6.8

CVSS3.1

CVE-2025-14803 - Nex-Forms Express WP Form Builder < 9.1.8 - Authenticated Stored XSS

The NEX-Forms WordPress plugin before 9.1.8 does not sanitise and escape some of its settings. The NEX-Forms WordPress plugin before 9.1.8 can be configured in such a way that could allow subscribers to perform Stored Cross-Site Scripting.

πŸ“… Published: Jan. 9, 2026, 6 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-13749 - Clearfy <= 2.4.0 - Cross-Site Request Forgery to Update Notification Tampering

The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.0. This is due to missing nonce validation on the "wbcr_upm_change_flag" function. This makes it possible for un…

πŸ“… Published: Jan. 9, 2026, 5:25 a.m. πŸ”„ Last Modified: April 22, 2026, 12:15 a.m.

5.3

CVSS3.1

CVE-2025-14886 - Japanized for WooCommerce <= 2.7.17 - Missing Authorization to Unauthenticated Order Status Modific…

The Japanized for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `order` REST API endpoint in all versions up to, and including, 2.7.17. This makes it possible for unauthenticated attackers to mark any WooCommerce order a…

πŸ“… Published: Jan. 9, 2026, 4:31 a.m. πŸ”„ Last Modified: April 22, 2026, 12:15 a.m.

4.3

CVSS3.1

CVE-2025-66315 - ZTE MF258K Pro Version Server has a Configuration Defect Vulnerability

There is a configuration defect vulnerability in the version server of ZTE MF258K Pro products. Due to improper directory permission settings, an attacker can execute write permissions in a specific directory.

πŸ“… Published: Jan. 9, 2026, 2:24 a.m. πŸ”„ Last Modified: March 12, 2026, 7:26 p.m.

6.4

CVSS3.1

CVE-2025-14525 - Kubevirt: kubevirt: vm administration denial of service via guest agent

A flaw was found in kubevirt. A user within a virtual machine (VM), if the guest agent is active, can exploit this by causing the agent to report an excessive number of network interfaces. This action can overwhelm the system's ability to store VM configuration updates, effectively blocking changes…

πŸ“… Published: Jan. 9, 2026, 2:02 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.3

CVSS4.0

CVE-2026-22712 - ApprovedRevs allows bypassing the inline CSS sanitizer

Improper Encoding or Escaping of OutputΒ due to magic word replacement in ParserAfterTidy vulnerability in The Wikimedia Foundation Mediawiki - ApprovedRevs Extension allows Input Data Manipulation.This issue affects Mediawiki - ApprovedRevs Extension: 1.45, 1.44, 1.43, 1.39.

πŸ“… Published: Jan. 9, 2026, 12:06 a.m. πŸ”„ Last Modified: April 18, 2026, 7:30 a.m.

2.3

CVSS4.0

CVE-2026-22713 - Stored XSS through edit summaries in GrowthExperiments

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - GrowthExperiments Extension: 1.45, 1.44, 1.43, 1.39.

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 7:30 a.m.

7.5

CVSS3.1

CVE-2025-66744 -

In Yonyou YonBIP v3 and before, the LoginWithV8 interface in the series data application service system is vulnerable to path traversal, allowing unauthorized access to sensitive information within the system

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-67281 -

In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple SQL injection vulnerabilities exists which allow a low privileged and administrative user to access the database and its content.

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Jan. 22, 2026, 9:35 p.m.

6.5

CVSS3.1

CVE-2025-67004 -

** Disputed ** An Information Disclosure vulnerability in CouchCMS 2.4 allow an Admin user to read arbitrary files via traversing directories back after back. It can Disclosure the source code or any other confidential information if weaponize accordingly. NOTE: A community member states that this …

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Jan. 23, 2026, 7:15 p.m.
Total resulsts: 348413
Page 2140 of 34,842
Β« previous page Β» next page
Filters