4.3

CVSS3.1

CVE-2025-12366 - Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.5 - Authenticated (Author+) Insecure…

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.5 via the pagelayer_replace_page function due to missing validation on a user controlled key. This makes it possible for authe…

πŸ“… Published: Nov. 13, 2025, 3:27 a.m. πŸ”„ Last Modified: April 22, 2026, 9:15 p.m.

6.5

CVSS3.1

CVE-2025-12089 - Data Tables Generator by Supsystic <= 1.10.45 - Authenticated (Admin+) Arbitrary File Deletion

The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the cleanCache() function in all versions up to, and including, 1.10.45. This makes it possible for authenticated attackers, with Administrator-level acce…

πŸ“… Published: Nov. 13, 2025, 3:27 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-59367 -

An authentication bypass vulnerability has been identified in certain DSL series routers, may allow remote attackers to gain unauthorized access into the affected system. Refer to the 'Security Update for DSL Series Router' section on the ASUS Security Advisory for more information.

πŸ“… Published: Nov. 13, 2025, 2:09 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

3.9

CVSS3.1

CVE-2025-64711 - PrivateBin vulnerable to malicious filename use for self-XSS / HTML injection locally for users

PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Starting in version 1.7.7 and prior to version 2.0.3, dragging a file whose filename contains HTML is reflected verbatim into the page via the drag-and-drop helper, so any user who drops a crafted file on PrivateBi…

πŸ“… Published: Nov. 13, 2025, 1:50 a.m. πŸ”„ Last Modified: Nov. 25, 2025, 5:37 p.m.

5.1

CVSS4.0

CVE-2025-64716 - Anubis vulnerable to possible XSS via redir parameter when using subrequest auth mode

Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scraper bots. Prior to version 1.23.0, when using subrequest authentication, Anubis did not perform validation of the redirect URL and redirects user to any URL scheme. While most mode…

πŸ“… Published: Nov. 13, 2025, 1:46 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-64710 - Bitplatform Boilerplate has cross-site scripting vulnerability

Bitplatform Boilerplate is a Visual studio and .NET project template. Versions prior to 9.11.3 are affected by a cross-site scripting (XSS) vulnerability in the WebInteropApp/WebAppInterop, potentially allowing attackers to inject malicious scripts that compromise the security and integrity of web …

πŸ“… Published: Nov. 13, 2025, 1:40 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-60699 -

A buffer overflow vulnerability exists in the TOTOLINK A950RG Router firmware V5.9c.4592_B20191022_ALL within the `global.so` binary. The `getSaveConfig` function retrieves the `http_host` parameter from user input via `websGetVar` and copies it into a fixed-size stack buffer (`v13`) using `strcpy(…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 1:51 a.m.

5.4

CVSS3.1

CVE-2025-60671 -

A command injection vulnerability exists in the D-Link DIR-823G router firmware DIR823G_V1.0.2B05_20181207.bin in the timelycheck and sysconf binaries, which process the /var/system/linux_vlan_reinit file. The vulnerability occurs because content read from this file is only partially validated for …

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 7:04 p.m.

7.3

CVSS3.1

CVE-2025-60698 -

A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `rc` binaries. The `sub_432F60` function in `prog.cgi` stores user-supplied `SetSysLogSettings/IPAddress` values in NVRAM via `nvram_safe_set("SysLogRemote_IPAddress", ...)`. T…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 12:28 p.m.

5.3

CVSS3.1

CVE-2025-47220 -

A local file enumeration was found in Keyfactor SignServer versions prior to 7.3.2 .The property VISIBLE_SIGNATURE_CUSTOM_IMAGE_PATH, which exists in the PDFSigner and the PAdESSigner, can be set to any path without any restrictions by an admin user. In the case that the provided path points to an …

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 8:15 p.m.
Total resulsts: 349182
Page 3027 of 34,919
Β« previous page Β» next page
Filters