4.3

CVSS3.1

CVE-2025-54005 - WordPress SKT Page Builder plugin <= 4.9 - Broken Access Control vulnerability

Missing Authorization vulnerability in sonalsinha21 SKT Page Builder skt-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SKT Page Builder: from n/a through <= 4.9.

πŸ“… Published: Dec. 16, 2025, 8:12 a.m. πŸ”„ Last Modified: April 24, 2026, 7:30 p.m.

2.7

CVSS3.1

CVE-2025-54004 - WordPress WCFM – Frontend Manager for WooCommerce plugin <= 6.7.24 - Broken Access Control vulnerab…

Missing Authorization vulnerability in WC Lovers WCFM – Frontend Manager for WooCommerce wc-frontend-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WCFM – Frontend Manager for WooCommerce: from n/a through <= 6.7.24.

πŸ“… Published: Dec. 16, 2025, 8:12 a.m. πŸ”„ Last Modified: April 24, 2026, 7:30 p.m.

2.7

CVSS3.1

CVE-2025-49300 - WordPress Traveler Option Tree plugin <= 2.8 - Sensitive Data Exposure vulnerability

Insertion of Sensitive Information Into Sent Data vulnerability in shinetheme Traveler Option Tree custom-option-tree allows Retrieve Embedded Sensitive Data.This issue affects Traveler Option Tree: from n/a through <= 2.8.

πŸ“… Published: Dec. 16, 2025, 8:12 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-11991 - JetFormBuilder <= 3.5.3 - Missing Authorization to Unauthenticated Form Generation

The JetFormBuilder β€” Dynamic Blocks Form Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the run_callback function in all versions up to, and including, 3.5.3. This makes it possible for unauthenticated attackers to generate forms…

πŸ“… Published: Dec. 16, 2025, 7:21 a.m. πŸ”„ Last Modified: April 21, 2026, 12:45 a.m.

5.9

CVSS3.1

CVE-2025-13439 - Fancy Product Designer | WooCommerce WordPress <= 6.4.8 - Unauthenticated Information Disclosure an…

The Fancy Product Designer plugin for WordPress is vulnerable to Information Disclosure and PHAR Deserialization in all versions up to, and including, 6.4.8. This is due to insufficient validation of user-supplied input in the 'url' parameter of the 'fpd_custom_uplod_file' AJAX action, which flows …

πŸ“… Published: Dec. 16, 2025, 7:21 a.m. πŸ”„ Last Modified: April 21, 2026, 5:15 p.m.

8.6

CVSS4.0

CVE-2025-66635 -

Stack-based buffer overflow vulnerability exists in SEIKO EPSON Web Config. Specially crafted data input by a logged-in user may execute arbitrary code. As for the details of the affected products and versions, see the information provided by the vendor under [References].

πŸ“… Published: Dec. 16, 2025, 6:59 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS3.1

CVE-2025-62330 - HCL DevOps Deploy is susceptible to a cleartext transmission of sensitive information

HCL DevOps Deploy is susceptible to a cleartext transmission of sensitive information because the HTTP port remains accessible and does not redirect to HTTPS as intended. As a result, an attacker with network access could intercept or modify user credentials and session-related data via passive mo…

πŸ“… Published: Dec. 16, 2025, 6:16 a.m. πŸ”„ Last Modified: Jan. 7, 2026, 9:05 p.m.

5.3

CVSS3.1

CVE-2025-12809 - dokan pro <= 4.1.3 - Missing Authorization to Unauthenticated Sensitive Information Exposure

The Dokan Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the `/dokan/v1/wholesale/register` REST API endpoint in all versions up to, and including, 4.1.3. This makes it possible for unauthenticated attackers to enumerate users and retrieve…

πŸ“… Published: Dec. 16, 2025, 5:25 a.m. πŸ”„ Last Modified: April 22, 2026, 12:15 a.m.

4.3

CVSS3.1

CVE-2025-13794 - Auto Featured Image <= 4.2.1 - Missing Authorization to Authenticated (Contributor+) Post Thumbnail…

The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the bulk_action_generate_handler function in all versions up to, and including, 4.2.1. This makes it possible for authenticated attackers, with …

πŸ“… Published: Dec. 16, 2025, 5:25 a.m. πŸ”„ Last Modified: April 22, 2026, 4:15 p.m.

8.5

CVSS4.0

CVE-2025-14252 -

An Improper Access Control vulnerability in Advantech SUSI driver (susi.sys) allows attackers to read/write arbitrary memory, I/O ports, and MSRs, resulting in privilege escalation, arbitrary code execution, and information disclosure. This issue affects Advantech SUSI: 5.0.24335 and prior.

πŸ“… Published: Dec. 16, 2025, 5:19 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 347604
Page 2419 of 34,761
Β« previous page Β» next page
Filters