4.9

CVSS3.1

CVE-2025-13090 - WP Directory Kit <= 1.4.6 - Authenticated (Admin+) SQL Injection

The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'search' parameter in all versions up to, and including, 1.4.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authe…

📅 Published: Dec. 2, 2025, 11:20 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS4.0

CVE-2025-13353 - gokey allows secret recovery from a seed file without the master password

In gokey versions <0.2.0, a flaw in the seed decryption logic resulted in passwords incorrectly being derived solely from the initial vector and the AES-GCM authentication tag of the key seed. This issue has been fixed in gokey version 0.2.0. This is a breaking change. The fix has invalidated …

📅 Published: Dec. 2, 2025, 11:03 a.m. 🔄 Last Modified: Dec. 15, 2025, 3:31 p.m.

9.8

CVSS3.1

CVE-2025-41742 - Sprecher Automation: SPRECON-E series has a critical vulnerability due to the use of static cryptog…

Sprecher Automations SPRECON-E-C,  SPRECON-E-P, SPRECON-E-T3 is vulnerable to attack by an unauthorized remote attacker via default cryptographic keys. The use of these keys allows the attacker to read, modify, and write projects and data, or to access any device via remote maintenance.

📅 Published: Dec. 2, 2025, 10:39 a.m. 🔄 Last Modified: Feb. 23, 2026, 5:15 p.m.

4

CVSS3.1

CVE-2025-41743 - Sprecher Automation: SPRECON-E series prone to weak encryption of update files

Insufficient encryption strength in Sprecher Automation SPRECON-E-C, SPRECON-E-P, and SPRECON-E-T3 allows a local unprivileged attacker to extract data from update images and thus obtain limited information about the architecture and internal processes.

📅 Published: Dec. 2, 2025, 10:38 a.m. 🔄 Last Modified: Feb. 23, 2026, 5:16 p.m.

9.1

CVSS3.1

CVE-2025-41744 - Sprecher Automation: SPRECON-E series has static default key material for TLS connections

Sprecher Automations SPRECON-E series uses default cryptographic keys that allow an unprivileged remote attacker to access all encrypted communications, thereby compromising confidentiality and integrity.

📅 Published: Dec. 2, 2025, 10:38 a.m. 🔄 Last Modified: Feb. 23, 2026, 5:15 p.m.

4.8

CVSS4.0

CVE-2025-13873 - The feature to import a survey is prone to stored Cross-Site Script attacks

Stored Cross-Site Scripting (XSS) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on web application allows an attacker to inject arbitrary JavaScript code, which executes in the browsing context of any visitor accessing the compromised survey.

📅 Published: Dec. 2, 2025, 9:56 a.m. 🔄 Last Modified: Dec. 4, 2025, 5:49 p.m.

2.1

CVSS4.0

CVE-2025-13872 - Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio

Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on Web-based platforms allows an attacker to force the server to perform HTTP GET requests via crafted import requests to an arbitrary destination.

📅 Published: Dec. 2, 2025, 9:51 a.m. 🔄 Last Modified: Dec. 4, 2025, 5:52 p.m.

2.3

CVSS4.0

CVE-2025-13871 - The feature to manage resources is prone to Cross-Site Request Forgery attacks

Cross-Site Request Forgery (CSRF) in the resource-management feature of ObjectPlanet Opinio 7.26 rev12562 allows to upload files on behalf of the connected users and then access such files without authentication.

📅 Published: Dec. 2, 2025, 9:42 a.m. 🔄 Last Modified: Dec. 4, 2025, 5:54 p.m.

3.1

CVSS3.1

CVE-2025-13870 - Unauthorized access and subscription vulnerability in Boards

Mattermost versions 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate the user permission when accessing the files and subscribing to the block in Boards, which allows an authenticated user to access other board files and was able to subscribe to the block from other boards that the user does …

📅 Published: Dec. 2, 2025, 9:28 a.m. 🔄 Last Modified: Dec. 3, 2025, 8:57 p.m.

8.1

CVSS3.1

CVE-2025-13516 - SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers <= 1.9.0 - Una…

The SureMail – SMTP and Email Logs Plugin for WordPress is vulnerable to Unrestricted Upload of File with Dangerous Type in versions up to and including 1.9.0. This is due to the plugin's save_file() function in inc/emails/handler/uploads.php which duplicates all email attachments to a web-accessib…

📅 Published: Dec. 2, 2025, 8:24 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 345142
Page 2449 of 34,515
« previous page » next page
Filters