5.3

CVSS3.1

CVE-2025-68505 - WordPress H5P plugin <= 1.16.1 - Broken Access Control vulnerability

Missing Authorization vulnerability in icc0rz H5P h5p allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects H5P: from n/a through <= 1.16.1.

πŸ“… Published: Dec. 24, 2025, 12:31 p.m. πŸ”„ Last Modified: April 24, 2026, 6:59 p.m.

4.9

CVSS3.1

CVE-2025-68500 - WordPress Prime Slider – Addons For Elementor plugin <= 4.0.10 - Server Side Request Forgery (SSRF)…

Server-Side Request Forgery (SSRF) vulnerability in bdthemes Prime Slider – Addons For Elementor bdthemes-prime-slider-lite allows Server Side Request Forgery.This issue affects Prime Slider – Addons For Elementor: from n/a through <= 4.0.10.

πŸ“… Published: Dec. 24, 2025, 12:31 p.m. πŸ”„ Last Modified: April 24, 2026, 7:09 p.m.

5.9

CVSS3.1

CVE-2025-68497 - WordPress Astra Widgets plugin <= 1.2.16 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Astra Widgets astra-widgets allows Stored XSS.This issue affects Astra Widgets: from n/a through <= 1.2.16.

πŸ“… Published: Dec. 24, 2025, 12:31 p.m. πŸ”„ Last Modified: April 24, 2026, 7:09 p.m.

7.6

CVSS3.1

CVE-2025-68496 - WordPress User Feedback plugin <= 1.10.0 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Syed Balkhi User Feedback userfeedback-lite allows Blind SQL Injection.This issue affects User Feedback: from n/a through <= 1.10.0.

πŸ“… Published: Dec. 24, 2025, 12:31 p.m. πŸ”„ Last Modified: April 24, 2026, 7:09 p.m.

5.3

CVSS3.1

CVE-2025-68494 - WordPress Premium Addons for Elementor plugin <= 4.11.53 - Sensitive Data Exposure vulnerability

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Leap13 Premium Addons for Elementor premium-addons-for-elementor allows Retrieve Embedded Sensitive Data.This issue affects Premium Addons for Elementor: from n/a through <= 4.11.53.

πŸ“… Published: Dec. 24, 2025, 12:31 p.m. πŸ”„ Last Modified: April 24, 2026, 7:09 p.m.

0.0

CVE-2023-54061 - x86: fix clear_user_rep_good() exception handling annotation

In the Linux kernel, the following vulnerability has been resolved: x86: fix clear_user_rep_good() exception handling annotation This code no longer exists in mainline, because it was removed in commit d2c95f9d6802 ("x86: don't use REP_GOOD or ERMS for user memory clearing") upstream. However, r…

πŸ“… Published: Dec. 24, 2025, 12:23 p.m. πŸ”„ Last Modified: Dec. 24, 2025, 1:16 p.m.

0.0

CVE-2023-54054 - scsi: qla2xxx: Fix buffer overrun

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix buffer overrun Klocwork warning: Buffer Overflow - Array Index Out of Bounds Driver uses fc_els_flogi to calculate size of buffer. The actual buffer is nested inside of fc_els_flogi which is smaller. Replace…

πŸ“… Published: Dec. 24, 2025, 12:23 p.m. πŸ”„ Last Modified: Dec. 24, 2025, 1:16 p.m.

4.1

CVSS3.1

CVE-2025-64641 - Mattermost Jira plugin crafted action leaks Jira issue details

Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fail to verify that post actions invoking /share-issue-publicly were created by the Jira plugin which allowed a malicious Mattermost user to exfiltrate Jira tickets when victim users interacted with affec…

πŸ“… Published: Dec. 24, 2025, 8:02 a.m. πŸ”„ Last Modified: Dec. 31, 2025, 6:55 p.m.

4.3

CVSS3.1

CVE-2025-13767 - Unauthorized Read Access to Private Channel Posts via Mattermost Jira Plugin

Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fails to validate user channel membership when attaching Mattermost posts as comments to Jira issues, which allows an authenticated attacker with access to the Jira plugin to read post content and attachm…

πŸ“… Published: Dec. 24, 2025, 8:01 a.m. πŸ”„ Last Modified: Dec. 31, 2025, 6:56 p.m.

2.2

CVSS3.1

CVE-2025-57840 - Privilege Bypass in ADB

ADB(Android Debug Bridge) is affected by type privilege bypass, successful exploitation of this vulnerability may affect service availability.

πŸ“… Published: Dec. 24, 2025, 6:55 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 2423 of 34,919
Β« previous page Β» next page
Filters