8.6

CVSS4.0

CVE-2025-14884 - D-Link DIR-605 Firmware Update Service command injection

A vulnerability was detected in D-Link DIR-605 202WWB03. Affected by this issue is some unknown functionality of the component Firmware Update Service. Performing manipulation results in command injection. The attack can be initiated remotely. The exploit is now public and may be used. This vulnera…

πŸ“… Published: Dec. 18, 2025, 5:02 p.m. πŸ”„ Last Modified: Jan. 7, 2026, 8:15 p.m.

9.3

CVSS4.0

CVE-2025-14879 - Tenda WH450 HTTP Request onSSIDChange stack-based overflow

A weakness has been identified in Tenda WH450 1.0.0.18. Affected is an unknown function of the file /goform/onSSIDChange of the component HTTP Request Handler. This manipulation of the argument ssid_index causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploi…

πŸ“… Published: Dec. 18, 2025, 5:02 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:16 a.m.

5.4

CVSS3.1

CVE-2025-62960 - WordPress Construction Light theme <= 1.6.7 - Broken Access Control vulnerability

Missing Authorization vulnerability in sparklewpthemes Construction Light construction-light allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Construction Light: from n/a through <= 1.6.7.

πŸ“… Published: Dec. 18, 2025, 4:51 p.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

5.4

CVSS3.1

CVE-2025-62961 - WordPress Sparkle FSE theme <= 1.0.9 - Broken Access Control vulnerability

Missing Authorization vulnerability in sparklewpthemes Sparkle FSE sparkle-fse allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sparkle FSE: from n/a through <= 1.0.9.

πŸ“… Published: Dec. 18, 2025, 4:50 p.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

5

CVSS3.1

CVE-2025-62998 - WordPress WP AI CoPilot plugin <= 1.2.7 - Sensitive Data Exposure vulnerability

Insertion of Sensitive Information Into Sent Data vulnerability in WP Messiah WP AI CoPilot ai-co-pilot-for-wp allows Retrieve Embedded Sensitive Data.This issue affects WP AI CoPilot: from n/a through <= 1.2.7.

πŸ“… Published: Dec. 18, 2025, 4:49 p.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

5.3

CVSS3.1

CVE-2025-63002 - WordPress Sermon Manager plugin <= 2.30.0 - Broken Access Control vulnerability

Missing Authorization vulnerability in wpforchurch Sermon Manager sermon-manager-for-wordpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sermon Manager: from n/a through <= 2.30.0.

πŸ“… Published: Dec. 18, 2025, 4:46 p.m. πŸ”„ Last Modified: April 23, 2026, 3:34 p.m.

5.3

CVSS3.1

CVE-2025-63043 - WordPress Post Grid and Gutenberg Blocks plugin <= 2.3.23 - Insecure Direct Object References (IDOR…

Authorization Bypass Through User-Controlled Key vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.3.23.

πŸ“… Published: Dec. 18, 2025, 4:45 p.m. πŸ”„ Last Modified: April 23, 2026, 3:35 p.m.

6.5

CVSS3.1

CVE-2025-64235 - WordPress Tuturn plugin < 3.6 - Arbitrary File Download vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AmentoTech Tuturn allows Path Traversal.This issue affects Tuturn: from n/a before 3.6.

πŸ“… Published: Dec. 18, 2025, 4:43 p.m. πŸ”„ Last Modified: April 28, 2026, 4:14 p.m.

9.8

CVSS3.1

CVE-2025-64236 - WordPress Tuturn plugin < 3.6 - Broken Authentication vulnerability

Authentication Bypass Using an Alternate Path or Channel vulnerability in AmentoTech Tuturn allows Authentication Abuse.This issue affects Tuturn: from n/a before 3.6.

πŸ“… Published: Dec. 18, 2025, 4:21 p.m. πŸ”„ Last Modified: April 28, 2026, 4:14 p.m.

8.7

CVSS4.0

CVE-2025-14896 -

due to insufficient sanitazation in Vega’s `convert()` function when `safeMode` is enabled and the spec variable is an array. An attacker can craft a malicious Vega diagram specification that will allow them to send requests to any URL, including local file system paths, leading to exposure of sens…

πŸ“… Published: Dec. 18, 2025, 4:20 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 2511 of 34,919
Β« previous page Β» next page
Filters