8.8

CVSS3.1

CVE-2025-15347 - Creator LMS – The LMS for Creators, Coaches, and Trainers <= 1.1.12 - Missing Authorization to Auth…

The Creator LMS – The LMS for Creators, Coaches, and Trainers plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check in the get_items_permissions_check function in all versions up to, and including, 1.1.12. Thi…

📅 Published: Jan. 20, 2026, 2:26 p.m. 🔄 Last Modified: April 20, 2026, 4 p.m.

5.4

CVSS3.1

CVE-2025-15043 - The Events Calendar <= 6.15.13 - Missing Authorization to Authenticated (Subscriber+) Data Migratio…

The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'start_migration', 'cancel_migration', and 'revert_migration' functions in all versions up to, and including, 6.15.13. This makes it possible for authenticated attackers, with …

📅 Published: Jan. 20, 2026, 2:26 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2026-0690 - FlatPM – Ad Manager, AdSense and Custom Code <= 3.2.2 - Authenticated (Contributor+) Stored Cross-S…

The FlatPM – Ad Manager, AdSense and Custom Code plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rank_math_description' custom field in all versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenti…

📅 Published: Jan. 20, 2026, 2:26 p.m. 🔄 Last Modified: April 18, 2026, 5 a.m.

5.4

CVSS3.1

CVE-2026-0548 - Tutor LMS – eLearning and online course solution <= 3.9.4 - Missing Authorization to Authenticated …

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized attachment deletion due to a missing capability check on the `delete_existing_user_photo` function in all versions up to, and including, 3.9.4. This makes it possible for authenticated attackers,…

📅 Published: Jan. 20, 2026, 2:26 p.m. 🔄 Last Modified: April 15, 2026, 9:45 p.m.

8.1

CVSS3.1

CVE-2026-0726 - Nexter Extension – Site Enhancements Toolkit <= 4.4.6 - Unauthenticated PHP Object Injection via 'n…

The Nexter Extension – Site Enhancements Toolkit plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.4.6 via deserialization of untrusted input in the 'nxt_unserialize_replace' function. This makes it possible for unauthenticated attackers to inject a …

📅 Published: Jan. 20, 2026, 2:26 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-9283 - ArmorStart® LT - Multiple Denial-of-Service Vulnerabilities

A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP Step Limits Storms tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.

📅 Published: Jan. 20, 2026, 1:59 p.m. 🔄 Last Modified: Feb. 2, 2026, 6:08 p.m.

8.7

CVSS4.0

CVE-2025-9282 - ArmorStart® LT - Multiple Denial-of-Service Vulnerabilities

A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive limited storm tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.

📅 Published: Jan. 20, 2026, 1:59 p.m. 🔄 Last Modified: Feb. 2, 2026, 6:08 p.m.

8.7

CVSS4.0

CVE-2025-9281 - ArmorStart® LT - Multiple Denial-of-Service Vulnerabilities

A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive step limit storm tests, the device reboots

📅 Published: Jan. 20, 2026, 1:58 p.m. 🔄 Last Modified: Feb. 2, 2026, 6:08 p.m.

9.9

CVSS3.1

CVE-2026-22844 - Zoom Node Deployments - Command Injection

A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting participant to conduct remote code execution of the MMR via network access.

📅 Published: Jan. 20, 2026, 1:57 p.m. 🔄 Last Modified: April 18, 2026, 4 p.m.

8.7

CVSS4.0

CVE-2025-9280 - ArmorStart® LT - Multiple Denial-of-Service Vulnerabilities

A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. Fuzzing performed using Defensics causes the device to become unresponsive, requiring a reboot.

📅 Published: Jan. 20, 2026, 1:57 p.m. 🔄 Last Modified: Feb. 2, 2026, 6:08 p.m.
Total resulsts: 349182
Page 2061 of 34,919
« previous page » next page
Filters