9.3

CVSS4.0

CVE-2025-8536 - SQL Injection in DobryCMS

A SQL injection vulnerability has been identified in DobryCMS. Improper neutralization of input provided by user into language functionality allows for SQL Injection attacks. This issue affects older branches of this software.

πŸ“… Published: Oct. 24, 2025, 2:18 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS3.1

CVE-2025-43994 -

Dell Storage Center - Dell Storage Manager, version(s) DSM 20.1.21, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.

πŸ“… Published: Oct. 24, 2025, 2:14 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 2:31 p.m.

9.8

CVSS3.1

CVE-2025-43995 -

Dell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. Authentication Bypass in DSM Data Collector. An u…

πŸ“… Published: Oct. 24, 2025, 2:09 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

6.5

CVSS3.1

CVE-2025-46425 -

Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

πŸ“… Published: Oct. 24, 2025, 2:04 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

0.0

CVE-2025-12152 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“… Published: Oct. 24, 2025, 12:53 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:15 p.m.

4.3

CVSS3.1

CVE-2025-11576 - AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant <= 1.6.5 - Unauthenticated …

The AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 1.6.5. This is due to insufficient sanitization in the 'newcodebyte_chatbot_export_messages' function. This makes it possible for una…

πŸ“… Published: Oct. 24, 2025, 12:29 p.m. πŸ”„ Last Modified: April 22, 2026, 12:45 p.m.

7.5

CVSS3.1

CVE-2025-10861 - Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers …

The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.1.4. This is due to insufficient validation on the URLs supplied via the URL parameter. Th…

πŸ“… Published: Oct. 24, 2025, 11:25 a.m. πŸ”„ Last Modified: April 22, 2026, 1 p.m.

4.3

CVSS3.1

CVE-2025-5605 - Authentication Bypass via URI Manipulation in Multiple WSO2 Products' Management Console Leading to…

An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor with access to the console can manipulate the request URI to bypass authentication and access certain restricted resources, resulting in partial information disclosure. The known ex…

πŸ“… Published: Oct. 24, 2025, 10:09 a.m. πŸ”„ Last Modified: Nov. 21, 2025, 2:20 p.m.

5.9

CVSS3.1

CVE-2025-5350 - SSRF and Reflected XSS Vulnerability in Deprecated Try-It Feature of Multiple WSO2 Products

SSRF and Reflected XSS Vulnerabilities exist in multiple WSO2 products within the deprecated Try-It feature, which was accessible only to administrative users. This feature accepted user-supplied URLs without proper validation, leading to server-side request forgery (SSRF). Additionally, the retrie…

πŸ“… Published: Oct. 24, 2025, 10:08 a.m. πŸ”„ Last Modified: Nov. 21, 2025, 2:33 p.m.

8.8

CVSS3.1

CVE-2025-10680 -

OpenVPN 2.7_alpha1 through 2.7_beta1 on POSIX based platforms allows a remote authenticated server to inject shell commands via DNS variables when --dns-updown is in use

πŸ“… Published: Oct. 24, 2025, 10:06 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3288 of 34,919
Β« previous page Β» next page
Filters