Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-62040

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YOP YOP Poll yop-poll.This issue affects YOP Poll: from n/a through <= 6.5.37.

PUBLISHED
Vendor
YOP
Product
YOP Poll
Provider severity
HIGH
Conflicts
0

CVE-2025-6204

An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to execute arbitrary code.

PUBLISHEDCISA KEV
Vendor
Dassault Systèmes
Product
DELMIA Apriso
Provider severity
HIGH
Conflicts
0

CVE-2025-62039

Insertion of Sensitive Information Into Sent Data vulnerability in Ays Pro AI ChatBot with ChatGPT and Content Generator by AYS ays-chatgpt-assistant allows Retrieve Embedded Sensitive Data.This issue affects AI ChatBot with ChatGPT and Content Generator by AYS: from n/a through <= 2.6.6.

PUBLISHED
Vendor
Ays Pro
Product
AI ChatBot with ChatGPT and Content Generator by AYS
Provider severity
HIGH
Conflicts
0

CVE-2025-62038

Insertion of Sensitive Information Into Sent Data vulnerability in Sovlix MeetingHub meetinghub allows Retrieve Embedded Sensitive Data.This issue affects MeetingHub: from n/a through <= 1.23.9.

PUBLISHED
Vendor
Sovlix
Product
MeetingHub
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62037

Missing Authorization vulnerability in uxper Togo togo.This issue affects Togo: from n/a through < 1.0.4.

PUBLISHED
Vendor
uxper
Product
Togo
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62036

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxper Togo togo.This issue affects Togo: from n/a through < 1.0.4.

PUBLISHED
Vendor
uxper
Product
Togo
Provider severity
HIGH
Conflicts
0

CVE-2025-62035

Deserialization of Untrusted Data vulnerability in uxper Togo togo.This issue affects Togo: from n/a through < 1.0.4.

PUBLISHED
Vendor
uxper
Product
Togo
Provider severity
HIGH
Conflicts
0

CVE-2025-62034

Incorrect Privilege Assignment vulnerability in uxper Togo togo.This issue affects Togo: from n/a through < 1.0.4.

PUBLISHED
Vendor
uxper
Product
Togo
Provider severity
HIGH
Conflicts
0

CVE-2025-62033

Missing Authorization vulnerability in uxper Togo togo.This issue affects Togo: from n/a through < 1.0.4.

PUBLISHED
Vendor
uxper
Product
Togo
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62032

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Cloud Library td-cloud-library allows DOM-Based XSS.This issue affects tagDiv Cloud Library: from n/a through < 3.9.2.

PUBLISHED
Vendor
tagDiv
Product
tagDiv Cloud Library
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62031

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer.This issue affects tagDiv Composer: from n/a through <= 5.4.1.

PUBLISHED
Vendor
tagDiv
Product
tagDiv Composer
Provider severity
HIGH
Conflicts
0

CVE-2025-62030

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer.This issue affects tagDiv Composer: from n/a through <= 5.4.1.

PUBLISHED
Vendor
tagDiv
Product
tagDiv Composer
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6203

A malicious user may submit a specially-crafted complex payload that otherwise meets the default request size limit which results in excessive memory and CPU consumption of Vault. This may lead to a timeout in Vault’s auditing subroutine, potentially resulting in the Vault server to become unresponsive. This vulnerability, CVE-2025-6203, is fixed in Vault Community Edition 1.20.3 and Vault Enterprise 1.20.3, 1.19.9, 1.18.14, and 1.16.25.

PUBLISHED
Vendor
HashiCorp, HashiCorp
Product
Vault Enterprise, Vault
Provider severity
HIGH
Conflicts
1

CVE-2025-62029

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themesion Grevo grevo.This issue affects Grevo: from n/a through <= 2.4.

PUBLISHED
Vendor
themesion
Product
Grevo
Provider severity
HIGH
Conflicts
0

CVE-2025-62028

Missing Authorization vulnerability in ThemeNectar Salient salient.This issue affects Salient: from n/a through < 17.4.0.

