Search Results (328890 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-2893 1 Jegstudio 1 Gutenverse 2025-05-06 6.4 Medium
The Gutenverse – Ultimate Block Addons and Page Builder for Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's countdown Block in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2024-27984 1 Ivanti 1 Avalanche 2025-05-06 7.1 High
A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to delete specific type of files and/or cause denial of service.
CVE-2025-1458 1 Bdthemes 1 Element Pack 2025-05-06 6.4 Medium
The Element Pack Addons for Elementor – Free Templates and Widgets for Your WordPress Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets like Dual Button, Creative Button, Image Stack and more in all versions up to, and including, 5.10.29 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2025-2575 1 Wpzita 1 Z Companion 2025-05-06 6.4 Medium
The Z Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file. Note: This requires Royal Shop theme to be installed.
CVE-2025-2541 1 Wedevs 1 Wp Project Manager 2025-05-06 6.4 Medium
The WP Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.22 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.
CVE-2024-2027 1 Devowl 1 Real Media Library 2025-05-06 6.4 Medium
The Real Media Library: Media Library Folder & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its style attributes in all versions up to, and including, 4.22.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2023-52342 2 Google, Unisoc 9 Android, S8000, S8000 Firmware and 6 more 2025-05-06 7.5 High
In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no additional execution privileges needed
CVE-2023-52343 2 Google, Unisoc 5 Android, S8000, T760 and 2 more 2025-05-06 5.5 Medium
In SecurityCommand message after as security has been actived., there is a possible improper input validation. This could lead to remote information disclosure no additional execution privileges needed
CVE-2023-52344 2 Google, Unisoc 5 Android, S8000, T760 and 2 more 2025-05-06 5.3 Medium
In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no additional execution privileges needed
CVE-2023-52346 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-05-06 4.4 Medium
In modem driver, there is a possible system crash due to improper input validation. This could lead to local information disclosure with System execution privileges needed
CVE-2023-52347 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-05-06 5.5 Medium
In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
CVE-2023-52348 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-05-06 4.4 Medium
In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
CVE-2023-52351 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-05-06 7.8 High
In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
CVE-2023-52533 2 Google, Unisoc 5 Android, S8000, T760 and 2 more 2025-05-06 5.3 Medium
In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no additional execution privileges needed
CVE-2023-52534 2 Google, Unisoc 5 Android, S8000, T760 and 2 more 2025-05-06 5.9 Medium
In ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote denial of service with no additional execution privileges needed
CVE-2023-52535 2 Google, Unisoc 7 Android, Sc7731e, Sc9832e and 4 more 2025-05-06 4.4 Medium
In vsp driver, there is a possible missing verification incorrect input. This could lead to local denial of service with no additional execution privileges needed
CVE-2024-23658 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-05-06 4.4 Medium
In camera driver, there is a possible use after free due to a logic error. This could lead to local denial of service with System execution privileges needed
CVE-2024-39441 2 Google, Unisoc 13 Android, S8000, T310 and 10 more 2025-05-06 7.1 High
In wifi display, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed.
CVE-2023-52341 2 Google, Unisoc 5 Android, S8000, T760 and 2 more 2025-05-06 7.5 High
In Plaintext COUNTER CHECK message accepted before AS security activation, there is a possible missing permission check. This could lead to remote information disclosure no additional execution privileges needed
CVE-2024-42789 2 Kashipara, Lopalopa 2 Music Management System, Music Management System 2025-05-06 6.3 Medium
A Reflected Cross Site Scripting (XSS) vulnerability was found in "/music/controller.php?page=test" in Kashipara Music Management System v1.0. This vulnerability allows remote attackers to execute arbitrary code via the "page" parameter.