5.1

CVSS4.0

CVE-2025-67859 - Polkit Authorization Check can be Bypassed in the TLP power daemon

A Improper Authentication vulnerability in TLP allows local users to arbitrarily control the power profile in use as well as the daemon’s log settings.This issue affects TLP: from 1.9 before 1.9.1.

📅 Published: Jan. 14, 2026, 11:34 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.9

CVSS3.1

CVE-2025-0647 -

In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidation when a TLBI is issued to the PE, either by the same PE or another PE in the shareability domain. In this case, the PE may retain stale TLB entries which should have been invalidated by t…

📅 Published: Jan. 14, 2026, 10:58 a.m. 🔄 Last Modified: Jan. 26, 2026, 7:40 p.m.

8.6

CVSS3.1

CVE-2026-0532 - External Control of File Name or Path and Server-Side Request Forgery (SSRF) in Kibana Google Gemin…

External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918) can allow an attacker to cause arbitrary file disclosure through a specially crafted credentials JSON payload in the Google Gemini connector configuration. This requires an attacker to have authentica…

📅 Published: Jan. 14, 2026, 10:14 a.m. 🔄 Last Modified: April 18, 2026, 6:30 a.m.

6.5

CVSS3.1

CVE-2026-0529 - Improper Validation of Array Index in Packetbeat Leading to Overflow Buffers

Improper Validation of Array Index (CWE-129) in Packetbeat’s MongoDB protocol parser can allow an attacker to cause Overflow Buffers (CAPEC-100) through specially crafted network traffic. This requires an attacker to send a malformed payload to a monitored network interface where MongoDB protocol p…

📅 Published: Jan. 14, 2026, 10:09 a.m. 🔄 Last Modified: April 18, 2026, 6:30 a.m.

0.0

CVE-2026-23550 - WordPress Modular DS plugin <= 2.5.1 - Privilege Escalation vulnerability

Incorrect Privilege Assignment vulnerability in Modular DS Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from n/a through <= 2.5.1.

📅 Published: Jan. 14, 2026, 8:44 a.m. 🔄 Last Modified: April 16, 2026, 6:15 p.m.

5.3

CVSS3.1

CVE-2025-15475 - PayHere Payment Gateway Plugin for WooCommerce <= 2.3.9 - Missing Authorization to Unauthenticated …

The PayHere Payment Gateway Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to an improper validation logic in the check_payhere_response function in all versions up to, and including, 2.3.9. This makes it possible for unauthenticated attackers to …

📅 Published: Jan. 14, 2026, 6:40 a.m. 🔄 Last Modified: April 20, 2026, 9:15 p.m.

4.3

CVSS3.1

CVE-2025-15376 - Stopwords for comments <= 1.1 - Missing Authorization to Cross-Site Request Forgery

The Stopwords for comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing nonce validation on the 'set_stopwords_for_comments' and 'delete_stopwords_for_comments' functions. This makes it possible for unauthenticate…

📅 Published: Jan. 14, 2026, 6:40 a.m. 🔄 Last Modified: April 21, 2026, 12:30 a.m.

5.3

CVSS3.1

CVE-2025-14173 - Perfit WooCommerce <= 1.0.1 - Missing Authorization to Unauthenticated Arbitrary Plugin Settings De…

The Perfit WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.1. This is due to missing authorization checks on the `logout` function called via the `actions` function hooked to `admin_init`. This makes it possible for unauthenticated a…

📅 Published: Jan. 14, 2026, 6:40 a.m. 🔄 Last Modified: April 21, 2026, 12:30 a.m.

4.3

CVSS3.1

CVE-2025-14846 - SocialChamp with WordPress <= 1.3.5 - Cross-Site Request Forgery to Plugin Settings Update

The SocialChamp with WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.5. This is due to missing nonce validation on the wpsc_settings_tab_menu function. This makes it possible for unauthenticated attackers to modify plugin settings…

📅 Published: Jan. 14, 2026, 6:40 a.m. 🔄 Last Modified: April 21, 2026, 12:30 a.m.

5.3

CVSS3.1

CVE-2025-15513 - Float Payment Gateway <= 1.1.9 - Improper Authorization to Unauthenticated Order Status Manipulation

The Float Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to improper error handling in the verifyFloatResponse() function in all versions up to, and including, 1.1.9. This makes it possible for unauthenticated attackers to mark any WooCommerce order as f…

📅 Published: Jan. 14, 2026, 6:40 a.m. 🔄 Last Modified: April 20, 2026, 9:15 p.m.
Total resulsts: 345362
Page 1751 of 34,537
« previous page » next page
Filters