9.8

CVSS3.1

CVE-2025-11833 - Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.0 - Missing A…

The Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the __construct function in all versions up to, and including, 3.6.0. This makes it possible for unauthenticated …

πŸ“… Published: Nov. 1, 2025, 3:34 a.m. πŸ”„ Last Modified: April 22, 2026, 2 p.m.

6.9

CVSS4.0

CVE-2025-62275 -

Blogs in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions does not check permission of images in a blog entry, which allows remote attackers to…

πŸ“… Published: Nov. 1, 2025, 2:42 a.m. πŸ”„ Last Modified: Nov. 10, 2025, 4:20 p.m.

6.4

CVSS3.1

CVE-2025-11922 - Inactive Logout <= 3.5.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting

The Inactive Logout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ina_redirect_page_individual_user' parameter in all versions up to, and including, 3.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wit…

πŸ“… Published: Nov. 1, 2025, 1:47 a.m. πŸ”„ Last Modified: April 21, 2026, 2 a.m.

8.8

CVSS3.1

CVE-2025-11920 - WPCOM Member <= 1.7.14 - Authenticated (Contributor+) Local File Inclusion via Shortcode

The WPCOM Member plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7.14 via the action parameter in one of its shortcodes. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary .…

πŸ“… Published: Nov. 1, 2025, 1:47 a.m. πŸ”„ Last Modified: April 22, 2026, 1 p.m.

5.3

CVSS3.1

CVE-2025-11174 - Document Library Lite <= 1.1.6 - Missing Authorization to Sensitive Information Exposure

The Document Library Lite plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and including, 1.1.6. This is due to the plugin exposing an unauthenticated AJAX action dll_load_posts which returns a JSON table of document data without performing nonce or capability che…

πŸ“… Published: Nov. 1, 2025, 1:47 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-11816 - Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages <= 3.5.1 -…

The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the disconnect_account_request() function in all versions up to, and including, 3.5.1. This makes…

πŸ“… Published: Nov. 1, 2025, 1:47 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.6

CVSS4.0

CVE-2025-62276 -

The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions uses an incorrect cache-control header,…

πŸ“… Published: Oct. 31, 2025, 11:34 p.m. πŸ”„ Last Modified: Nov. 10, 2025, 4:29 p.m.

6.2

CVSS3.1

CVE-2025-12464 - Qemu-kvm: stack buffer overflow in e1000 device via short frames in loopback mode

A stack-based buffer overflow was found in the QEMU e1000 network device. The code for padding short frames was dropped from individual network devices and moved to the net core code. The issue stems from the device's receive code still being able to process a short frame in loopback mode. This cou…

πŸ“… Published: Oct. 31, 2025, 9:15 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS3.1

CVE-2025-60711 - Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Protection mechanism failure in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

πŸ“… Published: Oct. 31, 2025, 7:29 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:56 p.m.

7.6

CVSS4.0

CVE-2025-10693 - Silicon Labs Z-Wave PIR Sensor Joins Network as Non-Secure

When SmartStart Inclusion fails during the onboarding of a Z-Wave PIR sensor, the sensor will join the network as a non-secure device. This vulnerability exists in Silicon Labs' Z-Wave PIR Sensor Reference design delivered as part of SiSDK v2025.6.0 and v2025.6.1.

πŸ“… Published: Oct. 31, 2025, 7:20 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346554
Page 2924 of 34,656
Β« previous page Β» next page
Filters