8.1

CVSS3.1

CVE-2025-8855 - 2FA Expiry Bypass in Optimus Software's Brokerage Automation

Authorization Bypass Through User-Controlled Key, Weak Password Recovery Mechanism for Forgotten Password, Authentication Bypass by Assumed-Immutable Data vulnerability in Optimus Software Brokerage Automation allows Exploiting Trust in Client, Authentication Bypass, Manipulate Registry Information…

πŸ“… Published: Nov. 14, 2025, 12:39 p.m. πŸ”„ Last Modified: Nov. 14, 2025, 12:39 p.m.

4.9

CVSS3.1

CVE-2025-11981 - School Management System – WPSchoolPress <= 2.2.23 - Authenticated (Administrator+) SQL Injection

The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'SCodes' parameter in all versions up to, and including, 2.2.23 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This mak…

πŸ“… Published: Nov. 14, 2025, 11:20 a.m. πŸ”„ Last Modified: Nov. 14, 2025, 11:20 a.m.

4.9

CVSS3.1

CVE-2025-11794 - Password hash and MFA secret returned in user email verification endpoint

Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to sanitize user data which allows system administrators to access password hashes and MFA secrets via the POST /api/v4/users/{user_id}/email/verify/member endpoint

πŸ“… Published: Nov. 14, 2025, 10:45 a.m. πŸ”„ Last Modified: Nov. 14, 2025, 10:45 a.m.

5.4

CVSS3.1

CVE-2025-55073 - MS Teams plugin OAuth allows editing arbitrary posts

Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to validate the relationship between the post being updated and the MSTeams plugin OAuth flow which allows an attacker to edit arbitrary posts via a crafted MSTeams plugin OAuth redirect URL.

πŸ“… Published: Nov. 14, 2025, 8:03 a.m. πŸ”„ Last Modified: Nov. 14, 2025, 8:03 a.m.

6.5

CVSS3.1

CVE-2025-55070 - Lack of MFA enforcement in WebSocket connections

Mattermost versions <11 fail to enforce multi-factor authentication on WebSocket connections which allows unauthenticated users to access sensitive information via WebSocket events

πŸ“… Published: Nov. 14, 2025, 8:02 a.m. πŸ”„ Last Modified: Nov. 14, 2025, 8:02 a.m.

3.1

CVSS3.1

CVE-2025-41436 - Unauthorized access to archived channel content via threads interface

Mattermost versions <11.0 fail to properly enforce the "Allow users to view archived channels" setting which allows regular users to access archived channel content and files via the "Open in Channel" functionality from followed threads

πŸ“… Published: Nov. 14, 2025, 8 a.m. πŸ”„ Last Modified: Nov. 14, 2025, 8 a.m.

4.3

CVSS3.1

CVE-2025-11776 - Guest user can discover archived public channels

Mattermost versions <11 fail to properly restrict access to archived channel search API which allows guest users to discover archived public channels via the `/api/v4/teams/{team_id}/channels/search_archived` endpoint

πŸ“… Published: Nov. 14, 2025, 7:58 a.m. πŸ”„ Last Modified: Nov. 14, 2025, 7:58 a.m.

0.0

CVE-2025-10686 - Creta Testimonial Showcase < 1.2.4 - Editor+ Local File Inclusion

The Creta Testimonial Showcase WordPress plugin before 1.2.4 is vulnerable to Local File Inclusion. This makes it possible for authenticated attackers, with editor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files.

πŸ“… Published: Nov. 14, 2025, 6 a.m. πŸ”„ Last Modified: Nov. 14, 2025, 6 a.m.

8.6

CVSS4.0

CVE-2025-64444 -

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in NCP-HG100 1.4.48.16 and earlier. If exploited, a remote attacker who has obtained the authentication information to log in to the management page of the product may execute an arbitrary OS com…

πŸ“… Published: Nov. 14, 2025, 5:15 a.m. πŸ”„ Last Modified: Nov. 14, 2025, 5:15 a.m.

8.7

CVSS4.0

CVE-2025-13161 - IQ Service International|IQ-Support - Arbitrary File Read

IQ-Support developed by IQ Service International has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files.

πŸ“… Published: Nov. 14, 2025, 3:05 a.m. πŸ”„ Last Modified: Nov. 14, 2025, 3:05 a.m.
Total resulsts: 318296
Page 2 of 31,830
Β« previous page Β» next page
Filters