6.4

CVSS3.1

CVE-2025-11161 - WPBakery Page Builder <= 8.6.1 - Stored Cross-Site Scripting via vc_custom_heading Shortcode

The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vc_custom_heading shortcode in all versions up to, and including, 8.6.1. This is due to insufficient restriction of allowed HTML tags and improper sanitization of user-supplied attributes in the fontโ€ฆ

๐Ÿ“… Published: Oct. 15, 2025, 6:43 a.m. ๐Ÿ”„ Last Modified: Nov. 26, 2025, 3:10 p.m.

8.5

CVSS4.0

CVE-2025-26861 -

RemoteCall Remote Support Program (for Operator) versions prior to 5.3.0 contain an uncontrolled search path element vulnerability. If a crafted DLL is placed in the same folder with the affected product, it may cause an arbitrary code execution.

๐Ÿ“… Published: Oct. 15, 2025, 6:07 a.m. ๐Ÿ”„ Last Modified: Oct. 21, 2025, 9:41 a.m.

8.5

CVSS4.0

CVE-2025-26860 -

RemoteCall Remote Support Program (for Operator) versions prior to 5.1.0 contain an uncontrolled search path element vulnerability. If a crafted DLL is placed in the same folder with the affected product, it may cause an arbitrary code execution.

๐Ÿ“… Published: Oct. 15, 2025, 6:06 a.m. ๐Ÿ”„ Last Modified: Oct. 21, 2025, 9:41 a.m.

8.5

CVSS4.0

CVE-2025-26859 -

RemoteView PC Application Console versions prior to 6.0.2 contain an uncontrolled search path element vulnerability. If a crafted DLL is placed in the same folder with the affected product, it may cause an arbitrary code execution.

๐Ÿ“… Published: Oct. 15, 2025, 6:06 a.m. ๐Ÿ”„ Last Modified: Oct. 21, 2025, 9:41 a.m.

5.5

CVSS3.1

CVE-2025-10406 - BlindMatrix e-Commerce < 3.1 - Contributor+ LFI

The BlindMatrix e-Commerce WordPress plugin before 3.1 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users, such as contributors, to perform LFI attacks.

๐Ÿ“… Published: Oct. 15, 2025, 6 a.m. ๐Ÿ”„ Last Modified: Jan. 9, 2026, 9:16 p.m.

6.8

CVSS3.1

CVE-2025-31702 -

A vulnerability exists in certain Dahua embedded products. Third-party malicious attacker with obtained normal user credentials could exploit the vulnerability to access certain data which are restricted to admin privileges, such as system-sensitive files through specific HTTP request. This may cauโ€ฆ

๐Ÿ“… Published: Oct. 15, 2025, 5:53 a.m. ๐Ÿ”„ Last Modified: Oct. 20, 2025, 1:27 p.m.

7.2

CVSS4.0

CVE-2025-55080 - Improper Parameter Check in ThreadX Syscall Implementation

In Eclipse ThreadX before 6.4.3, when memory protection is enabled, syscall parameters verification wasn't enough, allowing an attacker to obtain an arbitrary memory read/write.

๐Ÿ“… Published: Oct. 15, 2025, 5:41 a.m. ๐Ÿ”„ Last Modified: Oct. 22, 2025, 4:31 p.m.

6.4

CVSS3.1

CVE-2025-8561 - Ova Advent <= 1.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Ova Advent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 1.1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with cโ€ฆ

๐Ÿ“… Published: Oct. 15, 2025, 5:23 a.m. ๐Ÿ”„ Last Modified: Oct. 20, 2025, 1:27 p.m.

7.3

CVSS3.1

CVE-2025-6042 - Lisfinity Core - Lisfinity Core plugin used for pebasยฎ Lisfinity WordPress theme <= 1.4.0 - Unautheโ€ฆ

The Lisfinity Core - Lisfinity Core plugin used for pebasยฎ Lisfinity WordPress theme plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.4.0. This is due to the plugin assigning the editor role by default. While limitations with respect to capabilitiesโ€ฆ

๐Ÿ“… Published: Oct. 15, 2025, 5:23 a.m. ๐Ÿ”„ Last Modified: Oct. 21, 2025, 9:41 a.m.

4.3

CVSS3.1

CVE-2025-11176 - Quick Featured Images <= 13.7.2 - Insecure Direct Object Reference to Image Manipulation

The Quick Featured Images plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 13.7.2 via the qfi_set_thumbnail and qfi_delete_thumbnail AJAX actions due to missing validation on a user controlled key. This makes it possible for authenticated โ€ฆ

๐Ÿ“… Published: Oct. 15, 2025, 5:23 a.m. ๐Ÿ”„ Last Modified: Oct. 20, 2025, 1:26 p.m.
Total resulsts: 343054
Page 2800 of 34,306
ยซ previous page ยป next page
Filters