5.3

CVSS4.0

CVE-2025-40893 - HTML injection in Asset List in Guardian/CMC before 25.5.0

A Stored HTML Injection vulnerability was discovered in the Asset List functionality due to improper validation of network traffic data. An unauthenticated attacker can send specially crafted network packets to inject HTML tags into asset attributes. When a victim views the affected assets in the A…

📅 Published: Dec. 18, 2025, 1:17 p.m. 🔄 Last Modified: April 14, 2026, 10:16 a.m.

7.1

CVSS4.0

CVE-2025-40892 - Stored Cross-Site Scripting (XSS) in Reports in Guardian/CMC before 25.5.0

A Stored Cross-Site Scripting vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenticated user with report privileges can define a malicious report containing a JavaScript payload, or a victim can be socially engineered to import a ma…

📅 Published: Dec. 18, 2025, 1:16 p.m. 🔄 Last Modified: April 14, 2026, 10:16 a.m.

2.3

CVSS4.0

CVE-2025-40891 - HTML injection in in Time Machine functionality in Guardian/CMC before 25.5.0

A Stored HTML Injection vulnerability was discovered in the Time Machine Snapshot Diff functionality due to improper validation of network traffic data. An unauthenticated attacker can send specially crafted network packets at two different times to inject HTML tags into asset attributes across two…

📅 Published: Dec. 18, 2025, 1:14 p.m. 🔄 Last Modified: April 14, 2026, 10:16 a.m.

4.3

CVSS3.1

CVE-2025-13110 - HUSKY – Products Filter Professional for WooCommerce <= 1.3.7.3 - Authenticated (Subscriber+) Insec…

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.7.3 via the "woof_add_subscr" function due to missing validation on a user controlled key. This makes it possible for authenticat…

📅 Published: Dec. 18, 2025, 12:22 p.m. 🔄 Last Modified: April 22, 2026, 12:15 a.m.

7.5

CVSS3.1

CVE-2025-14437 - Hummingbird <= 3.18.0 - Unauthenticated Sensitive Information Exposure via Log File

The Hummingbird Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.18.0 via the 'request' function. This makes it possible for unauthenticated attackers to extract sensitive data including Cloudflare API credentials.

📅 Published: Dec. 18, 2025, 12:22 p.m. 🔄 Last Modified: April 21, 2026, 5:15 p.m.

4.3

CVSS3.1

CVE-2025-14618 - Sweet Energy Efficiency <= 1.0.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary G…

The Sweet Energy Efficiency plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on the 'sweet_energy_efficiency_action' AJAX handler in all versions up to, and including, 1.0.6. This makes it possible for authenticated attacker…

📅 Published: Dec. 18, 2025, 12:22 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-14277 - Prime Slider – Addons for Elementor <= 4.0.9 - Authenticated (Subscriber+) Server-Side Request Forg…

The Prime Slider – Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.9 via the import_elementor_template AJAX action. This makes it possible for authenticated attackers, with subscriber level access and above, to make we…

📅 Published: Dec. 18, 2025, 12:22 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2025-14883 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-68016. Reason: This candidate is a reservation duplicate of CVE-2025-68016. Notes: All CVE users should reference CVE-2025-68016 instead of this candidate. All references and descriptions in this candidate have been removed to prev…

📅 Published: Dec. 18, 2025, 12:04 p.m. 🔄 Last Modified: Jan. 20, 2026, 3:07 p.m.

9.3

CVSS4.0

CVE-2025-10910 - Gaining remote control over Govee devices

A flaw in the binding process of Govee’s cloud platform and devices allows a remote attacker to bind an existing, online Govee device to the attacker’s account, resulting in full control of the device and removal of the device from its legitimate owner’s account. The server‑side API allows device a…

📅 Published: Dec. 18, 2025, 11:21 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.6

CVSS3.1

CVE-2025-40602 -

A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).

📅 Published: Dec. 18, 2025, 10:58 a.m. 🔄 Last Modified: Dec. 19, 2025, 1:57 p.m.
Total resulsts: 345790
Page 2178 of 34,579
« previous page » next page
Filters