5.3

CVSS4.0

CVE-2025-15474 - AuntyFey Smart Combination Lock BLE Connection Flood DoS

AuntyFey Smart Combination Lock firmware versions as of 2025-12-24 contain a vulnerability that allows an unauthenticated attacker within Bluetooth Low Energy (BLE) range to cause a denial of service by repeatedly initiating BLE connections. Sustained connection attempts interrupt keypad authentica…

📅 Published: Jan. 7, 2026, 4:33 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-14468 - AMP for WP – Accelerated Mobile Pages <= 1.1.9 - Cross-Site Request Forgery to Comment Submission

The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.9. This is due to inverted nonce verification logic in the amp_theme_ajaxcomments AJAX handler, which rejects requests with VALID nonces and accepts reque…

📅 Published: Jan. 7, 2026, 4:32 a.m. 🔄 Last Modified: April 22, 2026, 4 p.m.

9.3

CVSS4.0

CVE-2026-0650 - OpenFlagr <= 1.1.18 Authentication Bypass via Prefix Whitelist Path Normalization

OpenFlagr versions prior to and including 1.1.18 contain an authentication bypass vulnerability in the HTTP middleware. Due to improper handling of path normalization in the whitelist logic, crafted requests can bypass authentication and access protected API endpoints without valid credentials. Una…

📅 Published: Jan. 7, 2026, 4:29 a.m. 🔄 Last Modified: April 18, 2026, 8:15 a.m.

7.2

CVSS4.0

CVE-2025-9611 - Microsoft Playwright MCP Server < 0.0.40 DNS Rebinding via Missing Origin Header Validation

Microsoft Playwright MCP Server versions prior to 0.0.40 fails to validate the Origin header on incoming connections. This allows an attacker to perform a DNS rebinding attack via a victim’s web browser and send unauthorized requests to a locally running MCP server, resulting in unintended invocati…

📅 Published: Jan. 7, 2026, 4:24 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-14059 - EmailKit <= 1.6.1 - Authenticated (Author+) Arbitrary File Read via Path Traversal

The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all versions up to, and including, 1.6.1. This is due to missing path validation in the create_template REST API endpoint where user-controlled input from the emailkit-editor-template parameter is passed di…

📅 Published: Jan. 7, 2026, 3:21 a.m. 🔄 Last Modified: April 22, 2026, 12:15 a.m.

6.4

CVSS3.1

CVE-2025-14891 - Customer Reviews for WooCommerce <= 5.93.1 - Authenticated (Subscriber+) Stored Cross-Site Scriptin…

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'displayName' parameter in all versions up to, and including, 5.93.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with cu…

📅 Published: Jan. 7, 2026, 3:21 a.m. 🔄 Last Modified: April 22, 2026, 12:15 a.m.

8.5

CVSS4.0

CVE-2026-20893 - Origin Validation Error Allows SYSTEM Privilege Execution in Fujitsu AuthConductor Client Basic V2

Origin validation error issue exists in Fujitsu Security Solution AuthConductor Client Basic V2 2.0.25.0 and earlier. If this vulnerability is exploited, an attacker who can log in to the Windows system where the affected product is installed may execute arbitrary code with SYSTEM privilege and/or …

📅 Published: Jan. 7, 2026, 3:16 a.m. 🔄 Last Modified: April 18, 2026, 8:15 a.m.

5.3

CVSS3.1

CVE-2025-12648 - WP-Members Membership Plugin <= 3.5.4.4 - Unauthenticated Information Exposure via Unprotected Files

The WP-Members Membership Plugin for WordPress is vulnerable to unauthorized file access in versions up to, and including, 3.5.4.4. This is due to storing user-uploaded files in predictable directories (wp-content/uploads/wpmembers/user_files/<user_id>/) without implementing proper access controls …

📅 Published: Jan. 7, 2026, 2:21 a.m. 🔄 Last Modified: April 21, 2026, 5 p.m.

7.1

CVSS4.0

CVE-2025-14631 - Null Pointer Dereference Vulnerability in Malformed 802.11 Frame of TP-Link Archer BE400

A NULL Pointer Dereference vulnerability in TP-Link Archer BE400 V1(802.11 modules) allows  an adjacent attacker to cause a denial-of-service (DoS) by triggering a device reboot. This issue affects Archer BE400: xi 1.1.0 Build 20250710 rel.14914.

📅 Published: Jan. 7, 2026, 1:04 a.m. 🔄 Last Modified: March 12, 2026, 7:29 p.m.

5.1

CVSS4.0

CVE-2026-0649 - invoiceninja Migration Import Import.php copy server-side request forgery

A security vulnerability has been detected in invoiceninja up to 5.12.38. The affected element is the function copy of the file /app/Jobs/Util/Import.php of the component Migration Import. The manipulation of the argument company_logo leads to server-side request forgery. It is possible to initiate…

📅 Published: Jan. 7, 2026, 12:32 a.m. 🔄 Last Modified: April 18, 2026, 5 p.m.
Total resulsts: 348200
Page 2162 of 34,820
« previous page » next page
Filters