6.5
CVE-2025-62761 - WordPress Knowledge Base documentation & wiki plugin โ BasePress plugin <= 2.17.0.1 - Cross Site Scโฆ
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BasePress Knowledge Base documentation & wiki plugin โ BasePress basepress allows Stored XSS.This issue affects Knowledge Base documentation & wiki plugin โ BasePress: from n/a through <= 2.17.0.1.
8.7
CVE-2025-15387 - QNO Technology๏ฝVPN Firewall - Insufficient Entropy
VPN Firewall developed by QNO Technology has a Insufficient Entropy vulnerability, allowing unauthenticated remote attackers to obtain any logged-in user session through brute-force attacks and subsequently log into the system.
7
CVE-2025-15017 -
A vulnerability exists in serial device servers where active debug code remains enabled in the UART interface. An attacker with physical access to the device can directly connect to the UART interface and, without authentication, user interaction, or execution conditions, gain unauthorized access tโฆ
7.1
CVE-2025-2026 -
The NPort 6100-G2/6200-G2 Series is affected by a high-severity vulnerability (CVE-2025-2026) that allows remote attackers to execute a null byte injection through the deviceโs web API. This may lead to an unexpected device reboot and result in a denial-of-service (DoS) condition. An authenticatedโฆ
7.7
CVE-2025-1977 -
The NPort 6100-G2/6200-G2 Series is affected by an execution with unnecessary privileges vulnerability (CVE-2025-1977) that allows an authenticated user with read-only access to perform unauthorized configuration changes through the MCC (Moxa CLI Configuration) tool. The issue can be exploited remoโฆ
7.8
CVE-2025-15279 - FontForge GUtils BMP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
FontForge GUtils BMP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FontForge. User interaction is required to exploit this vulnerability in that the target must visit a mโฆ
7.8
CVE-2025-15278 - FontForge GUtils XBM File Parsing Integer Overflow Remote Code Execution Vulnerability
FontForge GUtils XBM File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FontForge. User interaction is required to exploit this vulnerability in that the target must visit a malicious pโฆ
7.8
CVE-2025-15277 - FontForge GUtils SGI File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
FontForge GUtils SGI File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FontForge. User interaction is required to exploit this vulnerability in that the target must visit a mโฆ
7.8
CVE-2025-15276 - FontForge SFD File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability
FontForge SFD File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FontForge. User interaction is required to exploit this vulnerability in that the target must visit a mโฆ
8.8
CVE-2025-15280 - FontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerability
FontForge SFD File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of FontForge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or opโฆ