0.0

CVE-2025-68124 -

reserved but not needed

📅 Published: Dec. 15, 2025, 4:48 p.m. 🔄 Last Modified: Feb. 13, 2026, 8:47 p.m.

0.0

CVE-2025-68126 -

reserved but not needed

📅 Published: Dec. 15, 2025, 4:48 p.m. 🔄 Last Modified: Feb. 13, 2026, 8:47 p.m.

0.0

CVE-2025-68125 -

reserved but not needed

📅 Published: Dec. 15, 2025, 4:48 p.m. 🔄 Last Modified: Feb. 13, 2026, 8:47 p.m.

6.4

CVSS3.1

CVE-2025-14387 - LearnPress – WordPress LMS Plugin <= 4.3.1 - Authenticated (Subscriber+) Stored Cross-Site Scriptin…

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above,…

📅 Published: Dec. 15, 2025, 3:30 p.m. 🔄 Last Modified: Dec. 15, 2025, 9:33 p.m.

8.7

CVSS4.0

CVE-2025-13824 - Micro820®, Micro850®, Micro870® – Specialized Fuzzing Vulnerabilities

A security issue exists due to improper handling of malformed CIP packets during fuzzing. The controller enters a hard fault with solid red Fault LED and becomes unresponsive. Upon power cycle, the controller will enter recoverable fault where the MS LED and Fault LED become flashing red and report…

📅 Published: Dec. 15, 2025, 3:20 p.m. 🔄 Last Modified: Dec. 15, 2025, 9:33 p.m.

7.1

CVSS4.0

CVE-2025-13823 - Micro820®, Micro850®, Micro870® – Specialized Fuzzing Vulnerabilities

A security issue was found in the IPv6 stack in the Micro850 and Micro870 controllers when the controllers received multiple malformed packets during fuzzing. The controllers will go into recoverable fault with fault code 0xFE60. To recover the controller, clear the fault.

📅 Published: Dec. 15, 2025, 3:17 p.m. 🔄 Last Modified: Dec. 15, 2025, 9:33 p.m.

6.9

CVSS4.0

CVE-2025-34412 - Convercent Whistleblowing Platform Protection Mechanism Failure Insecure Default Browser & Session …

The Convercent Whistleblowing Platform operated by EQS Group contains a protection mechanism failure in its browser and session handling. By default, affected deployments omit HTTP security headers such as Content-Security-Policy, Referrer-Policy, Permissions-Policy, Cross-Origin-Embedder-Policy, C…

📅 Published: Dec. 15, 2025, 2:44 p.m. 🔄 Last Modified: Dec. 24, 2025, 2:47 p.m.

6.9

CVSS4.0

CVE-2025-34411 - Convercent Whistleblowing Platform Unauthenticated GetLegalEntity Endpoint Enables Customer Enumera…

The Convercent Whistleblowing Platform operated by EQS Group exposes an unauthenticated API endpoint at /GetLegalEntity that returns internal customer legal-entity names based on a supplied searchText fragment. A remote unauthenticated attacker can query the endpoint using common legal-suffix terms…

📅 Published: Dec. 15, 2025, 2:43 p.m. 🔄 Last Modified: Dec. 24, 2025, 2:46 p.m.

8.7

CVSS4.0

CVE-2025-34181 - NetSupport Manager < 14.12.0001 Authenticated Path Traversal Arbitrary File Write RCE

NetSupport Manager < 14.12.0001 contains an arbitrary file write vulnerability in its Connectivity Server/Gateway PUTFILE request handler. An attacker with a valid Gateway Key can supply a crafted filename containing directory traversal sequences to write files to arbitrary locations on the server.…

📅 Published: Dec. 15, 2025, 2:42 p.m. 🔄 Last Modified: Dec. 15, 2025, 9:33 p.m.

8.4

CVSS4.0

CVE-2025-34180 - NetSupport Manager < 14.12.0001 Gateway Key Reversible Encoding Credential Recovery

NetSupport Manager < 14.12.0001 relies on a shared Gateway Key for authentication between Manager/Control, Client, and Connectivity Server components. The key is stored using a reversible encoding scheme. An attacker who obtains access to a deployed client configuration file can decode the stored …

📅 Published: Dec. 15, 2025, 2:41 p.m. 🔄 Last Modified: Dec. 15, 2025, 9:33 p.m.
Total resulsts: 343054
Page 1994 of 34,306
« previous page » next page
Filters