PUBLISHED
Vendor
ThemeNectar
Product
Salient
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62027

Missing Authorization vulnerability in StellarWP Event Tickets event-tickets.This issue affects Event Tickets: from n/a through <= 5.26.3.

PUBLISHED
Vendor
StellarWP
Product
Event Tickets
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62026

Insertion of Sensitive Information Into Sent Data vulnerability in Blockspare Blockspare blockspare allows Retrieve Embedded Sensitive Data.This issue affects Blockspare: from n/a through <= 3.2.13.2.

PUBLISHED
Vendor
Blockspare
Product
Blockspare
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62025

Deserialization of Untrusted Data vulnerability in eyecix JobSearch wp-jobsearch.This issue affects JobSearch: from n/a through < 3.0.8.

PUBLISHED
Vendor
eyecix
Product
JobSearch
Provider severity
CRITICAL
Conflicts
0

CVE-2025-62024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jonathan Jernigan Pie Calendar pie-calendar.This issue affects Pie Calendar: from n/a through <= 1.2.9.

PUBLISHED
Vendor
Jonathan Jernigan
Product
Pie Calendar
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62023

Improper Control of Generation of Code ('Code Injection') vulnerability in Cristián Lávaque s2Member s2member.This issue affects s2Member: from n/a through <= 250905.

PUBLISHED
Vendor
Cristián Lávaque
Product
s2Member
Provider severity
CRITICAL
Conflicts
0

CVE-2025-62022

Missing Authorization vulnerability in BuddyPress BuddyPress buddypress.This issue affects BuddyPress: from n/a through <= 14.3.4.

PUBLISHED
Vendor
BuddyPress
Product
BuddyPress
Provider severity
HIGH
Conflicts
0

CVE-2025-62021

Missing Authorization vulnerability in Made Neat Acknowledgify acknowledgify.This issue affects Acknowledgify: from n/a through <= 1.1.3.

PUBLISHED
Vendor
Made Neat
Product
Acknowledgify
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62020

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Infomaniak Network VOD Infomaniak vod-infomaniak.This issue affects VOD Infomaniak: from n/a through <= 1.5.11.

PUBLISHED
Vendor
Infomaniak Network
Product
VOD Infomaniak
Provider severity
HIGH
Conflicts
0

CVE-2025-6202

Vulnerability in SK Hynix DDR5 on x86 allows a local attacker to trigger Rowhammer bit flips impacting the Hardware Integrity and the system's security. This issue affects DDR5: DIMMs produced from 2021-1 until 2024-12.

PUBLISHED
Vendor
SK Hynix
Product
DDR5
Provider severity
HIGH
Conflicts
0

CVE-2025-62019

Missing Authorization vulnerability in WPZOOM Recipe Card Blocks for Gutenberg & Elementor recipe-card-blocks-by-wpzoom.This issue affects Recipe Card Blocks for Gutenberg & Elementor: from n/a through <= 3.4.8.

PUBLISHED
Vendor
WPZOOM
Product
Recipe Card Blocks for Gutenberg & Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62018

Missing Authorization vulnerability in hogash KALLYAS kallyas.This issue affects KALLYAS: from n/a through <= 4.22.0.

PUBLISHED
Vendor
hogash
Product
KALLYAS
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62017

Missing Authorization vulnerability in hogash KALLYAS kallyas.This issue affects KALLYAS: from n/a through <= 4.22.0.

PUBLISHED
Vendor
hogash
Product
KALLYAS
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62016

Unrestricted Upload of File with Dangerous Type vulnerability in hogash KALLYAS kallyas.This issue affects KALLYAS: from n/a through <= 4.22.0.

PUBLISHED
Vendor
hogash
Product
KALLYAS
Provider severity
CRITICAL
Conflicts
0

CVE-2025-62015

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Josh Kohlbach Advanced Coupons for WooCommerce Coupons advanced-coupons-for-woocommerce-free.This issue affects Advanced Coupons for WooCommerce Coupons: from n/a through <= 4.6.8.

