6.5

CVSS3.1

CVE-2025-62761 - WordPress Knowledge Base documentation & wiki plugin โ€“ BasePress plugin <= 2.17.0.1 - Cross Site Scโ€ฆ

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BasePress Knowledge Base documentation & wiki plugin โ€“ BasePress basepress allows Stored XSS.This issue affects Knowledge Base documentation & wiki plugin โ€“ BasePress: from n/a through <= 2.17.0.1.

๐Ÿ“… Published: Dec. 31, 2025, 8:44 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:34 p.m.

8.7

CVSS4.0

CVE-2025-15387 - QNO Technology๏ฝœVPN Firewall - Insufficient Entropy

VPN Firewall developed by QNO Technology has a Insufficient Entropy vulnerability, allowing unauthenticated remote attackers to obtain any logged-in user session through brute-force attacks and subsequently log into the system.

๐Ÿ“… Published: Dec. 31, 2025, 8:23 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7

CVSS4.0

CVE-2025-15017 -

A vulnerability exists in serial device servers where active debug code remains enabled in the UART interface. An attacker with physical access to the device can directly connect to the UART interface and, without authentication, user interaction, or execution conditions, gain unauthorized access tโ€ฆ

๐Ÿ“… Published: Dec. 31, 2025, 7:44 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS4.0

CVE-2025-2026 -

The NPort 6100-G2/6200-G2 Series is affected by a high-severity vulnerability (CVE-2025-2026) that allows remote attackers to execute a null byte injection through the deviceโ€™s web API. This may lead to an unexpected device reboot and result in a denial-of-service (DoS) condition. An authenticatedโ€ฆ

๐Ÿ“… Published: Dec. 31, 2025, 7:32 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.7

CVSS4.0

CVE-2025-1977 -

The NPort 6100-G2/6200-G2 Series is affected by an execution with unnecessary privileges vulnerability (CVE-2025-1977) that allows an authenticated user with read-only access to perform unauthorized configuration changes through the MCC (Moxa CLI Configuration) tool. The issue can be exploited remoโ€ฆ

๐Ÿ“… Published: Dec. 31, 2025, 7:23 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2025-15279 - FontForge GUtils BMP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

FontForge GUtils BMP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FontForge. User interaction is required to exploit this vulnerability in that the target must visit a mโ€ฆ

๐Ÿ“… Published: Dec. 31, 2025, 6:59 a.m. ๐Ÿ”„ Last Modified: Jan. 7, 2026, 3:57 p.m.

7.8

CVSS3.1

CVE-2025-15278 - FontForge GUtils XBM File Parsing Integer Overflow Remote Code Execution Vulnerability

FontForge GUtils XBM File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FontForge. User interaction is required to exploit this vulnerability in that the target must visit a malicious pโ€ฆ

๐Ÿ“… Published: Dec. 31, 2025, 6:59 a.m. ๐Ÿ”„ Last Modified: Jan. 7, 2026, 4:01 p.m.

7.8

CVSS3.1

CVE-2025-15277 - FontForge GUtils SGI File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

FontForge GUtils SGI File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FontForge. User interaction is required to exploit this vulnerability in that the target must visit a mโ€ฆ

๐Ÿ“… Published: Dec. 31, 2025, 6:59 a.m. ๐Ÿ”„ Last Modified: Jan. 7, 2026, 4:02 p.m.

7.8

CVSS3.1

CVE-2025-15276 - FontForge SFD File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability

FontForge SFD File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FontForge. User interaction is required to exploit this vulnerability in that the target must visit a mโ€ฆ

๐Ÿ“… Published: Dec. 31, 2025, 6:59 a.m. ๐Ÿ”„ Last Modified: Jan. 7, 2026, 4:03 p.m.

8.8

CVSS3.1

CVE-2025-15280 - FontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerability

FontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FontForge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or opโ€ฆ

๐Ÿ“… Published: Dec. 31, 2025, 6:59 a.m. ๐Ÿ”„ Last Modified: Jan. 7, 2026, 3:50 p.m.
Total resulsts: 347837
Page 2198 of 34,784
ยซ previous page ยป next page
Filters