4.3

CVSS3.1

CVE-2025-14163 - Premium Addons for Elementor <= 4.11.53 - Cross-Site Request Forgery via 'insert_inner_template'

The Premium Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.11.53. This is due to missing nonce validation in the 'insert_inner_template' function. This makes it possible for unauthenticated attackers to create arbitrary …

πŸ“… Published: Dec. 23, 2025, 9:20 a.m. πŸ”„ Last Modified: April 21, 2026, 5 p.m.

6.4

CVSS3.1

CVE-2025-14548 - Calendar <= 1.3.16 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'event_desc'

The Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'event_desc' parameter in all versions up to, and including, 1.3.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access an…

πŸ“… Published: Dec. 23, 2025, 9:20 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-14155 - Premium Addons for Elementor <= 4.11.53 - Missing Authorization to Unauthenticated Sensitive Inform…

The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_template_content' function in all versions up to, and including, 4.11.53. This makes it possible for unauthentica…

πŸ“… Published: Dec. 23, 2025, 9:19 a.m. πŸ”„ Last Modified: April 22, 2026, 8:30 p.m.

6.9

CVSS4.0

CVE-2025-15034 - itsourcecode Student Management System record.php sql injection

A security flaw has been discovered in itsourcecode Student Management System 1.0. This affects an unknown part of the file /record.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be exploite…

πŸ“… Published: Dec. 23, 2025, 12:32 a.m. πŸ”„ Last Modified: Dec. 24, 2025, 3:04 p.m.

6.3

CVSS3.1

CVE-2025-67743 - Local Deep Research is Vulnerable to Server-Side Request Forgery (SSRF) in Download Service

Local Deep Research is an AI-powered research assistant for deep, iterative research. In versions from 1.3.0 to before 1.3.9, the download service (download_service.py) makes HTTP requests using raw requests.get() without utilizing the application's SSRF protection (safe_requests.py). This can allo…

πŸ“… Published: Dec. 23, 2025, 12:01 a.m. πŸ”„ Last Modified: Dec. 29, 2025, 4:08 p.m.

7.5

CVSS3.1

CVE-2025-67111 -

An integer overflow in the RTPS protocol implementation of OpenDDS DDS before v3.33.0 allows attackers to cause a Denial of Service (DoS) via a crafted message.

πŸ“… Published: Dec. 23, 2025, midnight πŸ”„ Last Modified: Jan. 6, 2026, 5:41 p.m.

5.5

CVSS3.1

CVE-2025-68341 - veth: reduce XDP no_direct return section to fix race

In the Linux kernel, the following vulnerability has been resolved: veth: reduce XDP no_direct return section to fix race As explain in commit fa349e396e48 ("veth: Fix race with AF_XDP exposing old or uninitialized descriptors") for veth there is a chance after napi_complete_done() that another C…

πŸ“… Published: Dec. 23, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2025-68339 - atm/fore200e: Fix possible data race in fore200e_open()

In the Linux kernel, the following vulnerability has been resolved: atm/fore200e: Fix possible data race in fore200e_open() Protect access to fore200e->available_cell_rate with rate_mtx lock in the error handling path of fore200e_open() to prevent a data race. The field fore200e->available_cell_…

πŸ“… Published: Dec. 23, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4

CVSS3.1

CVE-2025-65713 -

Home Assistant Core before v2025.8.0 is vulnerable to Directory Traversal. The Downloader integration does not fully validate file paths during concatenation, leaving a path traversal vulnerability.

πŸ“… Published: Dec. 23, 2025, midnight πŸ”„ Last Modified: Jan. 6, 2026, 5:27 p.m.

10

CVSS3.1

CVE-2025-67109 -

Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers to bypass certificate checks and execute commands with System privileges.

πŸ“… Published: Dec. 23, 2025, midnight πŸ”„ Last Modified: Jan. 6, 2026, 5:42 p.m.
Total resulsts: 349182
Page 2471 of 34,919
Β« previous page Β» next page
Filters