CVE & Security Advisory Details
Dokploy Platform
CVE-2025-53376
HIGHOS Command Injection
A critical OS command injection vulnerability was discovered in Dokploy that allows attackers to execute arbitrary system commands.
CVE-2025-53375
HIGHLocal File Inclusion
A local file inclusion vulnerability in Dokploy allows unauthorized access to sensitive files on the server.
CVE-2025-53374
MEDIUMInformation Disclosure
An information disclosure vulnerability in Dokploy exposes sensitive configuration and system information.
Cisco BroadWorks
CVE-2025-20307
MEDIUMCisco BroadWorks Application Delivery Platform Cross-Site Scripting Vulnerability
A cross-site scripting (XSS) vulnerability in Cisco BroadWorks Application Delivery Platform could allow an attacker to execute arbitrary JavaScript code.
pfSense Security Advisories
pfSense-SA-25_07.webgui
HIGHStored XSS in Wake on LAN pages and Dashboard widget
A stored cross-site scripting vulnerability was discovered in pfSense's Wake on LAN pages and Dashboard widget.
pfSense-SA-25_06.webgui
HIGHStored XSS in IPsec Phase 1
A stored cross-site scripting vulnerability exists in the IPsec Phase 1 configuration of pfSense.
pfSense-SA-25_05.webgui
HIGHStored XSS in Firewall Schedules
A stored cross-site scripting vulnerability was identified in pfSense Firewall Schedules configuration.
OpenZiti
CVE-2025-27500
CRITICALUnauthenticated Stored XSS on admin panel
An unauthenticated stored cross-site scripting vulnerability in OpenZiti's admin panel allows remote attackers to execute arbitrary JavaScript.
CVE-2025-27501
CRITICALUnauthenticated SSRF on admin panel
An unauthenticated server-side request forgery (SSRF) vulnerability in OpenZiti's admin panel enables attackers to access internal resources.
WordPress Plugin Vulnerabilities
CVE-2023-4691
CRITICALBookly <= 22.3.1 - Authenticated (Administrator+) SQL Injection
An authenticated SQL injection vulnerability in Bookly plugin versions up to 22.3.1 allows administrators to execute arbitrary SQL queries.
CVE-2023-4620
CRITICALBooking Calendar <= 9.7.3 - Unauthenticated Stored Cross-Site Scripting
An unauthenticated stored XSS vulnerability in Booking Calendar plugin allows attackers to inject malicious scripts.
CVE-2023-4490
CRITICALWP Job Portal <= 2.0.5 - Unauthenticated SQL Injection
An unauthenticated SQL injection vulnerability in WP Job Portal allows remote attackers to extract sensitive database information.
CVE-2023-4502
HIGHGTranslate <= 3.0.3 - Authenticated (Administrator+) Cross-Site Scripting via Multiple Parameters
Multiple authenticated XSS vulnerabilities in GTranslate plugin allow administrators to inject malicious scripts.
CVE-2023-1465
MEDIUMWP EasyPay <= 4.0.4 - Reflected Cross-Site Scripting
A reflected XSS vulnerability in WP EasyPay plugin allows attackers to execute JavaScript in user browsers.
CVE-2023-1546
MEDIUMMyCryptoCheckout <= 2.123 - Reflected Cross-Site Scripting via URL
A reflected XSS vulnerability via URL parameters in MyCryptoCheckout plugin enables script injection attacks.
CVE-2023-1554
HIGHQuick Paypal Payments <= 5.7.26.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
An authenticated stored XSS vulnerability in Quick Paypal Payments plugin allows administrators to persistently inject malicious scripts.