-2025-31726 | Jenkins Stack Hammer Plugin 1.0.6 and earlier stores Stack Hammer API keys unencrypted in job config... | | |
CVE-2025-31727 | Jenkins AsakusaSatellite Plugin 0.1.1 and earlier stores AsakusaSatellite API keys unencrypted in jo... | | |
CVE-2025-31728 | Jenkins AsakusaSatellite Plugin 0.1.1 and earlier does not mask AsakusaSatellite API keys displayed ... | | |
CVE-2025-31729 | WordPress WooTumblog plugin <= 2.1.4 - Content Injection vulnerability | | |
CVE-2025-31730 | WordPress Marketer Addons Plugin <= 1.0.1 - Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31731 | WordPress Author Bio Shortcode Plugin <= 2.5.3 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31732 | WordPress GB Gallery Slideshow plugin <= 1.3 - Broken Access Control vulnerability | | |
CVE-2025-31733 | WordPress WP Sitemap Plugin <= 1.0.0 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31734 | WordPress Simple Post Expiration plugin <= 1.0.1 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31735 | WordPress Footnotes for WordPress plugin <= 2016.1230 - Cross Site Scripting (XSS) Vulnerability | | |
CVE-2025-31736 | WordPress Rich Text Editor Plugin <= 1.0.1 - Broken Access Control vulnerability | | |
CVE-2025-31737 | WordPress Client Showcase plugin <= 1.2.0 - Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31738 | WordPress LeadQuizzes Plugin <= 1.1.0 - Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31739 | WordPress Minimalistic Event Manager plugin <= 1.1.1 - Broken Access Control vulnerability | | |
CVE-2025-31740 | WordPress News, Magazine and Blog Elements Plugin <= 1.3 - Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31741 | WordPress Easy Magazine plugin <= 2.1.13 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31742 | WordPress Dima Take Action Plugin <= 1.0.5 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31743 | WordPress Lightweight and Responsive Youtube Embed Plugin <= 1.0.0 - Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31744 | WordPress Lightweight and Responsive Youtube Embed plugin <= 1.0.0 - Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31745 | WordPress Subscription Form for Feedblitz Plugin <= 1.0.9 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31746 | WordPress Clients plugin <= 1.1.4 - Broken Access Control vulnerability | | |
CVE-2025-31747 | WordPress WP Chrono plugin <= 1.5.4 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31748 | WordPress Opal Portfolio Plugin <= 1.0.4 - Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31749 | WordPress HMH Footer Builder For Elementor plugin <= 1.0 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31750 | WordPress Breaking News WP Plugin <= 1.3 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31751 | WordPress Breaking News WP Plugin <= 1.3 - CSRF to Settings Change vulnerability | | |
CVE-2025-31752 | WordPress Bulk Fields Editor plugin <= 1.8.0 - Broken Access Control vulnerability | | |
CVE-2025-31753 | WordPress Advanced Speed Increaser Plugin <= 2.2.1 - Cross Site Request Forgery (CSRF) vulnerability | | |
CVE-2025-31754 | WordPress DobsonDev Shortcodes plugin <= 2.1.12 - Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31755 | WordPress pCloud Backup plugin <= 1.0.1 - Broken Access Control vulnerability | | |
CVE-2025-31756 | WordPress TZ PlusGallery Plugin <= 1.5.5 - Cross Site Request Forgery (CSRF) vulnerability | | |
CVE-2025-31757 | WordPress Free Woocommerce Product Table View plugin <= 1.78 - Broken Access Control vulnerability | | |
CVE-2025-31758 | WordPress Free Woocommerce Product Table View plugin <= 1.78 - Arbitrary Content Deletion vulnerability | | |
