5.3

CVSS4.0

CVE-2025-13472 - Missing authorization in BlazeMeter Jenkins Plugin

A fix was made in BlazeMeter Jenkins Plugin version 4.27 to allow users only with certain permissions to see the list of available resources like credential IDs, bzm workspaces and bzm project Ids. Prior to this fix, anyone could see this list as a dropdown on the Jenkins UI.

๐Ÿ“… Published: Dec. 3, 2025, 8:42 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.2

CVSS4.0

CVE-2025-29864 -

Protection Mechanism Failure vulnerability in ESTsoft ALZip on Windows allows SmartScreen bypass.This issue affects ALZip: from 12.01 before 12.29.

๐Ÿ“… Published: Dec. 3, 2025, 8:13 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-13946 - Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark

MEGACO dissector infinite loop in Wireshark 4.6.0 to 4.6.1 and 4.4.0 to 4.4.11 allows denial of service

๐Ÿ“… Published: Dec. 3, 2025, 8:04 a.m. ๐Ÿ”„ Last Modified: March 27, 2026, 1:56 p.m.

5.5

CVSS3.1

CVE-2025-13945 - Improperly Controlled Sequential Memory Allocation in Wireshark

HTTP3 dissector crash in Wireshark 4.6.0 and 4.6.1 allows denial of service

๐Ÿ“… Published: Dec. 3, 2025, 8:04 a.m. ๐Ÿ”„ Last Modified: March 27, 2026, 1:56 p.m.

8.8

CVSS3.1

CVE-2025-12744 - Abrt: command-injection in abrt leading to local privilege escalation

A flaw was found in the ABRT daemonโ€™s handling of user-supplied mount information.ABRT copies up to 12 characters from an untrusted input and places them directly into a shell command (docker inspect %s) without proper validation. An unprivileged local user can craft a payload that injects shell meโ€ฆ

๐Ÿ“… Published: Dec. 3, 2025, 7:51 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-13486 - Advanced Custom Fields: Extended 0.9.0.5 - 0.9.1.1 - Unauthenticated Remote Code Execution in prepaโ€ฆ

The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_form() function. This is due to the function accepting user input and then passing that through call_user_func_array(). This makes it possible for unaโ€ฆ

๐Ÿ“… Published: Dec. 3, 2025, 6:47 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.7

CVSS3.1

CVE-2025-12954 - Timetable and Event Schedule by MotoPress < 2.4.16 - Contributor+ Event Disclosure via IDOR

The Timetable and Event Schedule by MotoPress WordPress plugin before 2.4.16 does not verify a user has access to a specific event when duplicating, leading to arbitrary event disclosure when to users with a role as low as Contributor.

๐Ÿ“… Published: Dec. 3, 2025, 6 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-10304 - Everest Backup โ€“ WordPress Cloud Backup, Migration, Restore & Cloning Plugin <= 2.3.8 - Missing Autโ€ฆ

The Everest Backup โ€“ WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the process_status_unlink() function in all versions up to, and including, 2.3.8. This makes it possible for unauthenticateโ€ฆ

๐Ÿ“… Published: Dec. 3, 2025, 3:27 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 1:15 a.m.

5.3

CVSS3.1

CVE-2025-12585 - MxChat โ€“ AI Chatbot for WordPress <= 2.5.5 - Unauthenticated Information Exposure

The MxChat โ€“ AI Chatbot for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.5 via upload filenames. This makes it possible for unauthenticated attackers to extract session values that can subsequently be used to access conversโ€ฆ

๐Ÿ“… Published: Dec. 3, 2025, 3:27 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 8:16 p.m.

4.9

CVSS3.1

CVE-2025-13495 - FluentCart A New Era of eCommerce <= 1.3.1 - Authenticated (Administrator+) SQL Injection via 'grouโ€ฆ

The FluentCart plugin for WordPress is vulnerable to SQL Injection via the 'groupKey' parameter in all versions up to, and including, 1.3.1. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for aโ€ฆ

๐Ÿ“… Published: Dec. 3, 2025, 3:27 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9 p.m.
Total resulsts: 349182
Page 2840 of 34,919
ยซ previous page ยป next page
Filters