8.1

CVSS3.1

CVE-2025-13516 - SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers <= 1.9.0 - Una…

The SureMail – SMTP and Email Logs Plugin for WordPress is vulnerable to Unrestricted Upload of File with Dangerous Type in versions up to and including 1.9.0. This is due to the plugin's save_file() function in inc/emails/handler/uploads.php which duplicates all email attachments to a web-accessib…

📅 Published: Dec. 2, 2025, 8:24 a.m. 🔄 Last Modified: April 8, 2026, 5:32 p.m.

7.5

CVSS3.1

CVE-2025-13724 - VikRentCar Car Rental Management System <= 1.4.4 - Authenticated (Author+) SQL Injection via 'month…

The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'month' parameter in all versions up to, and including, 1.4.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL q…

📅 Published: Dec. 2, 2025, 8:24 a.m. 🔄 Last Modified: April 8, 2026, 5 p.m.

6.3

CVSS3.1

CVE-2025-13534 - ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.2 - Authenticated (Contributor+) Privile…

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.3.2. This is due to missing authorization checks on the eh_crm_edit_agent AJAX action. This makes it possible for authenticated attackers, with …

📅 Published: Dec. 2, 2025, 8:24 a.m. 🔄 Last Modified: April 8, 2026, 4:45 p.m.

6.3

CVSS4.0

CVE-2025-10543 - paho.mqtt.golang: paho.mqtt.golang: Integer Overflow in UTF-8 String Encoding

In Eclipse Paho Go MQTT v3.1 library (paho.mqtt.golang) versions <=1.5.0 UTF-8 encoded strings, passed into the library, may be incorrectly encoded if their length exceeds 65535 bytes. This may lead to unexpected content in packets sent to the server (for example, part of an MQTT topic may leak int…

📅 Published: Dec. 2, 2025, 8:18 a.m. 🔄 Last Modified: Jan. 16, 2026, 9:22 p.m.

8.8

CVSS4.0

CVE-2025-10971 - Insecure Storage of Sensitive Information

Insecure Storage of Sensitive Information vulnerability in MeetMe on iOS, Android allows Retrieve Embedded Sensitive Data. This issue affects MeetMe: through v2.2.5.

📅 Published: Dec. 2, 2025, 7:55 a.m. 🔄 Last Modified: Dec. 4, 2025, 4:49 p.m.

4.3

CVSS3.1

CVE-2025-11726 - Beaver Builder – WordPress Page Builder <= 2.9.4 - Missing Authorization to Authenticated (Contribu…

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.9.4. This is due to insufficient capability checks in the REST API endpoints under the 'fl-controls/v1' namespace that control site-wide Global Presets. Th…

📅 Published: Dec. 2, 2025, 7:24 a.m. 🔄 Last Modified: April 8, 2026, 5:17 p.m.

5.3

CVSS3.1

CVE-2025-13696 - Zigaform <= 7.6.5 - Unauthenticated Form Submission Data Disclosure in rocket_front_payment_seesumm…

The Zigaform plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.6.5. This is due to the plugin exposing a public AJAX endpoint that retrieves form submission data without performing authorization checks to verify ownership or access rights. This…

📅 Published: Dec. 2, 2025, 7:24 a.m. 🔄 Last Modified: April 8, 2026, 4:50 p.m.

9

CVSS3.1

CVE-2025-12548 - Github.com/che-incubator/che-code: eclipse che — unauthenticated rce and secret exfiltration via tc…

A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command execution and secret exfiltration (SSH keys, tokens, etc.) from other users' Developer Workspace containers, via an unauthenticated JSON-RPC / websocket API exposed on TCP port 3333.

📅 Published: Dec. 2, 2025, 7:07 a.m. 🔄 Last Modified: Jan. 21, 2026, 10:19 p.m.

6.5

CVSS3.1

CVE-2025-12483 - Visualizer: Tables and Charts Manager for WordPress <= 3.11.12 - Authenticated (Contributor+) SQL I…

The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'query' parameter in all versions up to, and including, 3.11.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL quer…

📅 Published: Dec. 2, 2025, 6:40 a.m. 🔄 Last Modified: April 8, 2026, 5:09 p.m.

4.3

CVSS3.1

CVE-2025-13140 - SurveyJS: Drag & Drop WordPress Form Builder <= 1.12.20 - Cross-Site Request Forgery to Survey Dele…

The SurveyJS: Drag & Drop WordPress Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.12.20. This is due to missing nonce validation on the SurveyJS_DeleteSurvey AJAX action. This makes it possible for unauthenticated attackers to …

📅 Published: Dec. 2, 2025, 6:40 a.m. 🔄 Last Modified: April 8, 2026, 4:55 p.m.
Total resulsts: 343942
Page 2330 of 34,395
« previous page » next page
Filters