6.5

CVSS3.1

CVE-2025-13781 - Missing Authorization in GitLab

GitLab has remediated an issue in GitLab EE affecting all versions from 18.5 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to modify instance-wide AI feature provider settings by exploiting missing authorization checks in GraphQL mutations.

πŸ“… Published: Jan. 9, 2026, 10:03 a.m. πŸ”„ Last Modified: Jan. 22, 2026, 9:13 p.m.

7.5

CVSS3.1

CVE-2025-64092 - Unauthenticated SQL injection via GET request parameters

This vulnerability allows unauthenticated attackers to inject an SQL request into GET request parameters and directly query the underlying database.

πŸ“… Published: Jan. 9, 2026, 10:03 a.m. πŸ”„ Last Modified: Feb. 12, 2026, 5:42 p.m.

8.6

CVSS3.1

CVE-2025-64091 - Authenticated Remote Code Execution in the NTP-configuration

This vulnerability allows authenticated attackers to execute commands via the NTP-configuration of the device.

πŸ“… Published: Jan. 9, 2026, 10 a.m. πŸ”„ Last Modified: Feb. 12, 2026, 5:45 p.m.

10

CVSS3.1

CVE-2025-64090 - Authenticated Remote Code Execution in device hostname

This vulnerability allows authenticated attackers to execute commands via the hostname of the device.

πŸ“… Published: Jan. 9, 2026, 9:59 a.m. πŸ”„ Last Modified: Feb. 12, 2026, 5:45 p.m.

6.1

CVSS3.1

CVE-2025-13895 - Top Position Google Finance <= 0.1.0 - Reflected Cross-Site Scripting

The Top Position Google Finance plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` variable in all versions up to, and including, 0.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers t…

πŸ“… Published: Jan. 9, 2026, 9:19 a.m. πŸ”„ Last Modified: April 20, 2026, 9:15 p.m.

6.4

CVSS3.1

CVE-2025-13900 - WP Popup Magic <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'name' Short…

The WP Popup Magic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter of the [wppum_end] shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

πŸ“… Published: Jan. 9, 2026, 9:19 a.m. πŸ”„ Last Modified: April 20, 2026, 9:15 p.m.

6.4

CVSS3.1

CVE-2025-13853 - Nearby Now Reviews <= 5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode …

The Nearby Now Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_tech' parameter of the nn-tech shortcode in all versions up to, and including, 5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, w…

πŸ“… Published: Jan. 9, 2026, 9:19 a.m. πŸ”„ Last Modified: April 21, 2026, 4:45 p.m.

6.4

CVSS3.1

CVE-2025-13729 - Entry Views <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Entry Views plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'entry-views' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated att…

πŸ“… Published: Jan. 9, 2026, 9:19 a.m. πŸ”„ Last Modified: April 22, 2026, 8:15 p.m.

6.4

CVSS3.1

CVE-2026-0627 - AMP for WP <= 1.1.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via SVG File Upload

The AMP for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versions up to, and including, 1.1.10. This is due to insufficient sanitization of SVG file content that only removes `<script>` tags while allowing other XSS vectors such as event handlers …

πŸ“… Published: Jan. 9, 2026, 8:20 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2025-14657 - Eventin – Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered) <= 4…

The Eventin – Event Manager, Events Calendar, Event Tickets and Registrations plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'post_settings' function in all versions up to, and including, 4.0.51. This makes it possible for unauthenti…

πŸ“… Published: Jan. 9, 2026, 7:22 a.m. πŸ”„ Last Modified: April 20, 2026, 9:15 p.m.
Total resulsts: 349182
Page 2213 of 34,919
Β« previous page Β» next page
Filters