6.9

CVSS4.0

CVE-2025-59372 -

A path traversal vulnerability has been identified in certain router models. A remote, authenticated attacker could exploit this vulnerability to write files outside the intended directory, potentially affecting device integrity. Refer to the 'Security Update for ASUS Router Firmware' section on thโ€ฆ

๐Ÿ“… Published: Nov. 25, 2025, 7:30 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS4.0

CVE-2025-59371 -

An authentication bypass vulnerability has been identified in the IFTTT integration feature. A remote, authenticated attacker could leverage this vulnerability to potentially gain unauthorized access to the device. This vulnerability does not affect Wi-Fi 7 series models. Refer to the 'Security Updโ€ฆ

๐Ÿ“… Published: Nov. 25, 2025, 7:30 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS4.0

CVE-2025-59370 -

A command injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vulnerability to potentially execute arbitrary commands, leading to the device executing unintended instructions. Refer to the 'Security Update for ASUS Router Firmware' section on tโ€ฆ

๐Ÿ“… Published: Nov. 25, 2025, 7:30 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS4.0

CVE-2025-59369 -

A SQL injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vulnerability to potentially execute arbitrary SQL queries, leading to unauthorized data access. Refer to the 'Security Update for ASUS Router Firmware' section on the ASUS Security Advโ€ฆ

๐Ÿ“… Published: Nov. 25, 2025, 7:29 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6

CVSS4.0

CVE-2025-59368 -

An integer underflow vulnerability has been identified in Aicloud. An authenticated attacker may trigger this vulnerability by sending a crafted request, potentially impacting the availability of the device. Refer to the ' Security Update for ASUS Router Firmware' section on the ASUS Security Adviโ€ฆ

๐Ÿ“… Published: Nov. 25, 2025, 7:29 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.2

CVSS4.0

CVE-2025-12003 -

A path traversal vulnerability has been identified in WebDAV, which may allow unauthenticated remote attackers to impact the integrity of the device. Refer to the ' Security Update for ASUS Router Firmware' section on the ASUS Security Advisory for more information.

๐Ÿ“… Published: Nov. 25, 2025, 7:28 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-12587 - Peer Publish <= 1.0 - Cross-Site Request Forgery

The Peer Publish plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation on the website management pages. This makes it possible for unauthenticated attackers to add, modify, or delete website configurationsโ€ฆ

๐Ÿ“… Published: Nov. 25, 2025, 7:28 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 1:30 a.m.

4.9

CVSS3.1

CVE-2025-13385 - Bookme <= 4.2 - Authenticated (Admin+) SQL Injection via 'filter[status]' Parameter

The Bookme โ€“ Free Online Appointment Booking and Scheduling Plugin for WordPress is vulnerable to time-based SQL Injection via the `filter[status]` parameter in all versions up to, and including, 4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on tโ€ฆ

๐Ÿ“… Published: Nov. 25, 2025, 7:28 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 1:30 a.m.

4.3

CVSS3.1

CVE-2025-12634 - Refund Request for WooCommerce <= 1.0 - Missing Authorization to Authenticated (Subscriber+) Refundโ€ฆ

The Refund Request for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_refund_status' function in all versions up to, and including, 1.0. This makes it possible for authenticated attackers, with Subscriber-level acโ€ฆ

๐Ÿ“… Published: Nov. 25, 2025, 7:28 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 1:30 a.m.

4.9

CVSS3.1

CVE-2025-13370 - ProjectList <= 0.3.0 - Authenticated (Editor+) SQL Injection via 'id' Parameter

The ProjectList plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' parameter in all versions up to, and including, 0.3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authโ€ฆ

๐Ÿ“… Published: Nov. 25, 2025, 7:28 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 6 p.m.
Total resulsts: 349182
Page 2907 of 34,919
ยซ previous page ยป next page
Filters