4.2

CVSS3.1

CVE-2025-58412 -

A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiADC 8.0.0, FortiADC 7.6.0 through 7.6.3, FortiADC 7.4 all versions, FortiADC 7.2 all versions may allow attacker to execute unauthorized code or commands via crafted URL.

πŸ“… Published: Nov. 19, 2025, 9:49 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:21 p.m.

7.3

CVSS4.0

CVE-2025-11446 -

Insertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manager allows Use of Known Domain Credentials.This issue affects upKeeper Manager: from 5.2.0 before 5.2.12.

πŸ“… Published: Nov. 19, 2025, 8:53 a.m. πŸ”„ Last Modified: Dec. 2, 2025, 8:32 p.m.

8

CVSS3.1

CVE-2025-13035 - Code Snippets <= 3.9.1 - Authenticated (Contributor+) PHP Code Injection via extract() and PHP Filt…

The Code Snippets plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.9.1. This is due to the plugin's use of extract() on attacker-controlled shortcode attributes within the `evaluate_shortcode_from_flat_file` method, which can be used to overwrite the …

πŸ“… Published: Nov. 19, 2025, 7:46 a.m. πŸ”„ Last Modified: Nov. 21, 2025, 9:16 a.m.

7.2

CVSS3.1

CVE-2025-13206 - GiveWP - Donation Plugin and Fundraising Platform <= 4.13.0 - Unauthenticated Stored Cross-Site Scr…

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜name’ parameter in all versions up to, and including, 4.13.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attack…

πŸ“… Published: Nov. 19, 2025, 7:46 a.m. πŸ”„ Last Modified: Nov. 26, 2025, 4:22 p.m.

7.2

CVSS3.1

CVE-2025-12484 - Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Fol…

The Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple social media username parameters in all versions up to, and including, 1.12.19 due to insufficient input sanit…

πŸ“… Published: Nov. 19, 2025, 7:46 a.m. πŸ”„ Last Modified: Nov. 20, 2025, 10:30 a.m.

8.3

CVSS4.0

CVE-2025-11243 - Allocation of Resources Without Limits or Throttling in Shelly Pro 4PM

Allocation of Resources Without Limits or Throttling vulnerability in Shelly Pro 4PM (before v1.6) allows Excessive Allocation via network.

πŸ“… Published: Nov. 19, 2025, 6:50 a.m. πŸ”„ Last Modified: Nov. 21, 2025, 6:15 p.m.

8.3

CVSS4.0

CVE-2025-12056 - Out-of-bounds Read in Shelly Pro 3EM

Out-of-bounds Read in Shelly Pro 3EMΒ (before v1.4.4) allows Overread Buffers.

πŸ“… Published: Nov. 19, 2025, 6:46 a.m. πŸ”„ Last Modified: Nov. 21, 2025, 6:15 p.m.

5.3

CVSS3.1

CVE-2025-12535 - SureForms <= 1.13.1 - Cross-Site Request Forgery Protection Bypass via Improper Nonce Distribution

The SureForms plugin for WordPress is vulnerable to Cross-Site Request Forgery Bypass in all versions up to, and including, 1.13.1. This is due to the plugin distributing generic WordPress REST API nonces (wp_rest) to unauthenticated users via the 'wp_ajax_nopriv_rest-nonce' action. While the plugi…

πŸ“… Published: Nov. 19, 2025, 6:45 a.m. πŸ”„ Last Modified: Nov. 20, 2025, 10:30 a.m.

4.3

CVSS3.1

CVE-2025-13085 - SiteSEO – SEO Simplified <= 1.3.2 - Insecure Direct Object Reference to Sensitive Post Meta Disclos…

The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to Improper Authorization leading to Sensitive Post Meta Disclosure in versions up to and including 1.3.2. This is due to missing object-level authorization checks in the resolve_variables() AJAX handler. This makes it possible for aut…

πŸ“… Published: Nov. 19, 2025, 6:45 a.m. πŸ”„ Last Modified: Nov. 20, 2025, 10:30 a.m.

9.8

CVSS3.1

CVE-2025-12057 - WavePlayer < 3.8.0 - Unauthenticated Arbitrary File Upload

The WavePlayer WordPress plugin before 3.8.0 does not have authorization in an AJAX action as well as does not validate the file to be copied locally, allowing unauthenticated users to upload arbitrary file on the server and lead to RCE

πŸ“… Published: Nov. 19, 2025, 6 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 9:16 p.m.
Total resulsts: 342254
Page 2272 of 34,226
Β« previous page Β» next page
Filters