8.8

CVSS3.1

CVE-2025-15270 - FontForge SFD File Parsing Improper Validation of Array Index Remote Code Execution Vulnerability

FontForge SFD File Parsing Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FontForge. User interaction is required to exploit this vulnerability in that the target must visit a …

πŸ“… Published: Dec. 31, 2025, 6:58 a.m. πŸ”„ Last Modified: Jan. 7, 2026, 4:11 p.m.

8.8

CVSS3.1

CVE-2025-15269 - FontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerability

FontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FontForge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or op…

πŸ“… Published: Dec. 31, 2025, 6:58 a.m. πŸ”„ Last Modified: Jan. 7, 2026, 4:12 p.m.

4.3

CVSS3.1

CVE-2025-14783 - Easy Digital Downloads <= 3.6.2 - Unvalidated Redirect in Password Reset Flow via edd_redirect

The Easy Digital Downloads plugin for WordPress is vulnerable to Unvalidated Redirect in all versions up to, and including, 3.6.2. This is due to insufficient validation on the redirect url supplied via the 'edd_redirect' parameter. This makes it possible for unauthenticated attackers to redirect u…

πŸ“… Published: Dec. 31, 2025, 6:24 a.m. πŸ”„ Last Modified: April 8, 2026, 4:47 p.m.

5.3

CVSS3.1

CVE-2025-14434 - Ultimate Post Kit < 4.0.16 – Unauthenticated Arbitrary Post Content Disclosure

The Ultimate Post Kit Addons for Elementor WordPress plugin before 4.0.16 exposes multiple AJAX β€œload more” endpoints such as upk_alex_grid_loadmore_posts without ensuring that posts to be displayed are published authentication. This allows an unauthenticated attacker to query arbitrary posts and r…

πŸ“… Published: Dec. 31, 2025, 6 a.m. πŸ”„ Last Modified: Jan. 5, 2026, 10:17 a.m.

7.5

CVSS3.1

CVE-2025-13029 - Knowband Mobile App Builder for wooCommerce < 3.0.0 – Unauthenticated Arbitrary User Deletion

The Knowband Mobile App Builder WordPress plugin before 3.0.0 does not have authorisation when deleting users via its REST API, allowing unauthenticated attackers to delete arbitrary users.

πŸ“… Published: Dec. 31, 2025, 6 a.m. πŸ”„ Last Modified: Jan. 5, 2026, 10:18 a.m.

0.0

CVE-2025-49342 - WordPress Custom Style plugin <= 1.0 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in merzedes Custom Style custom-style allows Stored XSS.This issue affects Custom Style: from n/a through <= 1.0.

πŸ“… Published: Dec. 31, 2025, 5:55 a.m. πŸ”„ Last Modified: April 1, 2026, 5:25 p.m.

4.5

CVSS3.1

CVE-2025-69277 - libsodium: libsodium: Improper validation of elliptic curve points could lead to data integrity or …

libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group.

πŸ“… Published: Dec. 31, 2025, 5:50 a.m. πŸ”„ Last Modified: Jan. 7, 2026, 5:16 p.m.

0.0

CVE-2025-49353 - WordPress Noindex by Path plugin <= 1.0 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Marcin Kijak Noindex by Path noindex-by-path allows Stored XSS.This issue affects Noindex by Path: from n/a through <= 1.0.

πŸ“… Published: Dec. 31, 2025, 5:36 a.m. πŸ”„ Last Modified: April 1, 2026, 5:25 p.m.

0.0

CVE-2025-68885 - WordPress Custom Post Status plugin <= 1.1.0 - Cross Site Request Forgery (CSRF) to Stored XSS vuln…

Cross-Site Request Forgery (CSRF) vulnerability in page-carbajal Custom Post Status custom-post-status allows Stored XSS.This issue affects Custom Post Status: from n/a through <= 1.1.0.

πŸ“… Published: Dec. 31, 2025, 5:34 a.m. πŸ”„ Last Modified: April 1, 2026, 5:28 p.m.

0.0

CVE-2025-49354 - WordPress Recent Posts From Each Category plugin <= 1.4 - Cross Site Request Forgery (CSRF) vulnera…

Cross-Site Request Forgery (CSRF) vulnerability in Mindstien Technologies Recent Posts From Each Category recent-posts-from-each-category allows Stored XSS.This issue affects Recent Posts From Each Category: from n/a through <= 1.4.

πŸ“… Published: Dec. 31, 2025, 5:30 a.m. πŸ”„ Last Modified: April 1, 2026, 5:25 p.m.
Total resulsts: 343923
Page 1810 of 34,393
Β« previous page Β» next page
Filters