8.7

CVSS4.0

CVE-2025-5491 - Acer ControlCenter - Remote Code Execution

Acer ControlCenter contains Remote Code Execution vulnerability. The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is misconfigured, allowing remote users with low privileges to interact with it and access its features. One s…

📅 Published: June 13, 2025, 1:56 a.m. 🔄 Last Modified: June 13, 2025, 1:56 a.m.

4.3

CVSS3.1

CVE-2025-5928 - WP Sliding Login/Dashboard Panel <= 2.1.1 - Cross-Site Request Forgery to Settings Update

The WP Sliding Login/Dashboard Panel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.1. This is due to missing or incorrect nonce validation on the wp_sliding_panel_user_options() function. This makes it possible for unauthenticated attacke…

📅 Published: June 13, 2025, 1:47 a.m. 🔄 Last Modified: June 13, 2025, 1:47 a.m.

5.3

CVSS3.1

CVE-2025-5938 - Digital Marketing and Agency Templates Addons for Elementor <= 1.1.1 - Cross-Site Request Forgery t…

The Digital Marketing and Agency Templates Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.1. This is due to missing or incorrect nonce validation on the import_templates() function. This makes it possible for unauthent…

📅 Published: June 13, 2025, 1:47 a.m. 🔄 Last Modified: June 13, 2025, 1:47 a.m.

6.4

CVSS3.1

CVE-2025-5123 - Contact Us Page – Contact People <= 3.7.4 - Authenticated (Contributor+) Stored Cross-Site Scriptin…

The Contact Us Page – Contact People plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ parameter in all versions up to, and including, 3.7.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contribut…

📅 Published: June 13, 2025, 1:47 a.m. 🔄 Last Modified: June 13, 2025, 1:47 a.m.

4.4

CVSS3.1

CVE-2025-5939 - Telegram for WP <= 1.6.1 - Authenticated (Admin+) Stored Cross-Site Scripting

The Telegram for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions a…

📅 Published: June 13, 2025, 1:47 a.m. 🔄 Last Modified: June 13, 2025, 1:47 a.m.
Load More Vulnerability
avatar

Mehmet Ince

@mdisec

CVE stats coming here

avatar

Nuri Çilengir

@ncilengir

CVE stats coming here

avatar

@aydinnyunus

CVE stats coming here

avatar

Seyit Sigirci

@h3xecute

CVE stats coming here

avatar

Ali İltizar

@iltosec

CVE stats coming here

avatar

@b3rsec

CVE stats coming here

avatar

Nicat Abbasov

@scan9

CVE stats coming here

avatar

Mücahit İç

@mucahic

CVE stats coming here

avatar

@arslan

CVE stats coming here