CVE-2025-31759 | WordPress Boo Recipes plugin <= 2.4.1 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31760 | WordPress SnapWidget Social Photo Feed Widget plugin <= 1.1.0 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31761 | WordPress Hypotext plugin <= 1.0.1 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31762 | WordPress Sheet2Site plugin <= 1.0.18 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31763 | WordPress Cache control by Cacholong Plugin <= 5.4.1 - Cross Site Request Forgery (CSRF) vulnerability | | |
CVE-2025-31764 | WordPress Cache control by Cacholong plugin <= 5.4.1 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31765 | WordPress GDPR Cookie Notice plugin <= 1.2.0 - Broken Access Control vulnerability | | |
CVE-2025-31766 | WordPress PhotoShelter for Photographers Blog Feed plugin <= 1.5.7 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31767 | WordPress Post Custom Templates Lite plugin <= 1.14 - Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31768 | WordPress Widget Manager Light plugin <= 1.18 - Broken Access Control vulnerability | | |
CVE-2025-31769 | WordPress CLP – Custom Login Page by NiteoThemes plugin <= 1.5.5 - Cross Site Request Forgery (CSRF) vulnerability | | |
CVE-2025-31770 | WordPress Content Manager Light plugin <= 3.2 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31771 | WordPress Team Members for Elementor Page Builder plugin <= 1.0.4 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31772 | WordPress WP Modal Popup with Cookie Integration plugin <= 2.4 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31773 | WordPress Ship Per Product plugin <= 2.1.0 - Broken Access Control vulnerability | | |
CVE-2025-31774 | WordPress Astra Security Suite plugin<= 0.2 - Broken Access Control vulnerability | | |
CVE-2025-31775 | WordPress Google SEO Pressor for Rich snippets Plugin <= 2.0 - Cross Site Request Forgery (CSRF) vulnerability | | |
CVE-2025-31776 | WordPress Uptime Robot Plugin <= 2.3 - Cross Site Request Forgery (CSRF) vulnerability | | |
CVE-2025-31777 | WordPress Clockinator Lite plugin <= 1.0.7 - Broken Access Control vulnerability | | |
CVE-2025-31778 | WordPress Donate Me Plugin <= 1.2.5 - Stored Cross-Site Scripting vulnerability | | |
CVE-2025-31779 | WordPress Query Wrangler plugin <= 1.5.53 - Cross Site Request Forgery (CSRF) vulnerability | | |
CVE-2025-31780 | WordPress Append Content plugin <= 2.1.1 - CSRF to Settings Change vulnerability | | |
CVE-2025-31781 | WordPress Gift Cards for WooCommerce plugin <= 1.5.8 - Broken Access Control vulnerability | | |
CVE-2025-31782 | WordPress mb.YTPlayer plugin <= 3.3.8 - Broken Access Control vulnerability | | |
CVE-2025-31783 | WordPress Leartes TRY Exchange Rates Plugin <= 2.1 - Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31784 | WordPress Embed Extended – Embed Maps, Videos, Websites, Source Codes, and more Plugin <= 1.4.0 - Cross Site Request Forgery (CSRF) vulnerability | | |
CVE-2025-31785 | WordPress Clearbit Reveal plugin <= 1.0.6 - Cross Site Request Forgery (CSRF) vulnerability | | |
CVE-2025-31786 | WordPress Simple Icons plugin <= 2.8.4 - Broken Access Control vulnerability | | |
CVE-2025-31787 | WordPress Cue by AudioTheme.com plugin <= 2.4.4 - Broken Access Control vulnerability | | |
CVE-2025-31788 | WordPress AIO Performance Profiler, Monitor, Optimize, Compress & Debug plugin <= 1.2 - Sensitive Data Exposure vulnerability | | |
CVE-2025-31789 | WordPress TextMe SMS plugin <= 1.9.1 - Broken Access Control vulnerability | S | |
CVE-2025-31790 | WordPress Posten plugin <= 0.0.1 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31791 | WordPress Pin Generator Plugin <= 2.0.0 - Broken Access Control vulnerability | | |
CVE-2025-31792 | WordPress Piotnet Forms plugin <= 1.0.30 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31793 | WordPress Piotnet Forms plugin <= 1.0.30 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31794 | WordPress WR Price List Manager For Woocommerce plugin <= 1.0.8 - Arbitrary Content Deletion vulnerability | | |
CVE-2025-31795 | WordPress Shopify to WooCommerce Migration plugin <= 1.3.0 - Settings Change vulnerability | | |
