0.0

CVE-2025-66180 -

Not used

πŸ“… Published: Nov. 24, 2025, 9:07 a.m. πŸ”„ Last Modified: Nov. 25, 2025, 3:55 a.m.

0.0

CVE-2025-66179 -

Not used

πŸ“… Published: Nov. 24, 2025, 9:07 a.m. πŸ”„ Last Modified: Nov. 25, 2025, 3:55 a.m.

0.0

CVE-2025-13598 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“… Published: Nov. 24, 2025, 8:13 a.m. πŸ”„ Last Modified: Nov. 24, 2025, 2:32 p.m.

2.7

CVSS4.0

CVE-2025-13596 - Improper Error Handling Leading to Sensitive Information Disclosure in CIGES ≀ 2.15.6

A sensitive information disclosure vulnerability exists in the error handling component of ATISoluciones CIGES Application version 2.15.6 and earlier. When certain unexpected conditions trigger unhandled exceptions, the application returns detailed error messages and stack traces to the client. Thi…

πŸ“… Published: Nov. 24, 2025, 7:30 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2025-13594 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“… Published: Nov. 24, 2025, 6:58 a.m. πŸ”„ Last Modified: Nov. 24, 2025, 4:24 p.m.

5.3

CVSS4.0

CVE-2025-13588 - lKinderBueno Streamity Xtream IPTV Player proxy.php server-side request forgery

A vulnerability was found in lKinderBueno Streamity Xtream IPTV Player up to 2.8. The impacted element is an unknown function of the file public/proxy.php. Performing manipulation results in server-side request forgery. The attack can be initiated remotely. The exploit has been made public and coul…

πŸ“… Published: Nov. 24, 2025, 6:32 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-13586 - SourceCodester Online Student Clearance System changepassword.php sql injection

A flaw has been found in SourceCodester Online Student Clearance System 1.0. Impacted is an unknown function of the file /Admin/changepassword.php. This manipulation of the argument txtconfirm_password causes sql injection. It is possible to initiate the attack remotely. The exploit has been publis…

πŸ“… Published: Nov. 24, 2025, 6:02 a.m. πŸ”„ Last Modified: Dec. 2, 2025, 3:09 a.m.

7.1

CVSS3.1

CVE-2025-12629 - Broken Link Manager <= 0.6.5 - Reflected XSS

The Broken Link Manager WordPress plugin through 0.6.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

πŸ“… Published: Nov. 24, 2025, 6 a.m. πŸ”„ Last Modified: April 28, 2026, 10:30 a.m.

4.7

CVSS3.1

CVE-2025-12569 - WP Front User Submit < 5.0.0 - Open Redirect

The Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.0 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue

πŸ“… Published: Nov. 24, 2025, 6 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS3.1

CVE-2025-12394 - Backup Migration < 2.0.0 - Unauthenticated Backup Download

The Backup Migration WordPress plugin before 2.0.0 does not properly generate its backup path in certain server configurations, allowing unauthenticated users to fetch a log that discloses the backup filename. The backup archive is then downloadable without authentication.

πŸ“… Published: Nov. 24, 2025, 6 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 2919 of 34,919
Β« previous page Β» next page
Filters