6.5

CVSS3.1

CVE-2025-14157 - Allocation of Resources Without Limits or Throttling in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 6.3 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to cause a Denial of Service condition by sending crafted API calls with large content parameters.

๐Ÿ“… Published: Dec. 11, 2025, 3:33 a.m. ๐Ÿ”„ Last Modified: Dec. 23, 2025, 9:05 p.m.

6.4

CVSS3.1

CVE-2025-9436 - Widgets for Google Reviews <= 13.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting viaโ€ฆ

The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `trustindex` shortcode in all versions up to, and including, 13.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for auโ€ฆ

๐Ÿ“… Published: Dec. 11, 2025, 3:27 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 1 a.m.

6.5

CVSS3.1

CVE-2025-10163 - List Category Posts <= 0.91.0 - Authenticated (Contributor+) SQL Injection via Plugin's Shortcode

The List category posts plugin for WordPress is vulnerable to time-based SQL Injection via the โ€˜starting_withโ€™ parameter of the catlist shortcode in all versions up to, and including, 0.91.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existiโ€ฆ

๐Ÿ“… Published: Dec. 11, 2025, 3:27 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9 p.m.

2.3

CVSS4.0

CVE-2025-14485 - EFM ipTIME A3004T Administrator Password timepro.cgi show_debug_screen command injection

A weakness has been identified in EFM ipTIME A3004T 14.19.0. This vulnerability affects the function show_debug_screen of the file /sess-bin/timepro.cgi of the component Administrator Password Handler. This manipulation of the argument aaksjdkfj with the input !@dnjsrureljrm*& causes command injectโ€ฆ

๐Ÿ“… Published: Dec. 11, 2025, 3:02 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-13764 - WP CarDealer <= 1.2.16 - Unauthenticated Privilege Escalation

The WP CarDealer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.16. This is due to the 'WP_CarDealer_User::process_register' function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers โ€ฆ

๐Ÿ“… Published: Dec. 11, 2025, 1:55 a.m. ๐Ÿ”„ Last Modified: April 20, 2026, 9:45 p.m.

5.8

CVSS3.1

CVE-2025-11467 - RSS Aggregator by Feedzy โ€“ Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 5.1โ€ฆ

The RSS Aggregator by Feedzy โ€“ Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 5.1.1 via the feedzy_lazy_load function. This makes it possible for unauthenticated attackerโ€ฆ

๐Ÿ“… Published: Dec. 11, 2025, 1:55 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 12:30 p.m.

6.5

CVSS3.1

CVE-2025-67720 - Pyrofork has a Path Traversal in download_media Method

Pyrofork is a modern, asynchronous MTProto API framework. Versions 2.3.68 and earlier do not properly sanitize filenames received from Telegram messages in the download_media method before using them in file path construction. When downloading media, if the user does not specify a custom filename (โ€ฆ

๐Ÿ“… Published: Dec. 11, 2025, 1:25 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2025-67719 - Ibexa User Bundle is missing password change validation

Ibexa is a composable end-to-end DXP (Digital Experience Platform). Versions 5.0.0-beta1 through 5.0.3 do not have password validation. During the transition from v4 to v5 an error was introduced into validation code which causes the validation of the previous password not to run as expected. This โ€ฆ

๐Ÿ“… Published: Dec. 11, 2025, 1:16 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-67718 - Formio improperly authorized permission elevation through specially crafted request path

Form.io is a combined Form and API platform for Serverless applications. Versions 3.5.6 and below and 4.0.0-rc.1 through 4.4.2 contain a flaw in path handling which could allow an attacker to access protected API endpoints by sending a crafted request path. An unauthenticated or unauthorized requesโ€ฆ

๐Ÿ“… Published: Dec. 11, 2025, 12:58 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-67717 - Zitadel Discloses the Total Number of Instance Users

ZITADEL is an open-source identity infrastructure tool. Versions 2.44.0 through 3.4.4 and 4.0.0-rc.1 through 4.7.1 disclose the total number of instance users to authenticated users, regardless of their specific permissions. While this does not leak individual user data or PII, disclosing the totalโ€ฆ

๐Ÿ“… Published: Dec. 11, 2025, 12:30 a.m. ๐Ÿ”„ Last Modified: Feb. 2, 2026, 3:10 p.m.
Total resulsts: 346624
Page 2409 of 34,663
ยซ previous page ยป next page
Filters