CVE-2025-31796 | WordPress ElementsCSS Addons for Elementor plugin <= 1.0.8.7 - Server Side Request Forgery (SSRF) vulnerability | | |
CVE-2025-31797 | WordPress Sprout Clients plugin <= 3.2 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31798 | WordPress Publitio Plugin <= 2.1.8 - Broken Access Control vulnerability | | |
CVE-2025-31799 | WordPress Publitio plugin <= 2.1.8 - Broken Access Control vulnerability | | |
CVE-2025-31800 | WordPress Publitio plugin <= 2.1.8 - Arbitrary File Read vulnerability | | |
CVE-2025-31801 | WordPress MX Time Zone Clocks plugin <= 5.1.1 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31802 | WordPress Shiptimize for WooCommerce plugin <= 3.1.86 - Settings Change vulnerability | | |
CVE-2025-31803 | WordPress Turisbook Booking System plugin <= 1.3.7 - Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31804 | WordPress Follow Us Badges plugin <= 3.1.11 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31805 | WordPress Gutena Kit plugin <= 2.0.7 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31806 | WordPress Webling Plugin <= 3.9.0 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31807 | WordPress Product Notices for WooCommerce plugin <= 1.3.3 - Cross Site Request Forgery (CSRF) vulnerability | | |
CVE-2025-31808 | WordPress SCSS WP Editor Plugin <= 1.1.8 - Cross Site Request Forgery (CSRF) vulnerability | | |
CVE-2025-31809 | WordPress Labinator Content Types Duplicator Plugin <= 1.1.3 - Cross Site Request Forgery (CSRF) vulnerability | | |
CVE-2025-31810 | WordPress Question Answer Plugin <= 1.2.70 - Broken Access Control vulnerability | | |
CVE-2025-31811 | WordPress Planyo online reservation system plugin <= 3.0 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31812 | WordPress BuddyPress Members Only plugin <= 3.5.3 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31813 | WordPress WPSHARE247 Elementor Addons plugin <= 2.1 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31814 | WordPress OwnerRez Plugin <= 1.2.0 - Cross Site Request Forgery (CSRF) vulnerability | | |
CVE-2025-31815 | WordPress Design Blocks plugin <= 1.2.2 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31816 | WordPress Mobile App Canvas Plugin <= 3.8.1 - Broken Access Control vulnerability | | |
CVE-2025-31817 | WordPress BlockWheels plugin <= 1.0.1 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31818 | WordPress ContentBot AI Writer plugin <= 1.2.4 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31819 | WordPress Nova Blocks by Pixelgrade plugin <= 2.1.8 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31820 | WordPress Automatic Featured Images from Videos plugin <= 1.2.4 - Broken Access Control vulnerability | | |
CVE-2025-31821 | WordPress Integration of Zoho CRM and Contact Form 7 plugin <= 1.0.6 - Open Redirection Vulnerability | | |
CVE-2025-31822 | WordPress WordPress Simple HTML Sitemap plugin <= 3.2 - Broken Access Control vulnerability | | |
CVE-2025-31823 | WordPress WPoperation Elementor Addons plugin 1.1.9 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31824 | WordPress WP Optin Wheel Plugin <= 1.4.7 - Server Side Request Forgery (SSRF) vulnerability | S | |
CVE-2025-31825 | WordPress Category Icon plugin <= 1.0.0 - Arbitrary File Download vulnerability | | |
CVE-2025-31826 | WordPress Ni WooCommerce Cost Of Goods plugin <= 3.2.8 - Broken Access Control vulnerability | | |
CVE-2025-31827 | WordPress Fonto plugin <= 1.2.2 - Arbitrary File Download vulnerability | | |
CVE-2025-31828 | WordPress Easy!Appointments plugin <= 1.4.2 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability | | |
CVE-2025-31829 | WordPress ShopCred plugin <= 1.2.8 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31830 | WordPress Printus Plugin <= 1.2.6 - Broken Access Control vulnerability | | |
