7.5

CVSS3.1

CVE-2025-30944 - WordPress Tablesome Table Premium <= 1.1.23 - Broken Access Control Vulnerability

Missing Authorization vulnerability in Essekia Tablesome Table Premium tablesome-premium allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Tablesome Table Premium: from n/a through <= 1.1.23.

πŸ“… Published: Oct. 22, 2025, 2:32 p.m. πŸ”„ Last Modified: April 23, 2026, 3:27 p.m.

10

CVSS3.1

CVE-2025-57870 - BUG-000179884 - There is a security vulnerability in ArcGIS Server Feature Services.

A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary SQL commands via a specific ArcGIS Feature Service operation. Successful exploitation can poten…

πŸ“… Published: Oct. 22, 2025, 2:26 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:57 p.m.

10

CVSS4.0

CVE-2016-15048 - AMTT HiBOS Command Injection RCE via server_ping.php

AMTT Hotel Broadband Operation System (HiBOS) contains an unauthenticated command injection vulnerability in the /manager/radius/server_ping.php endpoint. The application constructs a shell command that includes the user-supplied ip parameter and executes it without proper validation or escaping. A…

πŸ“… Published: Oct. 22, 2025, 2:21 p.m. πŸ”„ Last Modified: Dec. 31, 2025, 1:12 p.m.

5.4

CVSS3.1

CVE-2025-8848 - HTML Injection in Accept-Language Header in danny-avila/librechat

A vulnerability in danny-avila/librechat version 0.7.9 allows for HTML injection via the Accept-Language header. When a logged-in user sends an HTTP GET request with a crafted Accept-Language header, arbitrary HTML can be injected into the <html lang=""> tag of the response. This can lead to potent…

πŸ“… Published: Oct. 22, 2025, 1:54 p.m. πŸ”„ Last Modified: Oct. 30, 2025, 6:22 p.m.

0.0

CVE-2025-12068 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“… Published: Oct. 22, 2025, 1:50 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 4:15 p.m.

0.0

CVE-2023-53701 - netfilter: nf_tables: deactivate anonymous set from preparation phase

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: deactivate anonymous set from preparation phase [ backport for 4.14 of c1592a89942e9678f7d9c8030efa777c0d57edab ] Toggle deleted anonymous sets as inactive in the next generation, so users cannot perform an…

πŸ“… Published: Oct. 22, 2025, 1:23 p.m. πŸ”„ Last Modified: Oct. 22, 2025, 9:12 p.m.

5.4

CVSS3.0

CVE-2025-11844 - XPath Injection in Hugging Face Smolagents search_item_ctrl_f Function

Hugging Face Smolagents version 1.20.0 contains an XPath injection vulnerability in the search_item_ctrl_f function located in src/smolagents/vision_web_browser.py. The function constructs an XPath query by directly concatenating user-supplied input into the XPath expression without proper sanitiza…

πŸ“… Published: Oct. 22, 2025, 1:13 p.m. πŸ”„ Last Modified: Oct. 30, 2025, 5:43 p.m.

5.3

CVSS3.1

CVE-2025-11750 - User Enumeration via Distinct Error Messages in langgenius/dify-web

In langgenius/dify-web version 1.6.0, the authentication mechanism reveals the existence of user accounts by returning different error messages for non-existent and existing accounts. Specifically, when a login or registration attempt is made with a non-existent username or email, the system respon…

πŸ“… Published: Oct. 22, 2025, 1:13 p.m. πŸ”„ Last Modified: Oct. 30, 2025, 5:46 p.m.

5.7

CVSS4.0

CVE-2025-11411 - Possible domain hijacking via promiscuous records in the authority section

NLnet Labs Unbound up to and including version 1.24.1 is vulnerable to possible domain hijack attacks. Promiscuous NS RRSets that complement positive DNS replies in the authority section can be used to trick resolvers to update their delegation information for the zone. Usually these RRSets are use…

πŸ“… Published: Oct. 22, 2025, 12:28 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2025-11086 - Academy LMS Pro <= 3.3.7 - Unauthenticated Privilege Escalation via Social Login Addon

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3.7. This is due to the plugin not properly validating a user's role prior to registering a user via the Social Login addon. This…

πŸ“… Published: Oct. 22, 2025, 11:25 a.m. πŸ”„ Last Modified: April 22, 2026, 10 p.m.
Total resulsts: 349182
Page 3333 of 34,919
Β« previous page Β» next page
Filters