PUBLISHED
Vendor
Josh Kohlbach
Product
Advanced Coupons for WooCommerce Coupons
Provider severity
HIGH
Conflicts
0

CVE-2025-62014

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme ITok itok.This issue affects ITok: from n/a through <= 1.1.42.

PUBLISHED
Vendor
ApusTheme
Product
ITok
Provider severity
HIGH
Conflicts
0

CVE-2025-62013

Missing Authorization vulnerability in POSIMYTH UiChemy uichemy.This issue affects UiChemy: from n/a through <= 4.0.0.

PUBLISHED
Vendor
POSIMYTH
Product
UiChemy
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62012

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem (Elementor) thegem-elementor.This issue affects TheGem (Elementor): from n/a through <= 5.10.5.

PUBLISHED
Vendor
CodexThemes
Product
TheGem (Elementor)
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62011

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem thegem.This issue affects TheGem: from n/a through <= 5.10.5.

PUBLISHED
Vendor
CodexThemes
Product
TheGem
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62010

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme Famita famita allows PHP Local File Inclusion.This issue affects Famita: from n/a through <= 1.54.

PUBLISHED
Vendor
ApusTheme
Product
Famita
Provider severity
HIGH
Conflicts
0

CVE-2025-6201

The Pixel Manager for WooCommerce – Track Conversions and Analytics, Google Ads, TikTok and more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's conversion-pixel in all versions up to, and including, 1.49.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user ac

PUBLISHED
Vendor
alekv
Product
Pixel Manager for WooCommerce – Conversion Tracking, Google Ads, GA4, TikTok, Dynamic Remarketing
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62009

Cross-Site Request Forgery (CSRF) vulnerability in Dmitry V. (CEO of "UKR Solution") UPC/EAN/GTIN Code Generator upc-ean-barcode-generator allows Cross Site Request Forgery.This issue affects UPC/EAN/GTIN Code Generator: from n/a through <= 2.0.2.

PUBLISHED
Vendor
Dmitry V. (CEO of "UKR Solution")
Product
UPC/EAN/GTIN Code Generator
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62008

Deserialization of Untrusted Data vulnerability in acowebs Product Table For WooCommerce product-table-for-woocommerce.This issue affects Product Table For WooCommerce: from n/a through <= 1.2.4.

PUBLISHED
Vendor
acowebs
Product
Product Table For WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2025-62007

Incorrect Privilege Assignment vulnerability in bPlugins Voice Feedback voice-feedback allows Privilege Escalation.This issue affects Voice Feedback: from n/a through <= 1.0.3.

PUBLISHED
Vendor
bPlugins
Product
Voice Feedback
Provider severity
HIGH
Conflicts
0

CVE-2025-62006

Missing Authorization vulnerability in VeronaLabs WP SMS wp-sms.This issue affects WP SMS: from n/a through <= 7.0.1.

PUBLISHED
Vendor
VeronaLabs
Product
WP SMS
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62005

Cross-Site Request Forgery (CSRF) vulnerability in FantasticPlugins SUMO Memberships for WooCommerce sumomemberships allows Cross Site Request Forgery.This issue affects SUMO Memberships for WooCommerce: from n/a through < 7.8.0.

PUBLISHED
Vendor
FantasticPlugins
Product
SUMO Memberships for WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2025-62004

BullWall Server Intrusion Protection (SIP) services are initialized after login services during system startup. A local, authenticated attacker can log in after boot and before SIP MFA is running. The SIP services do not retroactively enforce MFA or disconnect sessions that were not subject to SIP MFA. Versions 4.6.0.0, 4.6.0.6, 4.6.0.7, and 4.6.1.4 are affected. Other versions mayy also be affected. BullWall plans to improve detection method documentation.

