5.3

CVSS3.1

CVE-2025-12898 - Pretty Google Calendar <= 2.0.0 - Missing Authorization to Unauthenticated Google API Key Exposure

The Pretty Google Calendar plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the pgcal_ajax_handler() function in all versions up to, and including, 2.0.0. This makes it possible for unauthenticated attackers to retrieve the Google API key set in…

📅 Published: Dec. 20, 2025, 3:20 a.m. 🔄 Last Modified: Dec. 23, 2025, 2:51 p.m.

5.4

CVSS3.1

CVE-2025-14734 - Amazon affiliate lite Plugin <= 1.0.0 - Cross-Site Request Forgery to Plugin Settings Update

The Amazon affiliate lite Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on the 'ADAL_settings_page' function. This makes it possible for unauthenticated attackers to update pl…

📅 Published: Dec. 20, 2025, 3:20 a.m. 🔄 Last Modified: Dec. 23, 2025, 2:51 p.m.

4.3

CVSS3.1

CVE-2025-14164 - Quran Gateway <= 1.5 - Cross-Site Request Forgery to Settings Update

The Quran Gateway plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missing nonce validation in the quran_gateway_options function. This makes it possible for unauthenticated attackers to modify the plugin's display settings v…

📅 Published: Dec. 20, 2025, 3:20 a.m. 🔄 Last Modified: Dec. 23, 2025, 2:51 p.m.

4.4

CVSS3.1

CVE-2025-14735 - Amazon affiliate lite Plugin <= 1.0.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

The "Amazon affiliate lite Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-leve…

📅 Published: Dec. 20, 2025, 3:20 a.m. 🔄 Last Modified: Dec. 23, 2025, 2:51 p.m.

5.3

CVSS4.0

CVE-2025-14591 - PII Leak Due to Change in EOR Handling

In Delphix Continuous Compliance version 2025.3.0 and later, following a recent bug fix to correctly handle CR+LF (Windows and DOS) End-of-Record (EOR) characters in delimited files, an issue was identified: using an incorrect EOR configuration can cause inaccurate parsing and leave personally iden…

📅 Published: Dec. 20, 2025, 3:04 a.m. 🔄 Last Modified: Jan. 5, 2026, 5:58 p.m.

8.7

CVSS4.0

CVE-2025-14300 - Unauthenticated Access to connectAP API Endpoint on Tapo C100 and C200

The HTTPS service on Tapo C200 V3 exposes a connectAP interface without proper authentication. An unauthenticated attacker on the same local network segment can exploit this to modify the device’s Wi-Fi configuration, resulting in loss of connectivity and denial-of-service (DoS).

📅 Published: Dec. 20, 2025, 12:43 a.m. 🔄 Last Modified: April 3, 2026, 10:16 p.m.

7.1

CVSS4.0

CVE-2025-14299 - Improper Content-Length Validation in HTTPS Requests on Tapo C200

The HTTPS server on Tapo C200 V3 does not properly validate the Content-Length header, which can lead to an integer overflow. An unauthenticated attacker on the same local network segment can send crafted HTTPS requests to trigger excessive memory allocation, causing the device to crash and resulti…

📅 Published: Dec. 20, 2025, 12:42 a.m. 🔄 Last Modified: Jan. 8, 2026, 7:38 p.m.

8.7

CVSS4.0

CVE-2025-8065 - Remote Code Execution via Stack-based Buffer Overflow in ONVIF SOAP Parser in TP-Link Tapo C200 and…

A stack-based buffer overflow vulnerability was identified in the ONVIF SOAP XML Parser in Tapo C200 v3 and C520WS v2.6. When processing XML tags with namespace prefixes, the parser fails to validate the prefix length before copying it to a fixed-size stack buffer. It allowed a crafted SOAP reques…

📅 Published: Dec. 20, 2025, 12:41 a.m. 🔄 Last Modified: April 3, 2026, 5:16 p.m.

10

CVSS3.1

CVE-2025-68613 - n8n Vulnerable to Remote Code Execution via Expression Injection

n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnerability in their workflow expression evaluation system. Under certain conditions, expressions supplied by authenticated …

📅 Published: Dec. 19, 2025, 10:23 p.m. 🔄 Last Modified: March 12, 2026, 3:55 a.m.

5.1

CVSS4.0

CVE-2023-53953 - WebsiteBaker 2.13.3 Stored Cross-Site Scripting via Page Creation

WebsiteBaker 2.13.3 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts when creating web pages. Attackers can craft malicious payloads in page titles that execute arbitrary JavaScript when the page is viewed by other users.

📅 Published: Dec. 19, 2025, 9:07 p.m. 🔄 Last Modified: March 5, 2026, 12:03 p.m.
Total resulsts: 342654
Page 1839 of 34,266
« previous page » next page
Filters