7.8

CVSS3.1

CVE-2025-66494 - Foxit PDF Reader PDF File Parsing Use-After-Free Remote Code Execution Vulnerability

A use-after-free vulnerability exists in the PDF file parsing of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1 on Windows. A PDF object managed by multiple parent objects could be freed while still being referenced, potentially allowing a remote attacker to execute arbitrary code.

πŸ“… Published: Dec. 19, 2025, 7:08 a.m. πŸ”„ Last Modified: Dec. 23, 2025, 5:36 p.m.

7.8

CVSS3.1

CVE-2025-66493 - Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability

A use-after-free vulnerability exists in the AcroForm handling of Foxit PDF Reader and Foxit PDF Editor before 2025.2.1,14.0.1 and 13.2.1 on Windows . When opening a PDF containing specially crafted JavaScript, a pointer to memory that has already been freed may be accessed or dereferenced, pote…

πŸ“… Published: Dec. 19, 2025, 7:07 a.m. πŸ”„ Last Modified: Dec. 23, 2025, 5:36 p.m.

8.6

CVSS4.0

CVE-2025-13008 - Session Token Disclosure in M-Files Web

An information disclosure vulnerability in M-Files Server before versions 25.12.15491.7, 25.8 LTS SR3, 25.2 LTS SR3 and 24.8 LTS SR5 allows an authenticated attacker using M-Files Web to capture session tokens of other active users.

πŸ“… Published: Dec. 19, 2025, 7:04 a.m. πŸ”„ Last Modified: Feb. 23, 2026, 11:16 a.m.

7.2

CVSS3.1

CVE-2025-13999 - HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player 2.4.0 - 2.5.1 - Unauthenticat…

The HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions from 2.4.0 up to, and including, 2.5.1 via the getIcyMetadata() function. This makes it possible for unauthenticated attackers to make web requ…

πŸ“… Published: Dec. 19, 2025, 6:48 a.m. πŸ”„ Last Modified: Dec. 21, 2025, 9:13 p.m.

6.4

CVSS3.1

CVE-2025-14449 - BA Book Everything <= 1.8.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via babe-se…

The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's babe-search-form shortcode in all versions up to, and including, 1.8.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authen…

πŸ“… Published: Dec. 19, 2025, 6:48 a.m. πŸ”„ Last Modified: Dec. 21, 2025, 9:13 p.m.

5.3

CVSS3.1

CVE-2025-13754 - Appointment Booking Calendar β€” Simply Schedule Appointments Booking Plugin <= 1.6.9.16 - Missing Au…

The Appointment Booking Calendar β€” Simply Schedule Appointments Booking Plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.9.16. This is due to the plugin exposing its admin embed endpoint at `/wp-json/ssa/v1/embed-inner-admin` without aut…

πŸ“… Published: Dec. 19, 2025, 6:48 a.m. πŸ”„ Last Modified: Dec. 21, 2025, 9:13 p.m.

6.5

CVSS3.1

CVE-2025-66174 -

There is an improper authentication vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for the serial port, an attacker with physical access could exploit this vulnerability by connecting to the affected products and run a series of commands.

πŸ“… Published: Dec. 19, 2025, 6:39 a.m. πŸ”„ Last Modified: Dec. 23, 2025, 9:45 p.m.

6.2

CVSS3.1

CVE-2025-66173 -

There is a privilege escalation vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for the serial port, an attacker with physical access could exploit this vulnerability by connecting to the affected products and gaining access to an unrestricted shel…

πŸ“… Published: Dec. 19, 2025, 6:39 a.m. πŸ”„ Last Modified: Dec. 23, 2025, 9:45 p.m.

5.6

CVSS4.0

CVE-2025-14267 - Unintended temporary cached data included in a structure only copy intended to be empty of data

Incomplete removal of sensitive information before transfer vulnerability in M-Files Corporation M-Files Server allows data leak exposure affecting versions before 25.12.15491.7

πŸ“… Published: Dec. 19, 2025, 6:15 a.m. πŸ”„ Last Modified: Feb. 23, 2026, 11:16 a.m.

7.2

CVSS3.1

CVE-2025-13307 - Ocean Modal Window < 2.3.3 - Editor+ Remote Code Execution via Modal Conditions

The Ocean Modal Window WordPress plugin before 2.3.3 is vulnerable to Remote Code Execution via the modal display logic. These modals can be displayed under user-controlled conditions that Editors and Administrators can set (edit_pages capability). The conditions are then executed as part of an eva…

πŸ“… Published: Dec. 19, 2025, 6 a.m. πŸ”„ Last Modified: Dec. 21, 2025, 9:14 p.m.
Total resulsts: 343183
Page 1900 of 34,319
Β« previous page Β» next page
Filters