CVE ID | Publié | Description | Score | Gravité | |
---|---|---|---|---|---|
CVE-2025-2905 |
2025-05-05 09h02 +00:00 |
An XML External Entity (XXE) vulnerability exists in the gateway component of WSO2 API Manager due t... |
9.1 |
Critique |
|
CVE-2025-3918 |
2025-05-03 01h43 +00:00 |
The Job Listings plugin for WordPress is vulnerable to Privilege Escalation due to improper authoriz... |
9.8 |
Critique |
|
CVE-2025-0782 |
2025-05-02 20h11 +00:00 |
A vulnerability in the S3 bucket configuration for h2oai/h2o-3 allows public write access to the 'h2... Authorization problems |
10 |
Critique |
|
CVE-2025-2605 |
2025-05-02 12h39 +00:00 |
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerabi... OS Command Injection |
9.9 |
Critique |
|
CVE-2025-2421 |
2025-05-02 11h27 +00:00 |
Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Informatics Samb... Code Injection |
8.2 |
Haute |
|
CVE-2025-2812 |
2025-05-02 08h24 +00:00 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i... SQL Injection |
9.8 |
Critique |
|
CVE-2024-13418 |
2025-05-02 03h21 +00:00 |
Multiple plugins and/or themes for WordPress are vulnerable to Arbitrary File Uploads due to a missi... File Inclusion |
8.8 |
Haute |
|
CVE-2025-3708 |
2025-05-02 02h55 +00:00 |
Le-show medical practice management system from Le-yan has a SQL Injection vulnerability, allowing u... SQL Injection |
9.8 |
Critique |
|
CVE-2025-3709 |
2025-05-02 03h13 +00:00 |
Agentflow from Flowring Technology has an Account Lockout Bypass vulnerability, allowing unauthentic... |
9.8 |
Critique |
|
CVE-2025-3746 |
2025-05-02 01h43 +00:00 |
The OTP-less one tap Sign in plugin for WordPress is vulnerable to privilege escalation via account ... Authorization problems |
9.8 |
Critique |