CVE-2025-31831 | WordPress AtomChat plugin <= 1.1.6 - Broken Access Control vulnerability | | |
CVE-2025-31832 | WordPress ACF City Selector plugin <= 1.16.0 - Sensitive Data Exposure vulnerability | | |
CVE-2025-31833 | WordPress JobBoard Job listing plugin Plugin <= 1.2.7 - Insecure Direct Object References (IDOR) vulnerability | | |
CVE-2025-31834 | WordPress JobBoard Job listing plugin Plugin <= 1.2.7 - Broken Access Control vulnerability | | |
CVE-2025-31835 | WordPress WP Plugin Info Card plugin <= 5.2.5 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31836 | WordPress Review Manager Plugin <= 2.2.0 - Broken Access Control vulnerability | | |
CVE-2025-31837 | WordPress WP Proposals plugin <= 2.3 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31838 | WordPress Eventbee RSVP Widget plugin <= 1.0 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31839 | WordPress Footer Contacts Bar Plugin <= 1.8 - Cross Site Request Forgery (CSRF) vulnerability | | |
CVE-2025-31840 | WordPress Simple Fixed Notice Plugin <= 1.6 - Cross Site Request Forgery (CSRF) vulnerability | | |
CVE-2025-31841 | WordPress FPW Category Thumbnails Plugin <= 1.9.5 - Broken Access Control vulnerability | | |
CVE-2025-31842 | WordPress Viral Loops WP Integration Plugin <= 3.4.0 - Sensitive Data Exposure vulnerability | | |
CVE-2025-31843 | WordPress OpenAI Tools for WordPress & WooCommerce plugin <= 2.1.5 - Broken Access Control vulnerability | | |
CVE-2025-31844 | WordPress Magical Blocks plugin <= 1.0.10 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31845 | WordPress Theme Duplicator Plugin <= 1.1 - Cross Site Request Forgery (CSRF) vulnerability | | |
CVE-2025-31846 | WordPress Theater for WordPress plugin <= 0.18.7 - Broken Access Control vulnerability | | |
CVE-2025-31847 | WordPress mFolio Lite plugin <= 1.2.2 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31848 | WordPress WordPress Adverts Plugin plugin <= 1.4 - Broken Access Control vulnerability | | |
CVE-2025-31849 | WordPress Nemesis All-in-One | Newspaper Builder Elementor Extention plugin <= 1.1.0 - Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31850 | WordPress PDF Generator Addon for Elementor Page Builder plugin <= 1.7.5 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31851 | WordPress Beds24 Online Booking plugin <= 2.0.26 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31852 | WordPress Bulk Product Sync plugin <= 8.6 - Cross Site Request Forgery (CSRF) vulnerability | | |
CVE-2025-31853 | WordPress Smartarget Popup Plugin <= 1.4 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31854 | WordPress Simple Sticky Add To Cart For WooCommerce plugin <= 1.4.5 - Broken Access Control vulnerability | | |
CVE-2025-31855 | WordPress SMM API plugin <= 6.0.27 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31856 | WordPress Export All Post Meta Plugin <= 1.2.1 - Broken Access Control vulnerability | | |
CVE-2025-31857 | WordPress Directorist AddonsKit for Elementor plugin <= 1.1.6 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31858 | WordPress Local Magic Plugin <= 2.6.0 - Broken Access Control vulnerability | | |
CVE-2025-31859 | WordPress Feedbucket – Website Feedback Tool Plugin <= 1.0.6 - Cross Site Request Forgery (CSRF) vulnerability | S | |
CVE-2025-31860 | WordPress WP AdCenter plugin <= 2.5.9 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31861 | WordPress Perfect Font Awesome Integration Plugin <= 2.2 - Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31862 | WordPress Job Board Manager Plugin <= 2.1.60 - Broken Access Control vulnerability | | |
CVE-2025-31863 | WordPress Agency Toolkit plugin <= 1.0.23 - Broken Access Control vulnerability | | |
CVE-2025-31864 | WordPress Beam me up Scotty – Back to Top Button plugin <= 1.0.23 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31865 | WordPress CartBoss plugin <= 4.1.2 - Broken Access Control vulnerability | | |
CVE-2025-31866 | WordPress ShipDepot for WooCommerce plugin <= 1.2.19 - Broken Access Control vulnerability | | |
CVE-2025-31867 | WordPress JS Job Manager Plugin <= 2.0.2 - Insecure Direct Object References (IDOR) vulnerability | | |
CVE-2025-31868 | WordPress JS Job Manager plugin <= 2.0.2 - Broken Access Control vulnerability | | |
CVE-2025-31869 | WordPress Black Widgets For Elementor plugin <= 1.3.9 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31870 | WordPress WP AutoKeyword plugin <= 1.0 - Arbitrary Content Deletion vulnerability | | |
CVE-2025-31871 | WordPress WP Clone any post type Plugin <= 3.4 - Open Redirect vulnerability | | |
CVE-2025-31872 | WordPress WP Clone any post type Plugin <= 3.4 - Broken Access Control vulnerability | | |
CVE-2025-31873 | WordPress SheetDB Plugin <= 1.3.3 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31874 | WordPress WebberZone Snippetz plugin <= 2.1.0 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31875 | WordPress FancyPost plugin <= 6.0.1 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31876 | WordPress Payday plugin <= 3.3.12 - Broken Access Control vulnerability | | |
CVE-2025-31877 | WordPress RestroPress plugin <= 3.1.8.4 - Broken Access Control vulnerability | | |
CVE-2025-31878 | WordPress UPC/EAN/GTIN Code Generator plugin <= 2.0.2 - Settings Change vulnerability | | |
CVE-2025-31879 | WordPress Barcode Generator for WooCommerce plugin <= 2.0.4 - Settings Change vulnerability | | |
CVE-2025-31880 | WordPress Pearl plugin <= 1.3.9 - Cross Site Request Forgery (CSRF) vulnerability | | |
CVE-2025-31881 | WordPress Pearl plugin <= 1.3.9 - Broken Access Control vulnerability | | |
CVE-2025-31882 | WordPress WordPress Webinar Plugin <= 1.33.27 - Broken Access Control vulnerability | | |
CVE-2025-31883 | WordPress WebinarPress plugin <= 1.33.27 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31884 | WordPress Norse Rune Oracle Plugin plugin <= 1.4.3 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31885 | WordPress Hyperlink Group Block plugin <= 2.0.1 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31886 | WordPress Social proof testimonials and reviews by Repuso plugin <= 5.21 - Broken Access Control vulnerability | | |
CVE-2025-31887 | WordPress MyBookProgress plugin <= 1.0.8 - Broken Access Control vulnerability | | |
CVE-2025-31888 | WordPress WP Multi Store Locator Plugin <= 2.5.2 - Cross Site Request Forgery (CSRF) vulnerability | | |
CVE-2025-31889 | WordPress Extensions for Elementor plugin <= 2.0.40 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31890 | WordPress Simple Map No Api plugin <= 1.9 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31891 | WordPress Gosign – Posts Slider Block plugin <= 1.1.0 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31892 | WordPress WP Crowdfunding plugin <= 2.1.13 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31893 | WordPress Botnet Attack Blocker plugin <= 2.0.0 - Stored Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31894 | WordPress Ebook Downloader plugin <= 1.0 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31895 | WordPress ABC Notation Plugin <= 6.1.3 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31896 | WordPress GetBookingsWP Plugin <= 1.1.27 - Broken Access Control vulnerability | | |
CVE-2025-31897 | WordPress Arrow Custom Feed for Twitter plugin <= 1.5.3 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31898 | WordPress MediaView plugin <= 1.1.2 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31899 | WordPress Awesome Logos plugin <= 1.2 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31900 | WordPress Lexicata plugin <= 1.0.16 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31901 | WordPress Digihood HTML Sitemap Plugin <= 3.1.1 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31902 | WordPress Social Share And Social Locker Plugin <= 1.4.1 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31903 | WordPress XV Random Quotes Plugin <= 1.37 - Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31904 | WordPress Ebook Downloader plugin <= 1.0 - CSRF to Stored XSS vulnerability | | |
