9.8

CVSS3.1

CVE-2025-13613 - Elated Membership <= 1.2 - Authentication Bypass via Social Login

The Elated Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.2. This is due to the plugin not properly logging in a user with the data that was previously verified through the 'eltdf_membership_check_facebook_user' and the 'eltdf_membersh…

πŸ“… Published: Dec. 10, 2025, 1:51 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2025-67507 - Filament's multi-factor authentication (app) recovery codes can be used multiple times

Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.3.0 contain a flaw in the handling of recovery codes for app-based multi-factor authentication, allowing the same recovery code to be reused indefinitely. This issue does not affect email…

πŸ“… Published: Dec. 10, 2025, 12:43 a.m. πŸ”„ Last Modified: March 4, 2026, 8:42 p.m.

9.8

CVSS3.1

CVE-2025-67506 - PipesHub Vulnerable to Path Traversal through Unauthenticated Arbitrary File Upload

PipesHub is a fully extensible workplace AI platform for enterprise search and workflow automation. Versions prior to 0.1.0-beta expose POST /api/v1/record/buffer/convert through missing authentication. The endpoint accepts a file upload and converts it to PDF via LibreOffice by uploading payload t…

πŸ“… Published: Dec. 10, 2025, 12:36 a.m. πŸ”„ Last Modified: March 17, 2026, 8:31 p.m.

5.3

CVSS3.1

CVE-2025-67485 - HTTP/HTTPS Traffic Interception Bypass in mad-proxy

mad-proxy is a Python-based HTTP/HTTPS proxy server for detection and blocking of malicious web activity using custom security policies. Versions 0.3 and below allow attackers to bypass HTTP/HTTPS traffic interception rules, potentially exposing sensitive traffic. This issue does not have a fix at …

πŸ“… Published: Dec. 10, 2025, 12:08 a.m. πŸ”„ Last Modified: March 9, 2026, 1:37 p.m.

6.8

CVSS3.1

CVE-2025-65822 -

The ESP32 system on a chip (SoC) that powers the Meatmeet Pro was found to have JTAG enabled. By leaving JTAG enabled on an ESP32 in a commercial product an attacker with physical access to the device can connect over this port and reflash the device's firmware with malicious code which will be exe…

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Jan. 21, 2026, 7:08 p.m.

9.1

CVSS3.1

CVE-2025-65792 -

DataGear v5.5.0 is vulnerable to Arbitrary File Deletion.

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 6:14 p.m.

6.5

CVSS3.1

CVE-2025-52493 -

PagerDuty Runbook through 2025-06-12 exposes stored secrets directly in the webpage DOM at the configuration page. Although these secrets appear masked as password fields, the actual secret values are present in the page source and can be revealed by simply modifying the input field type from "pass…

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 2:38 p.m.

9.8

CVSS3.1

CVE-2025-65820 -

An issue was discovered in Meatmeet Android Mobile Application 1.1.2.0. An exported activity can be spawned with the mobile application which opens a hidden page. This page, which is not available through the normal flows of the application, contains several devices which can be added to your accou…

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 8:03 p.m.

7.5

CVSS3.1

CVE-2025-63094 -

XiangShan Nanhu V2 and XiangShan Kunmighu V3 were discovered to use speculative execution and indirect branch prediction, allowing attackers to access sensitive information via side-channel analysis of the data cache.

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 9:23 p.m.

6.1

CVSS3.1

CVE-2025-56429 -

Cross Site Scripting vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to obtain sensitive information via the login.php component.

πŸ“… Published: Dec. 10, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 8:16 p.m.
Total resulsts: 345151
Page 2293 of 34,516
Β« previous page Β» next page
Filters