5.3

CVSS3.1

CVE-2025-13956 - LearnPress โ€“ WordPress LMS Plugin <= 4.3.1 - Missing Authorization to Unauthenticated Orders Statisโ€ฆ

The LearnPress โ€“ WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the statistic function in all versions up to, and including, 4.3.1. This makes it possible for unauthenticated attackers to view the plugin's orders statisticโ€ฆ

๐Ÿ“… Published: Dec. 16, 2025, 4:31 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 12:45 a.m.

5.3

CVSS4.0

CVE-2025-14749 - Ningyuanda TC155 ONVIF PTZ Control device_service access control

A vulnerability was identified in Ningyuanda TC155 57.0.2.0. This impacts an unknown function of the file /onvif/device_service of the component ONVIF PTZ Control Interface. The manipulation leads to improper access controls. The attack requires being on the local network. The exploit is publicly aโ€ฆ

๐Ÿ“… Published: Dec. 16, 2025, 3:02 a.m. ๐Ÿ”„ Last Modified: Dec. 18, 2025, 9:24 p.m.

5.3

CVSS4.0

CVE-2025-14748 - Ningyuanda TC155 ONVIF Device Management Service device_service access control

A vulnerability was determined in Ningyuanda TC155 57.0.2.0. This affects an unknown function of the file /onvif/device_service of the component ONVIF Device Management Service. Executing manipulation of the argument FactoryDefault with the input Hard can lead to improper access controls. The attacโ€ฆ

๐Ÿ“… Published: Dec. 16, 2025, 3:02 a.m. ๐Ÿ”„ Last Modified: Dec. 18, 2025, 9:24 p.m.

8.1

CVSS4.0

CVE-2025-59385 - QTS, QuTS hero

An authentication bypass by spoofing vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to access resources which are not otherwise accessible without proper authentication. We have already fixed the vulnerabiliโ€ฆ

๐Ÿ“… Published: Dec. 16, 2025, 2:25 a.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 4:07 p.m.

6.6

CVSS4.0

CVE-2025-62847 - QTS, QuTS hero

An improper neutralization of argument delimiters in a command vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to alter execution logic. We have already fixed the vulnerability in the following versions: QTS โ€ฆ

๐Ÿ“… Published: Dec. 16, 2025, 2:25 a.m. ๐Ÿ”„ Last Modified: March 18, 2026, 1:05 p.m.

8.1

CVSS4.0

CVE-2025-62848 - QTS, QuTS hero

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3297 build 2โ€ฆ

๐Ÿ“… Published: Dec. 16, 2025, 2:25 a.m. ๐Ÿ”„ Last Modified: March 18, 2026, 3:55 a.m.

5.2

CVSS4.0

CVE-2025-62849 - QTS, QuTS hero

An SQL injection vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3297 build 20251024 and โ€ฆ

๐Ÿ“… Published: Dec. 16, 2025, 2:24 a.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 4:07 p.m.

5.3

CVSS4.0

CVE-2025-14747 - Ningyuanda TC155 RTSP Service denial of service

A vulnerability was found in Ningyuanda TC155 57.0.2.0. The impacted element is an unknown function of the component RTSP Service. Performing manipulation results in denial of service. The attack must originate from the local network. The exploit has been made public and could be used. The vendor wโ€ฆ

๐Ÿ“… Published: Dec. 16, 2025, 2:02 a.m. ๐Ÿ”„ Last Modified: Dec. 18, 2025, 9:23 p.m.

5.3

CVSS4.0

CVE-2025-14746 - Ningyuanda TC155 RTSP Live Video Stream Endpoint improper authentication

A vulnerability has been found in Ningyuanda TC155 57.0.2.0. The affected element is an unknown function of the component RTSP Live Video Stream Endpoint. Such manipulation leads to improper authentication. The attack must be carried out from within the local network. The exploit has been disclosedโ€ฆ

๐Ÿ“… Published: Dec. 16, 2025, 2:02 a.m. ๐Ÿ”„ Last Modified: Dec. 18, 2025, 9:23 p.m.

5.3

CVSS4.0

CVE-2025-68115 - Parse Server vulnerable to Cross-Site Scripting (XSS) via Unescaped Mustache Template Variables

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 8.6.1 and 9.1.0-alpha.3, a Reflected Cross-Site Scripting (XSS) vulnerability exists in Parse Server's password reset and email verification HTML pages. The patch, available โ€ฆ

๐Ÿ“… Published: Dec. 16, 2025, 12:56 a.m. ๐Ÿ”„ Last Modified: Jan. 2, 2026, 4:49 p.m.
Total resulsts: 347632
Page 2423 of 34,764
ยซ previous page ยป next page
Filters