4.3

CVSS3.1

CVE-2025-12022 - ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.1 - Missing Authorization to Authenticat…

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'eh_crm_settings_restore_trash' AJAX endpoint in all versions up to, and including, 3.3.1. This makes it possible for authenticate…

📅 Published: Nov. 21, 2025, 5:32 a.m. 🔄 Last Modified: Nov. 21, 2025, 2:58 p.m.

4.3

CVSS3.1

CVE-2025-12085 - ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.1 - Missing Authorization to Authenticat…

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'eh_crm_settings_empty_trash' function in all versions up to, and including, 3.3.1. This makes it possible for authenticated attac…

📅 Published: Nov. 21, 2025, 5:32 a.m. 🔄 Last Modified: Nov. 21, 2025, 2:58 p.m.

4.3

CVSS3.1

CVE-2025-12023 - ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.1 - Missing Authorization to Authenticat…

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the eh_crm_restore_data() function in all versions up to, and including, 3.3.1. This makes it possible for authenticated attackers, wi…

📅 Published: Nov. 21, 2025, 5:32 a.m. 🔄 Last Modified: Nov. 21, 2025, 2:58 p.m.

5.3

CVSS3.1

CVE-2025-11368 - LearnPress – WordPress LMS Plugin <= 4.2.9.4 - Missing Authorization to Unauthenticated Arbitrary C…

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 4.2.9.4. This is due to missing capability checks in the REST endpoint /wp-json/lp/v1/load_content_via_ajax which allows arbitrary callback execution of…

📅 Published: Nov. 21, 2025, 5:32 a.m. 🔄 Last Modified: Nov. 21, 2025, 2:58 p.m.

9.3

CVSS4.0

CVE-2025-64310 -

EPSON WebConfig and Epson Web Control for SEIKO EPSON Projector Products do not restrict excessive authentication attempts. An administrative user's password may be identified through a brute force attack.

📅 Published: Nov. 21, 2025, 2:36 a.m. 🔄 Last Modified: Nov. 21, 2025, 2:58 p.m.

8

CVSS4.0

CVE-2025-64762 - authkit-nextjs may let session cookies be cached in CDNs

The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & AuthKit with Next.js. In authkit-nextjs version 2.11.0 and below, authenticated responses do not defensively apply anti-caching headers. In environments where CDN caching is enabled,…

📅 Published: Nov. 21, 2025, 1:29 a.m. 🔄 Last Modified: Nov. 21, 2025, 3:13 p.m.

5.8

CVSS4.0

CVE-2025-64751 - OpenFGA Improper Policy Enforcement

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.4.0 to v1.11.0 ( openfga-0.1.34 <= Helm chart <= openfga-0.2.48, v.1.4.0 <= docker <= v.1.11.0) are vulnerable to improper policy enforcement when certain Chec…

📅 Published: Nov. 21, 2025, 1:24 a.m. 🔄 Last Modified: Nov. 21, 2025, 3:13 p.m.

8.3

CVSS4.0

CVE-2025-62372 - vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs

vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before 0.11.1, users can crash the vLLM engine serving multimodal models by passing multimodal embedding inputs with correct ndim but incorrect shape (e.g. hidden dimension is wrong), regardless of wheth…

📅 Published: Nov. 21, 2025, 1:22 a.m. 🔄 Last Modified: Nov. 21, 2025, 3:13 p.m.

6.5

CVSS3.1

CVE-2025-62426 - vLLM vulnerable to DoS via large Chat Completion or Tokenization requests with specially crafted `c…

vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before 0.11.1, the /v1/chat/completions and /tokenize endpoints allow a chat_template_kwargs request parameter that is used in the code before it is properly validated against the chat template. With the…

📅 Published: Nov. 21, 2025, 1:21 a.m. 🔄 Last Modified: Nov. 21, 2025, 3:13 p.m.

8.8

CVSS3.1

CVE-2025-62164 - VLLM deserialization vulnerability leading to DoS and potential RCE

vLLM is an inference and serving engine for large language models (LLMs). From versions 0.10.2 to before 0.11.1, a memory corruption vulnerability could lead to a crash (denial-of-service) and potentially remote code execution (RCE), exists in the Completions API endpoint. When processing user-supp…

📅 Published: Nov. 21, 2025, 1:18 a.m. 🔄 Last Modified: Nov. 21, 2025, 3:13 p.m.
Total resulsts: 319170
Page 20 of 31,917
« previous page » next page
Filters