5.4

CVSS4.0

CVE-2025-14605 - Quartus Prime Pro Edition Advisory

Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Pro on Windows (System Console modules) allows Search Order Hijacking.This issue affects Quartus Prime Pro: from 17.0 through 25.1.1.

πŸ“… Published: Jan. 6, 2026, 9:15 p.m. πŸ”„ Last Modified: Jan. 12, 2026, 3:16 p.m.

7.1

CVSS3.1

CVE-2025-31642 - WordPress WPCHURCH plugin <= 2.7.0 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dasinfomedia WPCHURCH church-management allows Reflected XSS.This issue affects WPCHURCH: from n/a through <= 2.7.0.

πŸ“… Published: Jan. 6, 2026, 9:14 p.m. πŸ”„ Last Modified: April 23, 2026, 3:28 p.m.

5.3

CVSS3.1

CVE-2025-31051 - WordPress Plant - Gardening & Houseplants WordPress Theme <= 1.0.0 - Sensitive Data Exposure Vulner…

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in EngoTheme Plant - Gardening & Houseplants WordPress Theme plant allows Retrieve Embedded Sensitive Data.This issue affects Plant - Gardening & Houseplants WordPress Theme: from n/a through <= 1.0.0.

πŸ“… Published: Jan. 6, 2026, 9:13 p.m. πŸ”„ Last Modified: April 23, 2026, 3:27 p.m.

5.4

CVSS4.0

CVE-2025-14596 - Quartus Prime Pro Edition Installer Advisory

Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Pro Installer (SFX) on Windows allows Search Order Hijacking.This issue affects Quartus Prime Pro: from 24.1 through 24.3.1.

πŸ“… Published: Jan. 6, 2026, 9:06 p.m. πŸ”„ Last Modified: Jan. 12, 2026, 3:16 p.m.

9.9

CVSS3.1

CVE-2025-30996 - WordPress Themify Newsy <= 1.9.9 - Arbitrary File Upload Vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Newsy newsy allows Upload a Web Shell to a Web Server.This issue affects Themify Newsy: from n/a through <= 1.9.9.

πŸ“… Published: Jan. 6, 2026, 8:56 p.m. πŸ”„ Last Modified: April 23, 2026, 3:27 p.m.

8.4

CVSS4.0

CVE-2025-13744 - Improper Neutralization of Input During Web Page Generation vulnerability was identified in GitHub …

An Improper Neutralization of Input During Web Page Generation vulnerability was identified in GitHub Enterprise Server that allowed attacker controlled HTML to be rendered by the Filter component (search) across GitHub that could be used to exfiltrate sensitive information. An attacker would requi…

πŸ“… Published: Jan. 6, 2026, 8:44 p.m. πŸ”„ Last Modified: Jan. 30, 2026, 4:51 p.m.

7.1

CVSS3.1

CVE-2025-30631 - WordPress Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer) <= 1.2 - Cro…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA-Team Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer) azon-addon-js-composer allows Reflected XSS.This issue affects Amazon Affiliates Addon for WPBakery Page Builder…

πŸ“… Published: Jan. 6, 2026, 8:30 p.m. πŸ”„ Last Modified: April 23, 2026, 3:27 p.m.

8.8

CVSS3.1

CVE-2025-29004 - WordPress Responsive Coming Soon Landing Page / Holding Page for WordPress plugin <= 3.0 - Privileg…

Incorrect Privilege Assignment vulnerability in AA-Team Responsive Coming Soon Landing Page / Holding Page for WordPress wordpress-flat-countdown allows Privilege Escalation.This issue affects Responsive Coming Soon Landing Page / Holding Page for WordPress: from n/a through <= 3.0.

πŸ“… Published: Jan. 6, 2026, 8:25 p.m. πŸ”„ Last Modified: April 23, 2026, 3:26 p.m.

5.5

CVSS3.1

CVE-2026-21492 - iccDEV ToneMap Writer has NULL Pointer Member Call

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a NULL pointer member call vulnerability. This vulnerability affects users of the iccDEV libra…

πŸ“… Published: Jan. 6, 2026, 8:23 p.m. πŸ”„ Last Modified: April 18, 2026, 8:15 a.m.

5.3

CVSS4.0

CVE-2025-7048 - On affected platforms running Arista EOS with MACsec configuration, a specially crafted packet can …

On affected platforms running Arista EOS with MACsec configuration, a specially crafted packet can cause the MACsec process to terminate unexpectedly. Continuous receipt of these packets with certain MACsec configurations can cause longer term disruption of dataplane traffic.

πŸ“… Published: Jan. 6, 2026, 7:15 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346120
Page 1960 of 34,612
Β« previous page Β» next page
Filters