6.5

CVSS3.1

CVE-2025-13652 - CBX Bookmark & Favorite <= 2.0.4 - Authenticated (Subscriber+) SQL Injection via `orderby` Parameter

The CBX Bookmark & Favorite plugin for WordPress is vulnerable to generic SQL Injection via the โ€˜orderbyโ€™ parameter in all versions up to, and including, 2.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it poโ€ฆ

๐Ÿ“… Published: Jan. 6, 2026, 3:21 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 5 p.m.

6.5

CVSS3.1

CVE-2025-11723 - Appointment Booking Calendar โ€” Simply Schedule Appointments Booking Plugin <= 1.6.9.5 - Unauthenticโ€ฆ

The Appointment Booking Calendar โ€” Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.9.5 via the hash() function due to use of a hardcoded fall-back salt. This makes it possible for unauthenticaโ€ฆ

๐Ÿ“… Published: Jan. 6, 2026, 3:21 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 12:45 a.m.

4.9

CVSS3.1

CVE-2025-13409 - Form Vibes โ€“ Database Manager for Forms <= 1.4.13 - Authenticated (Admin+) SQL Injection

The Form Vibes โ€“ Database Manager for Forms plugin for WordPress is vulnerable to SQL Injection via the 'params' parameter in all versions up to, and including, 1.4.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makโ€ฆ

๐Ÿ“… Published: Jan. 6, 2026, 3:21 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 4 p.m.

8.8

CVSS3.1

CVE-2026-21485 - iccDEV Undefined Behavior (UB) and Out of Memory in CIccProfile::LoadTag()

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below are prone to have Undefined Behavior (UB) and Out of Memory errors. This issue is fixed in version 2.3.1.2.

๐Ÿ“… Published: Jan. 6, 2026, 3:17 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 8:15 p.m.

8.8

CVSS3.1

CVE-2026-21677 - iccDEV has Undefined Behavior in CIccCLUT::Init()

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below have Undefined Behavior in its CIccCLUT::Init function which initializes and sets the size of a CLUT. This issue is fixed in version 2.3.1.1.

๐Ÿ“… Published: Jan. 6, 2026, 3:11 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 8:30 a.m.

8.8

CVSS3.1

CVE-2026-21676 - iccDEV has a Heap-based Buffer Overflow in its CIccMBB::Validate() function

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below have a Heap-based Buffer Overflow in its CIccMBB::Validate function which checks tag data validity. This issue is fixed in version 2.3.1.1.

๐Ÿ“… Published: Jan. 6, 2026, 3:07 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 5 p.m.

8.5

CVSS4.0

CVE-2025-12793 -

An uncontrolled DLL loading path vulnerability exists in AsusSoftwareManagerAgent. A local attacker may influence the application to load a DLL from an attacker-controlled location, potentially resulting in arbitrary code execution. Refer to the ' Security Update for MyASUS' section on the ASUS Seโ€ฆ

๐Ÿ“… Published: Jan. 6, 2026, 2:14 a.m. ๐Ÿ”„ Last Modified: Jan. 28, 2026, 2:50 p.m.

7.3

CVSS3.1

CVE-2025-15364 - Download Manager <= 3.3.40 - Unauthenticated Limited Privilege Escalation via updatePassword

The Download Manager plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.3.40. This is due to the plugin not properly validating a user's identity prior to updating their details like password. This makes it possible for unauthentiโ€ฆ

๐Ÿ“… Published: Jan. 6, 2026, 1:50 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 4 p.m.

6.7

CVSS3.1

CVE-2025-20807 -

In dpe, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10114841; Issue ID: MSV-4451.

๐Ÿ“… Published: Jan. 6, 2026, 1:47 a.m. ๐Ÿ”„ Last Modified: March 30, 2026, 1:05 p.m.

6.7

CVSS3.1

CVE-2025-20806 -

In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10114835; Issue ID: MSV-4479.

๐Ÿ“… Published: Jan. 6, 2026, 1:47 a.m. ๐Ÿ”„ Last Modified: March 30, 2026, 1:05 p.m.
Total resulsts: 348124
Page 2171 of 34,813
ยซ previous page ยป next page
Filters