Search Results (359753 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-25519 1 Seacms 1 Seacms 2025-03-28 9.8 Critical
Seacms <=13.3 is vulnerable to SQL Injection in admin_zyk.php.
CVE-2025-25520 1 Seacms 1 Seacms 2025-03-28 9.8 Critical
Seacms <13.3 is vulnerable to SQL Injection in admin_pay.php.
CVE-2025-25521 1 Seacms 1 Seacms 2025-03-28 9.8 Critical
Seacms <=13.3 is vulnerable to SQL Injection in admin_type_news.php.
CVE-2025-25792 1 Seacms 1 Seacms 2025-03-28 4.4 Medium
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the isopen parameter at admin_weixin.php.
CVE-2025-25793 1 Seacms 1 Seacms 2025-03-28 5.1 Medium
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_notify.php.
CVE-2025-25794 1 Seacms 1 Seacms 2025-03-28 5.1 Medium
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ping.php.
CVE-2025-25796 1 Seacms 1 Seacms 2025-03-28 5.1 Medium
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_template.php.
CVE-2025-25797 1 Seacms 1 Seacms 2025-03-28 5.1 Medium
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_smtp.php.
CVE-2025-25799 1 Seacms 1 Seacms 2025-03-28 6 Medium
SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe.php.
CVE-2025-25800 1 Seacms 1 Seacms 2025-03-28 5.3 Medium
SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe_file.php.
CVE-2025-25802 1 Seacms 1 Seacms 2025-03-28 5.1 Medium
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ip.php.
CVE-2025-25813 1 Seacms 1 Seacms 2025-03-28 5.1 Medium
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_files.php.
CVE-2021-36871 1 Codecabin 1 Wp Go Maps 2025-03-28 5.5 Medium
Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in WordPress WP Google Maps Pro premium plugin (versions <= 8.1.11). Vulnerable parameters: &wpgmaps_marker_category_name, Value > &attributes[], Name > &attributes[], &icons[], &names[], &description, &link, &title.
CVE-2024-55461 1 Seacms 1 Seacms 2025-03-28 9.8 Critical
SeaCMS <=13.0 is vulnerable to command execution in phome.php via the function Ebak_RepPathFiletext().
CVE-2021-36872 1 Wordpress Popular Posts Project 1 Wordpress Popular Posts 2025-03-28 5.5 Medium
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in WordPress Popular Posts plugin (versions <= 5.3.3). Vulnerable at &widget-wpp[2][post_type].
CVE-2021-36873 1 Webence 1 Iq Block Country 2025-03-28 5.5 Medium
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in WordPress iQ Block Country plugin (versions <= 1.2.11). Vulnerable parameter: &blockcountry_blockmessage.
CVE-2024-42598 1 Seacms 1 Seacms 2025-03-28 6.7 Medium
SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_editplayer.php imposes restrictions on edited files, attackers can still bypass these restrictions and write code, allowing authenticated attackers to exploit the vulnerability to execute arbitrary commands and gain system privileges.
CVE-2021-36878 1 Stylemixthemes 1 Ulisting 2025-03-28 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for attackers to update settings.
CVE-2021-36879 1 Stylemixthemes 1 Ulisting 2025-03-28 9.8 Critical
Unauthenticated Privilege Escalation vulnerability in WordPress uListing plugin (versions <= 2.0.5). Possible if WordPress configuration allows user registration.
CVE-2024-30565 1 Seacms 1 Seacms 2025-03-28 8.8 High
An issue was discovered in SeaCMS version 12.9, allows remote attackers to execute arbitrary code via admin notify.php.