6.4

CVSS3.1

CVE-2025-12712 - Shouty <= 0.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via shouty Shortcode Attโ€ฆ

The Shouty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shouty shortcode in all versions up to, and including, 0.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contribuโ€ฆ

๐Ÿ“… Published: Nov. 27, 2025, 2:26 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:43 p.m.

6.4

CVSS3.1

CVE-2025-12666 - Google Drive upload and download link <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripโ€ฆ

The Google Drive upload and download link plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' parameter of the 'atachfilegoogle' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for auโ€ฆ

๐Ÿ“… Published: Nov. 27, 2025, 2:26 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:36 p.m.

4.3

CVSS3.1

CVE-2025-12578 - Reuters Direct <= 3.0.0 - Cross-Site Request Forgery to Settings Reset

The Reuters Direct plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.0. This is due to missing or incorrect nonce validation on the the 'class-reuters-direct-settings.php' page. This makes it possible for unauthenticated attackers to reset thโ€ฆ

๐Ÿ“… Published: Nov. 27, 2025, 2:26 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:35 p.m.

7.5

CVSS3.1

CVE-2025-66314 -

Improper Privilege Management vulnerability in ZTE ElasticNet UME R32 on Linux allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects ElasticNet UME R32: ElasticNet_UME_R32_V16.23.20.04.

๐Ÿ“… Published: Nov. 27, 2025, 2:08 a.m. ๐Ÿ”„ Last Modified: Dec. 1, 2025, 3:39 p.m.

6.9

CVSS4.0

CVE-2024-5540 - ALC WebCTRL Carrier i-Vu Reflected Cross-Site Scripting

The reflective cross-site scripting vulnerability found in ALC WebCTRL and Carrier i-Vu in versions older than 8.0 affects login panels allowing a malicious actor to compromise the client browser .

๐Ÿ“… Published: Nov. 27, 2025, 1:02 a.m. ๐Ÿ”„ Last Modified: Dec. 1, 2025, 3:39 p.m.

9.2

CVSS4.0

CVE-2024-5539 - ALC WebCTRL Carrier i-Vu Access Control Bypass

The Access Control Bypass vulnerability found in ALC WebCTRL and Carrier i-Vu in versions up to and including 8.5 allows a malicious actor to bypass intended access restrictions and expose sensitive information via the web based building automation server.

๐Ÿ“… Published: Nov. 27, 2025, 1:02 a.m. ๐Ÿ”„ Last Modified: Dec. 1, 2025, 3:39 p.m.

8.8

CVSS4.0

CVE-2025-0657 - ALC WebCTRL Carrier i-Vu and Gen5 Controllers Array Index out-of-range

A weakness in Automated Logic and Carrier i-Vu Gen5 router on driver version drv_gen5_106-01-2380, allows malformed packets to be sent through BACnet MS/TP network causing the devices to enter a fault state. This fault state requires a manual power cycle to return the device to network visibโ€ฆ

๐Ÿ“… Published: Nov. 27, 2025, 1 a.m. ๐Ÿ”„ Last Modified: Dec. 1, 2025, 3:39 p.m.

8.7

CVSS4.0

CVE-2025-0658 - Automated Logic and Carrier Zone Controllers malformed packets denial of service

A vulnerability in Automated Logic and Carrier's Zone Controllerย via BACnet protocol causes the device to crash. The device enters a fault state; after a reset, a second packet can leave it permanently unresponsive until a manual power cycle is performed.

๐Ÿ“… Published: Nov. 27, 2025, 1 a.m. ๐Ÿ”„ Last Modified: Dec. 1, 2025, 3:39 p.m.

6.9

CVSS4.0

CVE-2025-66361 -

An issue was discovered in Logpoint before 7.7.0. Sensitive information is exposed in System Processes for an extended period during high CPU load.

๐Ÿ“… Published: Nov. 27, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 3, 2025, 7:15 p.m.

6.9

CVSS4.0

CVE-2025-66360 -

An issue was discovered in Logpoint before 7.7.0. An improperly configured access control policy exposes sensitive Logpoint internal service (Redis) information to li-admin users. This can lead to privilege escalation.

๐Ÿ“… Published: Nov. 27, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 3, 2025, 7:12 p.m.
Total resulsts: 343761
Page 2350 of 34,377
ยซ previous page ยป next page
Filters