6.3

CVSS4.0

CVE-2025-11938 - ChurchCRM setup.php deserialization

A vulnerability was found in ChurchCRM up to 5.18.0. This vulnerability affects unknown code of the file setup/routes/setup.php. Performing a manipulation of the argument DB_PASSWORD/ROOT_PATH/URL results in deserialization. The attack may be initiated remotely. The attack's complexity is rated as …

πŸ“… Published: Oct. 19, 2025, 7:32 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 8:16 a.m.

5.3

CVSS3.1

CVE-2025-62672 -

rplay through 3.3.2 allows attackers to cause a denial of service (SIGSEGV and daemon crash) or possibly have unspecified other impact. This occurs in memcpy in the RPLAY_DATA case in rplay_unpack in librplay/rplay.c, potentially reachable via packet data with no authentication.

πŸ“… Published: Oct. 19, 2025, midnight πŸ”„ Last Modified: Oct. 21, 2025, 7:31 p.m.

8.8

CVSS3.1

CVE-2025-47410 - Apache Geode: CSRF attacks through GET requests to the Management and Monitoring REST API that can …

Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could allow an attacker who has tricked a user into giving up their Geode session credentials to submit malicious commands on the target system on behalf of the authenticated user. This …

πŸ“… Published: Oct. 18, 2025, 3:15 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

4.4

CVSS3.1

CVE-2025-11926 - Related Posts Lite <= 1.12 - Authenticated (Admin+) Stored Cross-Site Scripting

The Related Posts Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions…

πŸ“… Published: Oct. 18, 2025, 9:25 a.m. πŸ”„ Last Modified: April 8, 2026, 4:55 p.m.

8.8

CVSS3.1

CVE-2025-9890 - Theme Editor <= 3.0 - Cross-Site Request Forgery to Remote Code Execution

The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0. This is due to missing or incorrect nonce validation on the 'theme_editor_theme' page. This makes it possible for unauthenticated attackers to achieve remote code execution v…

πŸ“… Published: Oct. 18, 2025, 8:25 a.m. πŸ”„ Last Modified: April 8, 2026, 5:01 p.m.

8.5

CVSS4.0

CVE-2025-5555 - Nixdorf Wincor PORT IO Driver IOCTL wnport.sys sub_11100 stack-based overflow

A vulnerability has been found in Nixdorf Wincor PORT IO Driver up to 1.0.0.1. This affects the function sub_11100 in the library wnport.sys of the component IOCTL Handler. Such manipulation leads to stack-based buffer overflow. Local access is required to approach this attack. The exploit has been…

πŸ“… Published: Oct. 18, 2025, 8:02 a.m. πŸ”„ Last Modified: Oct. 21, 2025, 7:31 p.m.

5.3

CVSS3.1

CVE-2025-10750 - PowerBI Embed Reports <= 1.2.0 - Unauthenticated Sensitive Information Disclosure

The PowerBI Embed Reports plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 1.2.0. This is due to missing capability checks and authentication verification on the 'testUser' endpoint accessible via the mo_epbr_admin_observer() function hook…

πŸ“… Published: Oct. 18, 2025, 7:26 a.m. πŸ”„ Last Modified: April 8, 2026, 5:26 p.m.

5.3

CVSS3.1

CVE-2025-11256 - Kognetiks Chatbot <= 2.3.5 - Missing Authorization to Unauthenticated Limited File Uploads and Conv…

The Kognetiks Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 2.3.5. This makes it possible for unauthenticated attackers to upload limited safe files and erase conversations.

πŸ“… Published: Oct. 18, 2025, 7:26 a.m. πŸ”„ Last Modified: April 8, 2026, 4:40 p.m.

7.5

CVSS3.1

CVE-2025-11691 - PPOM – Product Addons & Custom Fields for WooCommerce <= 33.0.15 - Unauthenticated SQL Injection

The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the PPOM_Meta::get_fields_by_id() function in all versions up to, and including, 33.0.15 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation o…

πŸ“… Published: Oct. 18, 2025, 6:42 a.m. πŸ”„ Last Modified: April 8, 2026, 5:31 p.m.

6.5

CVSS3.1

CVE-2025-11372 - LearnPress – WordPress LMS Plugin <= 4.2.9.3 - Missing Authorization to Unauthenticated Database Ta…

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to modification of data in all versions up to, and including, 4.2.9.2. This is due to missing capability checks on the Admin Tools REST endpoints which are registered with permission_callback set to __return_true. This makes i…

πŸ“… Published: Oct. 18, 2025, 6:42 a.m. πŸ”„ Last Modified: April 8, 2026, 5:25 p.m.
Total resulsts: 343947
Page 2850 of 34,395
Β« previous page Β» next page
Filters