CVE-2025-31905 | WordPress Team Rosters Plugin <= 4.7 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31906 | WordPress WP Profitshare Plugin <= 1.4.9 - CSRF to Stored XSS vulnerability | | |
CVE-2025-31907 | WordPress Team Builder plugin <= 1.3 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31908 | WordPress JSON Structuring Markup plugin <= 0.1 - CSRF to Stored XSS vulnerability | | |
CVE-2025-31909 | WordPress Apptivo Business Site CRM plugin <= 5.3 - Arbitrary Content Deletion vulnerability | | |
CVE-2025-31910 | WordPress BookingPress Plugin <= 1.1.28 - SQL Injection vulnerability | | |
CVE-2025-31911 | WordPress Social Share And Social Locker plugin <= 1.4.2 - SQL Injection vulnerability | | |
CVE-2025-31912 | WordPress Enzio - Responsive Business WordPress Theme <= 1.1.8 - Local File Inclusion Vulnerability | | |
CVE-2025-31913 | WordPress Ogami <= 1.53 - Local File Inclusion Vulnerability | | |
CVE-2025-31914 | WordPress Pixel WordPress Form BuilderPlugin & Autoresponder <= 1.0.2 - SQL Injection Vulnerability | | |
CVE-2025-31915 | WordPress Pixel WordPress Form BuilderPlugin & Autoresponder <= 1.0.2 - Cross Site Request Forgery (CSRF) Vulnerability | | |
CVE-2025-31916 | WordPress JP Students Result Management System Premium plugin 1.1.7 - Arbitrary File Upload vulnerability | | |
CVE-2025-31917 | WordPress Universal Video Player plugin <= 3.8.3 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31918 | WordPress Simple Business Directory Pro <= 15.4.8 - Privilege Escalation Vulnerability | | |
CVE-2025-31919 | WordPress Spare <= 1.7 - PHP Object Injection Vulnerability | | |
CVE-2025-31920 | WordPress WP Guppy <= 4.3.3 - SQL Injection Vulnerability | | |
CVE-2025-31921 | WordPress WP Ultimate Tours Builder <= 1.055 - Cross Site Request Forgery (CSRF) Vulnerability | | |
CVE-2025-31922 | WordPress CSS3 Accordions for WordPress plugin <= 3.0 - CSRF to Stored XSS vulnerability | | |
CVE-2025-31923 | WordPress CSS3 Accordions for WordPress <= 3.0 - Broken Access Control Vulnerability | | |
CVE-2025-31924 | WordPress Crafts & Arts <= 2.5 - PHP Object Injection Vulnerability | | |
CVE-2025-31925 | WordPress SHOUT plugin <= 3.5.3 - Reflected Cross Site Scripting (XSS) vulnerability | | |
CVE-2025-31926 | WordPress Sticky Radio Player <= 3.4 - SQL Injection Vulnerability | | |
CVE-2025-31927 | WordPress Acerola <= 1.6.5 - PHP Object Injection Vulnerability | | |
CVE-2025-31928 | WordPress Multimedia Responsive Carousel with Image Video Audio Support <= 2.6.0 - SQL Injection Vulnerability | | |
CVE-2025-31929 | A vulnerability has been identified in IEC 1Ph 7.4kW Child socket (8EM1310-2EH04-0GA0) (All versions... | | |
CVE-2025-31930 | A vulnerability has been identified in IEC 1Ph 7.4kW Child socket (8EM1310-2EH04-0GA0) (All versions... | | |
CVE-2025-31932 | Deserialization of untrusted data issue exists in BizRobo! all versions. If this vulnerability is ex... | | |
CVE-2025-31933 | Growatt Cloud Applications Authorization Bypass Through User-Controlled Key | S | |
CVE-2025-31935 | Subnet Solutions PowerSYSTEM Center Deserialization of Untrusted Data | S | |
CVE-2025-31941 | Growatt Cloud portal Authorization Bypass Through User-Controlled Key | S | |
CVE-2025-31945 | Growatt Cloud portal Authorization Bypass Through User-Controlled Key | S | |
CVE-2025-31946 | Pixmeo OsiriX MD Use After Free | S | |
CVE-2025-31947 | Repeated LDAP login failures can lock an LDAP account | S | |
CVE-2025-31949 | Growatt Cloud portal Authorization Bypass Through User-Controlled Key | S | |
CVE-2025-31950 | Growatt Cloud portal Authorization Bypass Through User-Controlled Key | S |