7.8

CVSS3.1

CVE-2025-20735 -

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00435349; Issue ID: MSV-4051.

πŸ“… Published: Nov. 4, 2025, 6:19 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:47 p.m.

7.8

CVSS3.1

CVE-2025-20733 -

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00441509; Issue ID: MSV-4138.

πŸ“… Published: Nov. 4, 2025, 6:19 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:47 p.m.

6.7

CVSS3.1

CVE-2025-20730 -

In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10068463; Issue ID: MSV-4141.

πŸ“… Published: Nov. 4, 2025, 6:19 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:47 p.m.

7.8

CVSS3.1

CVE-2025-20728 -

In wlan STA driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00447115; Issue ID: MSV-4276.

πŸ“… Published: Nov. 4, 2025, 6:19 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:47 p.m.

7.5

CVSS3.1

CVE-2025-20725 -

In ims service, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for expl…

πŸ“… Published: Nov. 4, 2025, 6:19 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:47 p.m.

7.5

CVSS3.1

CVE-2025-20726 -

In Modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploit…

πŸ“… Published: Nov. 4, 2025, 6:19 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:47 p.m.

8.1

CVSS3.1

CVE-2025-20727 -

In Modem, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitati…

πŸ“… Published: Nov. 4, 2025, 6:19 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:47 p.m.

4.4

CVSS3.1

CVE-2025-12396 - Clubmember <= 0.2 - Authenticated (Admin+) Stored Cross-Site Scripting

The clubmember plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and abov…

πŸ“… Published: Nov. 4, 2025, 4:27 a.m. πŸ”„ Last Modified: April 21, 2026, 2 a.m.

6.4

CVSS3.1

CVE-2025-11812 - Reuse Builder <= 1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Reuse Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'reuse_builder_single_post_title' shortcode in all versions up to, and including, 1.7. This is due to insufficient input sanitization and output escaping on the 'style' attribute. This makes it possible for …

πŸ“… Published: Nov. 4, 2025, 4:27 a.m. πŸ”„ Last Modified: April 21, 2026, 6:45 p.m.

6.1

CVSS3.1

CVE-2025-12403 - Associados Amazon Plugin <= 0.8 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The Associados Amazon Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.8. This is due to missing or incorrect nonce validation on the brzon_admin_panel() function. This makes it possible for unauthenticated attackers to update settings …

πŸ“… Published: Nov. 4, 2025, 4:27 a.m. πŸ”„ Last Modified: April 21, 2026, 2 a.m.
Total resulsts: 349182
Page 3158 of 34,919
Β« previous page Β» next page
Filters