9.9

CVSS3.1

CVE-2025-30996 - Arbitrary File Upload Vulnerability in WordPress themes by Themify

Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Sidepane WordPress Theme, Themify Themify Newsy, Themify Themify Folo, Themify Themify Edmin, Themify Bloggie, Themify Photobox, Themify Wigi, Themify Rezo, Themify Slide allows Upload a Web Shell to a Web Server.This …

πŸ“… Published: Jan. 6, 2026, 8:56 p.m. πŸ”„ Last Modified: April 28, 2026, 7:30 p.m.

8.4

CVSS4.0

CVE-2025-13744 - Improper Neutralization of Input During Web Page Generation vulnerability was identified in GitHub …

An Improper Neutralization of Input During Web Page Generation vulnerability was identified in GitHub Enterprise Server that allowed attacker controlled HTML to be rendered by the Filter component (search) across GitHub that could be used to exfiltrate sensitive information. An attacker would requi…

πŸ“… Published: Jan. 6, 2026, 8:44 p.m. πŸ”„ Last Modified: Jan. 30, 2026, 4:51 p.m.

7.1

CVSS3.1

CVE-2025-30631 - Reflected Cross Site Scripting (XSS) vulnerability in AA-Team WordPress plugins

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA-Team Woocommerce Sales Funnel Builder, AA-Team Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer) allows Reflected XSS.This issue affects Woocommerce Sales Funnel Build…

πŸ“… Published: Jan. 6, 2026, 8:30 p.m. πŸ”„ Last Modified: April 28, 2026, 7:30 p.m.

8.8

CVSS3.1

CVE-2025-29004 - Privilege Escalation Vulnerability in AA-Team WordPress plugins

Incorrect Privilege Assignment vulnerability in AA-Team Premium Age Verification / Restriction for WordPress, AA-Team Responsive Coming Soon Landing Page / Holding Page for WordPress allows Privilege Escalation.This issue affects Premium Age Verification / Restriction for WordPress: from n/a throug…

πŸ“… Published: Jan. 6, 2026, 8:25 p.m. πŸ”„ Last Modified: April 28, 2026, 7:30 p.m.

5.5

CVSS3.1

CVE-2026-21492 - iccDEV ToneMap Writer has NULL Pointer Member Call

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a NULL pointer member call vulnerability. This vulnerability affects users of the iccDEV libra…

πŸ“… Published: Jan. 6, 2026, 8:23 p.m. πŸ”„ Last Modified: April 18, 2026, 8:15 a.m.

5.3

CVSS4.0

CVE-2025-7048 - On affected platforms running Arista EOS with MACsec configuration, a specially crafted packet can …

On affected platforms running Arista EOS with MACsec configuration, a specially crafted packet can cause the MACsec process to terminate unexpectedly. Continuous receipt of these packets with certain MACsec configurations can cause longer term disruption of dataplane traffic.

πŸ“… Published: Jan. 6, 2026, 7:15 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2026-21491 - iccDEV has unicode buffer overflow in CIccTagTextDescription

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. A vulnerability present in versions prior to 2.3.1.2 affects users of the iccDEV library who process ICC color profiles. It r…

πŸ“… Published: Jan. 6, 2026, 7:07 p.m. πŸ”„ Last Modified: April 18, 2026, 8:15 a.m.

6.1

CVSS3.1

CVE-2026-21490 - iccDEV has heap buffer overflow in CIccTagLut16::Validate()

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. A vulnerability present in versions prior to 2.3.1.2 affects users of the iccDEV library who process ICC color profiles. It r…

πŸ“… Published: Jan. 6, 2026, 7:04 p.m. πŸ”„ Last Modified: April 18, 2026, 8:15 p.m.

5.3

CVSS4.0

CVE-2026-0641 - TOTOLINK WA300 cstecgi.cgi sub_401510 command injection

A security vulnerability has been detected in TOTOLINK WA300 5.2cu.7112_B20190227. This vulnerability affects the function sub_401510 of the file cstecgi.cgi. The manipulation of the argument UPLOAD_FILENAME leads to command injection. The attack may be initiated remotely. The exploit has been disc…

πŸ“… Published: Jan. 6, 2026, 7:02 p.m. πŸ”„ Last Modified: April 18, 2026, 8:15 p.m.

6.1

CVSS3.1

CVE-2026-21494 - iccDEV has heap buffer overflow in CIccTagLut8::Validate()

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. A vulnerability present in versions prior to 2.3.1.2 affects users of the iccDEV library who process ICC color profiles. It r…

πŸ“… Published: Jan. 6, 2026, 7 p.m. πŸ”„ Last Modified: April 18, 2026, 8:15 a.m.
Total resulsts: 349182
Page 2266 of 34,919
Β« previous page Β» next page
Filters