9.8

CVSS3.1

CVE-2025-5397 - Jobmonster - Job Board WordPress Theme <= 4.8.1 - Authentication Bypass

The Noo JobMonster theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.8.1. This is due to the check_login() function not properly verifying a user's identity prior to successfully authenticating them This makes it possible for unauthenticated attacke…

πŸ“… Published: Oct. 31, 2025, 6:42 a.m. πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

5.3

CVSS3.1

CVE-2025-11191 - RealPress < 1.1.0 - Unauthenticated Content Creation/Email Sending via REST

The RealPress WordPress plugin before 1.1.0 registers the REST routes without proper permission checks, allowing the creation of pages and sending of emails from the site.

πŸ“… Published: Oct. 31, 2025, 6 a.m. πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

8.6

CVSS4.0

CVE-2025-54763 -

FutureNet MA and IP-K series provided by Century Systems Co., Ltd. contain an OS command Injection vulnerability. A user who logs in to the Web UI of the product may execute an arbitrary OS command.

πŸ“… Published: Oct. 31, 2025, 5:55 a.m. πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

6.9

CVSS4.0

CVE-2025-58152 -

FutureNet MA and IP-K series provided by Century Systems Co., Ltd. put the firmware version and the garbage collection information on the internal web page. With some crafted HTTP request, they can be accessed without authentication.

πŸ“… Published: Oct. 31, 2025, 5:55 a.m. πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

6.4

CVSS3.1

CVE-2025-11806 - Qzzr Shortcode Plugin <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Short…

The Qzzr Shortcode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qzzr' shortcode in all versions up to, and including, 1.0.1. This is due to insufficient input sanitization and output escaping on the 'quiz' attribute. This makes it possible for authenticated attackers, …

πŸ“… Published: Oct. 31, 2025, 2:26 a.m. πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

4.3

CVSS3.1

CVE-2025-11975 - FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, Act…

The FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_changes() function in all versions up to, and including, 1.1…

πŸ“… Published: Oct. 31, 2025, 2:26 a.m. πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

0.0

CVE-2025-12542 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: Oct. 31, 2025, 12:04 a.m. πŸ”„ Last Modified: Nov. 10, 2025, 10:19 p.m.

7.5

CVSS3.0

CVE-2025-6176 - Brotli decompression bomb DoS in scrapy/scrapy

Scrapy versions up to 2.13.2 are vulnerable to a denial of service (DoS) attack due to a flaw in its brotli decompression implementation. The protection mechanism against decompression bombs fails to mitigate the brotli variant, allowing remote servers to crash clients with less than 80GB of availa…

πŸ“… Published: Oct. 31, 2025, midnight πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

7.5

CVSS3.1

CVE-2025-63467 -

Totolink LR350 v9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the ssid parameter in the sub_425400 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Oct. 31, 2025, midnight πŸ”„ Last Modified: Nov. 5, 2025, 5:30 p.m.

7.5

CVSS3.1

CVE-2025-63460 -

Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the sub_4222E0 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Oct. 31, 2025, midnight πŸ”„ Last Modified: Nov. 5, 2025, 5:30 p.m.
Total resulsts: 318283
Page 181 of 31,829
Β« previous page Β» next page
Filters