PUBLISHED
Vendor
BullWall
Product
Server Intrusion Protection
Provider severity
HIGH
Conflicts
1

CVE-2025-62003

BullWall Server Intrusion Protection has a noticeable configuration-dependent delay before the MFA check for RDP connections. A remote, authenticated attacker can potentially bypass detection during this delay. Versions 4.6.0.0, 4.6.0.6, 4.6.0.7, and 4.6.1.4 are affected. Other versions may also be affected.

PUBLISHED
Vendor
BullWall
Product
Server Intrusion Protection
Provider severity
HIGH
Conflicts
1

CVE-2025-62002

BullWall Ransomware Containment considers the number of files modified to trigger detection. An authenticated attacker could encrypt a single (possibly large) file without triggering detection if thresholds are configured to require multiple file changes. The number of files to trigger detection can be configured by the user. Versions 4.6.0.0, 4.6.0.6, 4.6.0.7, and 4.6.1.4 are affected. Other versions may also be affected.

PUBLISHED
Vendor
BullWall
Product
Ransomware Containment
Provider severity
MEDIUM
Conflicts
1

CVE-2025-62001

BullWall Ransomware Containment supports configurable file and directory exclusions such as '$RECYCLE.BIN' to balance monitoring scope and performance. Certain exclusion patterns could allow an authenticated attacker to rename directories in a way that avoids monitoring. Fixed in 4.6.1.14 and 5.0.0.42, which remove hardcoded exclusion behavior and exposes exclusion handling as configurable settings.

PUBLISHED
Vendor
BullWall
Product
Ransomware Containment
Provider severity
HIGH
Conflicts
1

CVE-2025-62000

BullWall Ransomware Containment may not always detect an encrypted file. This issue affects a specific file inspection method that evaluates file content based on header bytes. An authenticated attacker could encrypt files, preserving the first four bytes and preventing this particular method from triggering. The affected product implements additional integrity-based detection mechanisms capable of identifying file corruption or encryption for some common file extensions independent of header by

PUBLISHED
Vendor
BullWall
Product
Ransomware Containment
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2025-6200

The GeoDirectory WordPress plugin before 2.8.120 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

PUBLISHED
Vendor
Unknown
Product
GeoDirectory
Provider severity
MEDIUM
Conflicts
1

CVE-2025-61999

OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to upload JavaScript or other content embedded in an SVG image used as a logo. Injected content is executed in the context of other users when they view affected pages. Successful exploitation allows the administrative user to perform actions on behalf of the target, including stealing session cookies, user credentials, or sensitive data.

PUBLISHED
Vendor
OPEXUS
Product
FOIAXpress
Provider severity
MEDIUM
Conflicts
1

CVE-2025-61998

OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to inject JavaScript or other content as a URL within the Technical Support Hyperlink Manager. Injected content is executed in the context of other users when they click the malicious link. Successful exploitation allows the administrative user to perform actions on behalf of the target, including stealing session cookies, user credentials, or sensitive data.

PUBLISHED
Vendor
OPEXUS
Product
FOIAXpress
Provider severity
MEDIUM
Conflicts
1

CVE-2025-61997

OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to inject JavaScript or other content within the Annual Report Enterprise Banner image upload field. Injected content is executed in the context of other users when they generate an Annual Report. Successful exploitation allows the administrative user to perform actions on behalf of the target, including stealing session cookies, user credentials, or sensitive data.

PUBLISHED
Vendor
OPEXUS
Product
FOIAXpress
Provider severity
MEDIUM
Conflicts
1

CVE-2025-61996

OPEXUS FOIAXpress before 11.13.3.0 allows an administrative user to inject JavaScript or other content within the Annual Report Template. Injected content is executed in the context of other users when they generate an Annual Report. Successful exploitation allows the administrative user to perform actions on behalf of the target, including stealing session cookies, user credentials, or sensitive data.

PUBLISHED
Vendor
OPEXUS
Product
FOIAXpress
Provider severity
MEDIUM
Conflicts
1