6.5

CVSS3.1

CVE-2025-64355 - WordPress JetElements For Elementor plugin <= 2.7.12 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElements For Elementor allows DOM-Based XSS.This issue affects JetElements For Elementor: from n/a through 2.7.12.

πŸ“… Published: Dec. 18, 2025, 4:16 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 4:16 p.m.

6.5

CVSS3.1

CVE-2025-66058 - WordPress Post Grid and Gutenberg Blocks plugin <= 2.3.17 - Broken Access Control vulnerability

Missing Authorization vulnerability in PickPlugins Post Grid and Gutenberg Blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Grid and Gutenberg Blocks: from n/a through 2.3.17.

πŸ“… Published: Dec. 18, 2025, 4:15 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 4:15 p.m.

9.3

CVSS4.0

CVE-2025-14878 - Tenda WH450 HTTP Request wirelessRestart stack-based overflow

A security flaw has been discovered in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/wirelessRestart of the component HTTP Request Handler. The manipulation of the argument GO results in stack-based buffer overflow. The attack may be performed from remote. The exploit h…

πŸ“… Published: Dec. 18, 2025, 4:02 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 4:02 p.m.

6.9

CVSS4.0

CVE-2025-14877 - Campcodes Supplier Management System add_retailer.php sql injection

A vulnerability was identified in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /admin/add_retailer.php. The manipulation of the argument cmbAreaCode leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available…

πŸ“… Published: Dec. 18, 2025, 4:02 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 4:02 p.m.

5.3

CVSS3.1

CVE-2025-14823 - Certificate Signing Extension Returns Encrypted Values

In deployments using the ScreenConnectβ„’ Certificate Signing Extension, encrypted configuration values including an Azure Key Vault-related key, could be returned to unauthenticated users through a client-facing endpoint under certain conditions. The values remained encrypted and securely stored at …

πŸ“… Published: Dec. 18, 2025, 3:50 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 3:50 p.m.

2

CVSS4.0

CVE-2025-68469 - ImageMagick vulnerable to heap-buffer-overflow

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.1-14, ImageMagick crashes when processing a crafted TIFF file. Version 7.1.1-14 fixes the issue.

πŸ“… Published: Dec. 18, 2025, 3:36 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 6 p.m.

7.3

CVSS4.0

CVE-2025-68278 - tinacms vulnerable to arbitrary code execution

Tina is a headless content management system. In tinacms prior to version 3.1.1, tinacms uses the gray-matter package in an insecure way allowing attackers that can control the content of the processed markdown files, e.g., blog posts, to execute arbitrary code. tinacms version 3.1.1, @tinacms/cli …

πŸ“… Published: Dec. 18, 2025, 3:27 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 3:27 p.m.

4.8

CVSS4.0

CVE-2025-64724 - Arduino IDE for macOS has Insecure File Permissions

Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS is installed with world-writable file permissions on sensitive application components, allowing any local user to replace legitimate files with malicious code. When another user launches the applicat…

πŸ“… Published: Dec. 18, 2025, 3:18 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 3:18 p.m.

4.8

CVSS4.0

CVE-2025-64723 - Arduino IDE for macOS has TCC Bypass via Dynamic Library Injection

Arduino IDE is an integrated development environment. Prior to version 2.3.7, Arduino IDE for macOS was configured with overly permissive security entitlements that could bypass macOS Hardened Runtime protections. This configuration allows attackers to inject malicious dynamic libraries into the ap…

πŸ“… Published: Dec. 18, 2025, 3:15 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 3:15 p.m.

7.1

CVSS4.0

CVE-2025-65011 - Unauthorized Access to files in WODESYS WD-R608U router

In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) an unauthorised user can view configuration files by directly referencing the resource in question. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version r…

πŸ“… Published: Dec. 18, 2025, 3:10 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 3:10 p.m.
Total resulsts: 323511
Page 24 of 32,352
Β« previous page Β» next page
Filters