5.4

CVSS3.1

CVE-2025-14020 -

LINE client for Android versions prior to 14.20 contains a UI spoofing vulnerability in the in-app browser where the full-screen security Toast notification is not properly re-displayed when users return from another application, potentially allowing attackers to conduct phishing attacks by imperso…

πŸ“… Published: Dec. 15, 2025, 6:39 a.m. πŸ”„ Last Modified: Dec. 15, 2025, 6:22 p.m.

3.4

CVSS3.1

CVE-2025-14019 -

LINE client for Android versions from 13.8 to 15.5 is vulnerable to UI spoofing in the in-app browser where a specific layout could obscure the full-screen warning prompt, potentially allowing attackers to conduct phishing attacks.

πŸ“… Published: Dec. 15, 2025, 6:38 a.m. πŸ”„ Last Modified: Dec. 15, 2025, 6:22 p.m.

9.3

CVSS4.0

CVE-2025-14708 - Shiguangwu sgwbox N3 WIREDCFGGET http_eshell_server buffer overflow

A weakness has been identified in Shiguangwu sgwbox N3 2.0.25. Affected by this vulnerability is an unknown functionality of the file /usr/sbin/http_eshell_server of the component WIREDCFGGET Interface. Executing manipulation of the argument params can lead to buffer overflow. The attack may be lau…

πŸ“… Published: Dec. 15, 2025, 6:32 a.m. πŸ”„ Last Modified: Dec. 15, 2025, 6:22 p.m.

9.3

CVSS4.0

CVE-2025-14707 - Shiguangwu sgwbox N3 DOCKER Feature http_eshell_server command injection

A security flaw has been discovered in Shiguangwu sgwbox N3 2.0.25. Affected is an unknown function of the file /usr/sbin/http_eshell_server of the component DOCKER Feature. Performing manipulation of the argument params results in command injection. The attack may be initiated remotely. The exploi…

πŸ“… Published: Dec. 15, 2025, 6:02 a.m. πŸ”„ Last Modified: Dec. 15, 2025, 6:22 p.m.

7.1

CVSS3.1

CVE-2025-13355 - URL Shortify < 1.11.4 - Reflected XSS

The URL Shortify WordPress plugin before 1.11.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

πŸ“… Published: Dec. 15, 2025, 6 a.m. πŸ”„ Last Modified: Dec. 15, 2025, 6:22 p.m.

7.1

CVSS3.1

CVE-2025-12684 - URL Shortify < 1.11.3 - Reflected XSS

The URL Shortify WordPress plugin before 1.11.3 does not sanitize and escape a parameter before outputting it back in the page, leading to a reflected cross site scripting, which could be used against high-privilege users such as admins.

πŸ“… Published: Dec. 15, 2025, 6 a.m. πŸ”„ Last Modified: Dec. 15, 2025, 6:22 p.m.

5.3

CVSS3.1

CVE-2025-11363 - Royal Elementor Addons and Templates < 1.7.1037 - Unauthenticated Media File Upload

The Royal Addons for Elementor WordPress plugin before 1.7.1037 does not have proper authorisation, allowing unauthenticated users to upload media files via the wpr_addons_upload_file action.

πŸ“… Published: Dec. 15, 2025, 6 a.m. πŸ”„ Last Modified: Dec. 15, 2025, 6:22 p.m.

8.7

CVSS4.0

CVE-2025-14712 - JHENG GAO|Student Learning Assessment and Support System - Exposure of Sensitive Information

Student Learning Assessment and Support System developed by JHENG GAO has a Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to view a specific page and obtain test accounts and password.

πŸ“… Published: Dec. 15, 2025, 5:37 a.m. πŸ”„ Last Modified: Dec. 15, 2025, 6:22 p.m.

6.9

CVSS4.0

CVE-2025-14549 - OMR on Z processors Exposing a possible buffer over-read problem

In the Eclipse OMR compiler component, since release 0.7.0, an optimization enabled for Eclipse OpenJ9 consumers of OMR on Z processors incorrectly handles NUL (0x00) characters during the Latin-compatible charset (UTF-8, ISO8859-1, ASCII, etc) to IBM-1047/037 translation sequence. This can cause t…

πŸ“… Published: Dec. 15, 2025, 5:32 a.m. πŸ”„ Last Modified: Dec. 15, 2025, 6:22 p.m.

9.3

CVSS4.0

CVE-2025-14706 - Shiguangwu sgwbox N3 NETREBOOT http_eshell_server command injection

A vulnerability was identified in Shiguangwu sgwbox N3 2.0.25. This impacts an unknown function of the file /usr/sbin/http_eshell_server of the component NETREBOOT Interface. Such manipulation leads to command injection. The attack can be launched remotely. The exploit is publicly available and mig…

πŸ“… Published: Dec. 15, 2025, 5:32 a.m. πŸ”„ Last Modified: Dec. 15, 2025, 6 p.m.
Total resulsts: 322536
Page 23 of 32,254
Β« previous page Β» next page
Filters