2.7

CVSS3.1

CVE-2025-64255 - WordPress Admin and Site Enhancements (ASE) plugin <= 8.0.8 - Broken Access Control vulnerability

Missing Authorization vulnerability in Bowo Admin and Site Enhancements (ASE) admin-site-enhancements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Admin and Site Enhancements (ASE): from n/a through <= 8.0.8.

📅 Published: Dec. 9, 2025, 2:13 p.m. 🔄 Last Modified: April 23, 2026, 3:35 p.m.

2.7

CVSS3.1

CVE-2025-64254 - WordPress Photo Block plugin <= 1.5.1 - Broken Access Control vulnerability

Missing Authorization vulnerability in Ronald Huereca Photo Block photo-block allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Photo Block: from n/a through <= 1.5.1.

📅 Published: Dec. 9, 2025, 2:13 p.m. 🔄 Last Modified: April 23, 2026, 3:35 p.m.

8.7

CVSS4.0

CVE-2025-9368 - 432ES-IG3 Series A Denial-of-Service Vulnerability

A security issue exists within 432ES-IG3 Series A, which affects GuardLink® EtherNet/IP Interface, resulting in denial-of-service. A manual power cycle is required to recover the device.

📅 Published: Dec. 9, 2025, 2:01 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-12807 - FactoryTalk® DataMosaix™ Private Cloud SQL Injection

A security issue was discovered in DataMosaix Private Cloud, allowing users with low privilege to perform sensitive database operations through exposed API endpoints.

📅 Published: Dec. 9, 2025, 1:56 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-12558 - Beaver Builder – WordPress Page Builder <= 2.9.4 - Authenticated (Contributor+) Sensitive Informati…

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4 via the 'get_attachment_sizes' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extra…

📅 Published: Dec. 9, 2025, 1:51 p.m. 🔄 Last Modified: April 22, 2026, 12:30 a.m.

7.2

CVSS3.1

CVE-2025-12705 - Social Reviews & Recommendations <= 2.5 - Unauthenticated Stored Cross-Site Scripting via Social Me…

The Social Reviews & Recommendations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in the 'trim_text' function in all versions up to, and including, 2.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated …

📅 Published: Dec. 9, 2025, 1:51 p.m. 🔄 Last Modified: April 22, 2026, 4 a.m.

5.3

CVSS3.1

CVE-2025-10876 - XSS in Talent Software's e-Bap

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Talent Software e-BAP Automation allows Cross-Site Scripting (XSS).This issue affects e-BAP Automation: from 1.8.96 before v.41815.

📅 Published: Dec. 9, 2025, 1:49 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS4.0

CVE-2025-12381 - Privilege Escalation via Misconfigured Sudoers Entry for Local Users in AlgoSec Firewall Analyzer

Improper Privilege Management vulnerability in AlgoSec Firewall Analyzer on Linux, 64 bit allows Privilege Escalation, Parameter Injection. A local user with access to the command line may escalate their privileges by abusing the parameters of a command that is approved in the sudoers file.  This …

📅 Published: Dec. 9, 2025, 1:41 p.m. 🔄 Last Modified: Dec. 17, 2025, 2:51 p.m.

5.4

CVSS3.1

CVE-2025-6924 - Reflected XSS in Talent Software's e-BAP

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Talent Software e-BAP Automation allows Reflected XSS.This issue affects e-BAP Automation: before 42957.

📅 Published: Dec. 9, 2025, 1:38 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2025-14333 - Memory safety bugs fixed in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 1…

Memory safety bugs present in Firefox ESR 140.5, Thunderbird ESR 140.5, Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Fire…

📅 Published: Dec. 9, 2025, 1:38 p.m. 🔄 Last Modified: April 20, 2026, 5:45 p.m.
Total resulsts: 347066
Page 2527 of 34,707
« previous page » next page
Filters