6.4

CVSS3.1

CVE-2025-14555 - Countdown Timer - Widget Countdown <= 2.7.7 - Authenticated (Contributor+) Stored Cross-Site Scriptโ€ฆ

The Countdown Timer โ€“ Widget Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdevart_countdown' shortcode in all versions up to, and including, 2.7.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it โ€ฆ

๐Ÿ“… Published: Jan. 10, 2026, 12:23 p.m. ๐Ÿ”„ Last Modified: April 20, 2026, 9:15 p.m.

4.8

CVSS4.0

CVE-2025-15504 - lief-project LIEF ELF Binary Parser.tcc parse_binary null pointer dereference

A security flaw has been discovered in lief-project LIEF up to 0.17.1. Affected by this issue is the function Parser::parse_binary of the file src/ELF/Parser.tcc of the component ELF Binary Parser. The manipulation results in null pointer dereference. The attack must be initiated from a local positโ€ฆ

๐Ÿ“… Published: Jan. 10, 2026, 11:32 a.m. ๐Ÿ”„ Last Modified: Feb. 23, 2026, 9:16 a.m.

6.4

CVSS3.1

CVE-2025-14506 - ConvertForce Popup Builder <= 0.0.7 - Stored Cross-Site Scripting via entrance_animation

The ConvertForce Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Gutenberg block's `entrance_animation` attribute in all versions up to, and including, 0.0.7. This is due to insufficient input sanitization and output escaping. This makes it possible for autheโ€ฆ

๐Ÿ“… Published: Jan. 10, 2026, 11:22 a.m. ๐Ÿ”„ Last Modified: April 20, 2026, 9:15 p.m.

7.5

CVSS3.1

CVE-2025-52435 - Apache Mynewt NimBLE: Invalid error handling in pause encryption procedure in NimBLE controller

J2EE Misconfiguration: Data Transmission Without Encryption vulnerability in Apache NimBLE. Improper handling of Pause Encryption procedure on Link Layer results in a previously encrypted connection being left in un-encrypted state allowing an eavesdropper to observe the remainder of the exchange.โ€ฆ

๐Ÿ“… Published: Jan. 10, 2026, 9:47 a.m. ๐Ÿ”„ Last Modified: Jan. 14, 2026, 4:30 p.m.

3.1

CVSS3.1

CVE-2025-53470 - Apache Mynewt NimBLE: Out-of-Bounds Write Vulnerability in NimBLE HCI H4 driver

Out-of-bounds Read vulnerability in Apache NimBLE HCI H4 driver. Specially crafted HCI event could lead to invalid memory read in H4 driver. This issue affects Apache NimBLE: through 1.8.ย  This issue requires a broken or bogus Bluetooth controller and thus severity is considered low. Users are โ€ฆ

๐Ÿ“… Published: Jan. 10, 2026, 9:46 a.m. ๐Ÿ”„ Last Modified: Jan. 14, 2026, 5:38 p.m.

7.5

CVSS3.1

CVE-2025-53477 - Apache Mynewt NimBLE: NULL Pointer Dereference in NimBLE host HCI layer

NULL Pointer Dereference vulnerability in Apache Nimble. Missing validation of HCI connection complete or HCI command TX buffer could lead to NULL pointer dereference. This issue requires disabled asserts and broken or bogus Bluetooth controller and thus severity is considered low. This issue affโ€ฆ

๐Ÿ“… Published: Jan. 10, 2026, 9:45 a.m. ๐Ÿ”„ Last Modified: Jan. 14, 2026, 5:38 p.m.

8.1

CVSS3.1

CVE-2025-62235 - Apache Mynewt NimBLE: Incorrect handling of SMP Security Request could lead to undesirable pairing

Authentication Bypass by Spoofing vulnerability in Apache NimBLE. Receiving specially crafted Security Request could lead to removal of original bondย and re-bond with impostor. This issue affects Apache NimBLE: through 1.8.0. Users are recommended to upgrade to version 1.9.0, which fixes the issuโ€ฆ

๐Ÿ“… Published: Jan. 10, 2026, 9:42 a.m. ๐Ÿ”„ Last Modified: Jan. 14, 2026, 5:45 p.m.

5.3

CVSS3.1

CVE-2026-0831 - Templately <= 3.4.8 - Unauthenticated Limited Arbitrary JSON File Write

The Templately plugin for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 3.4.8. This is due to inadequate input validation in the `save_template_to_file()` function where user-controlled parameters like `session_id`, `content_id`, and `ai_page_ids` are used toโ€ฆ

๐Ÿ“… Published: Jan. 10, 2026, 9:22 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-15503 - Sangfor Operation and Maintenance Management System common.jsp unrestricted upload

A security flaw has been discovered in Sangfor Operation and Maintenance Management System up to 3.0.8. The impacted element is an unknown function of the file /fort/trust/version/common/common.jsp. Performing a manipulation of the argument File results in unrestricted upload. The attack is possiblโ€ฆ

๐Ÿ“… Published: Jan. 10, 2026, 9:02 a.m. ๐Ÿ”„ Last Modified: Feb. 23, 2026, 8:27 a.m.

5.4

CVSS3.1

CVE-2025-14976 - User Registration & Membership <= 4.4.8 - Cross-Site Request Forgery to Arbitrary Post Deletion

The User Registration & Membership โ€“ Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.4.8. This is due to missing or incorrect nonce valโ€ฆ

๐Ÿ“… Published: Jan. 10, 2026, 8:22 a.m. ๐Ÿ”„ Last Modified: April 20, 2026, 9:15 p.m.
Total resulsts: 349182
Page 2200 of 34,919
ยซ previous page ยป next page
Filters