7.5

CVSS3.1

CVE-2025-13646 - Modula 2.13.1 - 2.13.2 - Authenticated (Author+) Arbitrary File Upload via Race Condition

The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ajax_unzip_file' function in versions 2.13.1 to 2.13.2. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files…

πŸ“… Published: Dec. 3, 2025, 2:25 a.m. πŸ”„ Last Modified: Dec. 15, 2025, 3:41 p.m.

6.4

CVSS3.1

CVE-2025-13448 - CSSIgniter Shortcodes <= 2.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'elem…

The CSSIgniter Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'element' shortcode attribute in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contribu…

πŸ“… Published: Dec. 3, 2025, 2:25 a.m. πŸ”„ Last Modified: April 22, 2026, 4:30 p.m.

7.2

CVSS3.1

CVE-2025-13645 - Modula 2.13.1 - 2.13.2 - Authenticated (Author+) Arbitrary File Deletion

The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'ajax_unzip_file' function in versions 2.13.1 to 2.13.2. This makes it possible for authenticated attackers, with Author-level access and above, to delete arbitrary…

πŸ“… Published: Dec. 3, 2025, 2:25 a.m. πŸ”„ Last Modified: Dec. 15, 2025, 3:39 p.m.

6.5

CVSS3.1

CVE-2025-65345 -

alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The zip/archiving functionality allows an attacker to create archives containing files and directories outside the intended scope due to improper path validation.

πŸ“… Published: Dec. 3, 2025, midnight πŸ”„ Last Modified: Dec. 16, 2025, 7:14 p.m.

5.3

CVSS3.1

CVE-2025-53965 -

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. The function used to decode the SOR transparent container lacks bounds checking, …

πŸ“… Published: Dec. 3, 2025, midnight πŸ”„ Last Modified: Dec. 5, 2025, 5:01 p.m.

5.1

CVSS3.1

CVE-2025-50361 -

Buffer Overflow was found in SmallBASIC community SmallBASIC with SDL Before v12_28, and commit sha:298a1d495355959db36451e90a0ac74bcc5593fe in the function main.cpp, which can lead to potential information leakage and crash.

πŸ“… Published: Dec. 3, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 8:21 p.m.

8.4

CVSS3.1

CVE-2025-50360 -

A heap buffer overflow in compiler.c and compiler.h in Pepper language 0.1.1commit 961a5d9988c5986d563310275adad3fd181b2bb7. Malicious execution of a pepper source file(.pr) could lead to arbitrary code execution or Denial of Service.

πŸ“… Published: Dec. 3, 2025, midnight πŸ”„ Last Modified: Dec. 16, 2025, 9:08 p.m.

9

CVSS3.1

CVE-2025-65267 -

In ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images allows attackers to embed malicious JavaScript. The payload executes when an administrator clicks the image link to view the avatar, resulting in stored cross-site scripting (XSS). Successful exploi…

πŸ“… Published: Dec. 3, 2025, midnight πŸ”„ Last Modified: Dec. 5, 2025, 6:35 p.m.

6.1

CVSS3.1

CVE-2025-57202 -

A stored cross-site scripting (XSS) vulnerability in the PwdGrp.cgi endpoint of AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the username field.

πŸ“… Published: Dec. 3, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 9:04 p.m.

6.2

CVSS3.1

CVE-2025-55076 -

A local privilege escalation vulnerability exists in the InstallationHelper service included with Plugin Alliance Installation Manager v1.4.0 for macOS. The service accepts unauthenticated XPC connections and executes input via system(), which may allow a local user to execute arbitrary commands wi…

πŸ“… Published: Dec. 3, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 8:56 p.m.
Total resulsts: 349182
Page 2841 of 34,919
Β« previous page Β» next page
Filters