5.3

CVSS3.1

CVE-2025-12585 - MxChat – AI Chatbot for WordPress <= 2.5.5 - Unauthenticated Information Exposure

The MxChat – AI Chatbot for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.5 via upload filenames. This makes it possible for unauthenticated attackers to extract session values that can subsequently be used to access convers…

📅 Published: Dec. 3, 2025, 3:27 a.m. 🔄 Last Modified: April 8, 2026, 6:23 p.m.

4.9

CVSS3.1

CVE-2025-13495 - FluentCart A New Era of eCommerce <= 1.3.1 - Authenticated (Administrator+) SQL Injection via 'grou…

The FluentCart plugin for WordPress is vulnerable to SQL Injection via the 'groupKey' parameter in all versions up to, and including, 1.3.1. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for a…

📅 Published: Dec. 3, 2025, 3:27 a.m. 🔄 Last Modified: April 8, 2026, 4:41 p.m.

7.5

CVSS3.1

CVE-2025-13646 - Modula 2.13.1 - 2.13.2 - Authenticated (Author+) Arbitrary File Upload via Race Condition

The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ajax_unzip_file' function in versions 2.13.1 to 2.13.2. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files…

📅 Published: Dec. 3, 2025, 2:25 a.m. 🔄 Last Modified: Dec. 15, 2025, 3:41 p.m.

6.4

CVSS3.1

CVE-2025-13448 - CSSIgniter Shortcodes <= 2.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'elem…

The CSSIgniter Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'element' shortcode attribute in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contribu…

📅 Published: Dec. 3, 2025, 2:25 a.m. 🔄 Last Modified: April 8, 2026, 4:43 p.m.

7.2

CVSS3.1

CVE-2025-13645 - Modula 2.13.1 - 2.13.2 - Authenticated (Author+) Arbitrary File Deletion

The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'ajax_unzip_file' function in versions 2.13.1 to 2.13.2. This makes it possible for authenticated attackers, with Author-level access and above, to delete arbitrary…

📅 Published: Dec. 3, 2025, 2:25 a.m. 🔄 Last Modified: Dec. 15, 2025, 3:39 p.m.

5.3

CVSS3.1

CVE-2025-53965 -

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. The function used to decode the SOR transparent container lacks bounds checking, …

📅 Published: Dec. 3, 2025, midnight 🔄 Last Modified: Dec. 5, 2025, 5:01 p.m.

7.7

CVSS3.1

CVE-2025-65843 -

Aquarius Desktop 3.0.069 for macOS contains an insecure file handling vulnerability in its support data archive generation feature. The application follows symbolic links placed inside the ~/Library/Logs/Aquarius directory and treats them as regular files. When building the support ZIP, Aquarius re…

📅 Published: Dec. 3, 2025, midnight 🔄 Last Modified: Dec. 18, 2025, 8:34 p.m.

7.5

CVSS3.1

CVE-2025-54326 -

An issue was discovered in Camera in Samsung Mobile Processor Exynos 1280 and 2200. Unnecessary registration of a hardware IP address in the Camera device driver can lead to a NULL pointer dereference, resulting in a denial of service.

📅 Published: Dec. 3, 2025, midnight 🔄 Last Modified: Dec. 5, 2025, 4:59 p.m.

7.8

CVSS3.1

CVE-2025-53841 -

The GC-AGENTS-SERVICE running as part of Akamai´s Guardicore Platform Agent for Windows versions prior to v49.20.1, v50.15.0, v51.12.0, v52.2.0 is affected by a local privilege escalation vulnerability. The service will attempt to read an OpenSSL configuration file from a non-existent location that…

📅 Published: Dec. 3, 2025, midnight 🔄 Last Modified: Dec. 10, 2025, 8:16 p.m.

7.8

CVSS3.1

CVE-2025-66431 -

WebPros Plesk before 18.0.73.5 and 18.0.74 before 18.0.74.2 on Linux allows remote authenticated users to execute arbitrary code as root via domain creation. The attacker needs "Create and manage sites" with "Domains management" and "Subdomains management."

📅 Published: Dec. 3, 2025, midnight 🔄 Last Modified: Dec. 4, 2025, 5:15 p.m.
Total resulsts: 343975
Page 2322 of 34,398
« previous page » next page
Filters