Medium - CVE-2025-1802 - The HT Mega – Absolute Addons For Elementor...
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘marker_title’, 'notification_content', and...
NA - CVE-2025-27888 - Severity: medium (5.8) / important
Server-Side...
Severity: medium (5.8) / important Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), URL Redirection to Untrusted...
NA - CVE-2025-2311 - Incorrect Use of Privileged APIs, Cleartext...
Incorrect Use of Privileged APIs, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in Sechard Information Technologies SecHard allows...
High - CVE-2025-2539 - The File Away plugin for WordPress is...
The File Away plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax() function in all versions up to, and including, 3.9.9.0.1. This makes...
NA - CVE-2024-48590 - Inflectra SpiraTeam 7.2.00 is vulnerable to...
Inflectra SpiraTeam 7.2.00 is vulnerable to Server-Side Request Forgery (SSRF) via the NewsReaderService. This allows an attacker to escalate privileges and obtain sensitive information.
NA - CVE-2025-0254 - HCL Digital Experience components Ring API and...
HCL Digital Experience components Ring API and dxclient may be vulnerable to man-in-the-middle (MitM) attacks prior to 9.5 CF226. An attacker could intercept and potentially alter communication...
NA - CVE-2025-29410 - A cross-site scripting (XSS) vulnerability in...
A cross-site scripting (XSS) vulnerability in the component /contact.php of Hospital Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload...
NA - CVE-2025-29412 - A cross-site scripting (XSS) vulnerability in...
A cross-site scripting (XSS) vulnerability in the Client Profile Update section of Mart Developers iBanking v2.0.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted...