7.5

CVSS3.1

CVE-2025-12633 - Booking Calendar | Appointment Booking | Bookit <= 2.5.0 - Missing Authorization to Unauthenticated…

The Booking Calendar | Appointment Booking | Bookit plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '/wp-json/bookit/v1/commerce/stripe/return' REST API Endpoint in all versions up to, and including, 2.5.0. This makes it possible for…

πŸ“… Published: Nov. 12, 2025, 7:27 a.m. πŸ”„ Last Modified: Nov. 14, 2025, 3:26 p.m.

7.1

CVSS3.1

CVE-2025-11560 - Team Members Showcase < 3.5.0 - Reflected XSS

The Team Members Showcase WordPress plugin before 3.5.0 does not sanitize and escape a parameter before outputting it back in the page, leading to reflected cross-site scripting, which could be used against high-privilege users such as admins.

πŸ“… Published: Nov. 12, 2025, 6 a.m. πŸ”„ Last Modified: Dec. 19, 2025, 7:15 p.m.

4.3

CVSS3.1

CVE-2025-12901 - Asgaros Forum <= 3.2.1 - Cross-Site Request Forgery to Subscription Settings Update

The Asgaros Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.1. This is due to missing nonce validation on the set_subscription_level() function. This makes it possible for unauthenticated attackers to modify the subscription settings …

πŸ“… Published: Nov. 12, 2025, 4:29 a.m. πŸ”„ Last Modified: Nov. 14, 2025, 3:26 p.m.

4.3

CVSS3.1

CVE-2025-12833 - GeoDirectory – WP Business Directory Plugin and Classified Listings Directory <= 2.8.139 - Missing …

The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.8.139 via the 'post_attachment_upload' function due to missing validation on a user controlled key. This m…

πŸ“… Published: Nov. 12, 2025, 4:29 a.m. πŸ”„ Last Modified: Nov. 12, 2025, 6:16 p.m.

4.3

CVSS3.1

CVE-2025-12087 - Wishlist and Save for later for Woocommerce <= 1.1.22 - Insecure Direct Object Reference to Authent…

The Wishlist and Save for later for Woocommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.22 via the 'awwlm_remove_added_wishlist_page' AJAX action due to missing validation on a user controlled key. This makes it possible for a…

πŸ“… Published: Nov. 12, 2025, 4:29 a.m. πŸ”„ Last Modified: Nov. 12, 2025, 6:33 p.m.

5.2

CVSS3.1

CVE-2025-54983 - Health check port on ZCC allows tunnel bypass

A health check port on Zscaler Client Connector on Windows, versions 4.6 < 4.6.0.216 and 4.7 < 4.7.0.47, which under specific circumstances was not released after use, allowed traffic to potentially bypass ZCC forwarding controls.

πŸ“… Published: Nov. 12, 2025, 3:07 a.m. πŸ”„ Last Modified: Nov. 12, 2025, 6:18 p.m.

4

CVSS3.1

CVE-2025-43205 -

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to bypass ASLR.

πŸ“… Published: Nov. 12, 2025, 12:20 a.m. πŸ”„ Last Modified: April 2, 2026, 7:20 p.m.

5.5

CVSS3.1

CVE-2025-40188 - pwm: berlin: Fix wrong register in suspend/resume

In the Linux kernel, the following vulnerability has been resolved: pwm: berlin: Fix wrong register in suspend/resume The 'enable' register should be BERLIN_PWM_EN rather than BERLIN_PWM_ENABLE, otherwise, the driver accesses wrong address, there will be cpu exception then kernel panic during sus…

πŸ“… Published: Nov. 12, 2025, midnight πŸ”„ Last Modified: Dec. 1, 2025, 6:19 a.m.

5.5

CVSS3.1

CVE-2025-40205 - btrfs: avoid potential out-of-bounds in btrfs_encode_fh()

In the Linux kernel, the following vulnerability has been resolved: btrfs: avoid potential out-of-bounds in btrfs_encode_fh() The function btrfs_encode_fh() does not properly account for the three cases it handles. Before writing to the file handle (fh), the function only returns to the user BTR…

πŸ“… Published: Nov. 12, 2025, midnight πŸ”„ Last Modified: Dec. 1, 2025, 6:20 a.m.

7.0

CVSS3.1

CVE-2025-40187 - net/sctp: fix a null dereference in sctp_disposition sctp_sf_do_5_1D_ce()

In the Linux kernel, the following vulnerability has been resolved: net/sctp: fix a null dereference in sctp_disposition sctp_sf_do_5_1D_ce() If new_asoc->peer.adaptation_ind=0 and sctp_ulpevent_make_authkey=0 and sctp_ulpevent_make_authkey() returns 0, then the variable ai_ev remains zero and th…

πŸ“… Published: Nov. 12, 2025, midnight πŸ”„ Last Modified: Dec. 1, 2025, 6:19 a.m.
Total resulsts: 342375
Page 2361 of 34,238
Β« previous page Β» next page
Filters