9.8

CVSS3.1

CVE-2017-20208 - RegistrationMagic - Custom Registration Forms <= 3.7.9.2 - PHP Object Injection

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 3.7.9.3 (exclusive) via deserialization of untrusted input from the is_expired_by_date() function. This makes it possible fo…

πŸ“… Published: Oct. 18, 2025, 3:33 a.m. πŸ”„ Last Modified: April 8, 2026, 5:20 p.m.

9.8

CVSS3.1

CVE-2017-20207 - Flickr Gallery <= 1.5.2 - Unauthenticated PHP Object Injection

The Flickr Gallery plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.2 via deserialization of untrusted input from the `pager ` parameter. This allows unauthenticated attackers to inject a PHP Object. Attackers were actively exploiting this vulnerabili…

πŸ“… Published: Oct. 18, 2025, 3:33 a.m. πŸ”„ Last Modified: April 8, 2026, 5:17 p.m.

6.4

CVSS3.1

CVE-2020-36854 - Async JavaScript <= 2.19.07.14 - Authenticated (Subscriber+) Stored Cross-Site Scripting

The Async JavaScript plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.19.07.14. This is due to missing authorization checks on the aj_steps AJAX aciton along with a lack on sanitization on the settings saved via the function. This makes it possi…

πŸ“… Published: Oct. 18, 2025, 3:33 a.m. πŸ”„ Last Modified: April 8, 2026, 5:16 p.m.

9.8

CVSS3.1

CVE-2017-20206 - Appointments <= 2.2.1 - Unauthenticated PHP Object Injection

The Appointments plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.2.1 via deserialization of untrusted input from the `wpmudev_appointments` cookie. This allows unauthenticated attackers to inject a PHP Object. Attackers were actively exploiting this vu…

πŸ“… Published: Oct. 18, 2025, 3:33 a.m. πŸ”„ Last Modified: April 8, 2026, 5:03 p.m.

7.2

CVSS3.1

CVE-2020-36853 - 10WebMapBuilder <= 1.0.63 - Unauthenticated Stored Cross-Site Scripting via Plugin Settings Change

The 10WebMapBuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Plugin Settings Change in versions up to, and including, 1.0.63 due to insufficient input sanitization and output escaping and a lack of capability checks. This makes it possible for unauthenticated attackers …

πŸ“… Published: Oct. 18, 2025, 3:33 a.m. πŸ”„ Last Modified: April 8, 2026, 5:02 p.m.

5.4

CVSS3.1

CVE-2025-11378 - ShortPixel Image Optimizer <= 6.3.4 - Authenticated (Contributor+) Settings Import/Export

The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'shortpixel_ajaxRequest' AJAX action in all versions up to, and including, 6.3.4. This makes it possible for authent…

πŸ“… Published: Oct. 18, 2025, 3:33 a.m. πŸ”„ Last Modified: April 8, 2026, 4:41 p.m.

4.4

CVSS3.1

CVE-2025-40001 - scsi: mvsas: Fix use-after-free bugs in mvs_work_queue

In the Linux kernel, the following vulnerability has been resolved: scsi: mvsas: Fix use-after-free bugs in mvs_work_queue During the detaching of Marvell's SAS/SATA controller, the original code calls cancel_delayed_work() in mvs_free() to cancel the delayed work item mwq->work_q. However, if mw…

πŸ“… Published: Oct. 18, 2025, midnight πŸ”„ Last Modified: Dec. 1, 2025, 6:16 a.m.

5.5

CVSS3.1

CVE-2025-40003 - net: mscc: ocelot: Fix use-after-free caused by cyclic delayed work

In the Linux kernel, the following vulnerability has been resolved: net: mscc: ocelot: Fix use-after-free caused by cyclic delayed work The origin code calls cancel_delayed_work() in ocelot_stats_deinit() to cancel the cyclic delayed work item ocelot->stats_work. However, cancel_delayed_work() ma…

πŸ“… Published: Oct. 18, 2025, midnight πŸ”„ Last Modified: Dec. 1, 2025, 6:16 a.m.

5.5

CVSS3.1

CVE-2025-40002 - thunderbolt: Fix use-after-free in tb_dp_dprx_work

In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Fix use-after-free in tb_dp_dprx_work The original code relies on cancel_delayed_work() in tb_dp_dprx_stop(), which does not ensure that the delayed work item tunnel->dprx_work has fully completed if it was already r…

πŸ“… Published: Oct. 18, 2025, midnight πŸ”„ Last Modified: Dec. 1, 2025, 6:16 a.m.

2.1

CVSS4.0

CVE-2025-62655 - SQL injection in Cargo via Special:CargoExport

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in The Wikimedia Foundation MediaWiki Cargo extension allows SQL Injection.This issue affects MediaWiki Cargo extension: 1.39, 1.43, 1.44.

πŸ“… Published: Oct. 17, 2025, 10:46 p.m. πŸ”„ Last Modified: Oct. 21, 2025, 7:31 p.m.
Total resulsts: 344032
Page 2862 of 34,404
Β« previous page Β» next page
Filters