5.9

CVSS3.1

CVE-2025-11380 - Everest Backup <= 2.3.5 - Missing Authorization to Unauthenticated Information Exposure

The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'everest_process_status' AJAX action in all versions up to, and including, 2.3.5. This makes it possible for un…

πŸ“… Published: Oct. 11, 2025, 2:24 a.m. πŸ”„ Last Modified: April 22, 2026, 12:45 p.m.

6.4

CVSS3.1

CVE-2025-9560 - Colibri Page Builder <= 1.0.334 - Authenticated (Contributor+) Stored Cross-Site Scripting via coli…

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's colibri_newsletter shortcode in all versions up to, and including, 1.0.334 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for a…

πŸ“… Published: Oct. 11, 2025, 2:24 a.m. πŸ”„ Last Modified: April 22, 2026, 5 p.m.

6.2

CVSS3.1

CVE-2025-54654 -

Permission control vulnerability in the Gallery module. Successful exploitation of this vulnerability may affect service confidentiality

πŸ“… Published: Oct. 11, 2025, 1:50 a.m. πŸ”„ Last Modified: Oct. 20, 2025, 4:17 p.m.

5.3

CVSS4.0

CVE-2025-11590 - CodeAstro Gym Management System equipment-entry.php sql injection

A weakness has been identified in CodeAstro Gym Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/equipment-entry.php. Executing a manipulation of the argument ename can lead to sql injection. It is possible to launch the attack remotely. The explo…

πŸ“… Published: Oct. 11, 2025, 1:02 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 8:16 a.m.

7.5

CVSS3.1

CVE-2025-31718 -

In modem, there is a possible system crash due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed.

πŸ“… Published: Oct. 11, 2025, 12:26 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-31717 -

In modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

πŸ“… Published: Oct. 11, 2025, 12:26 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-11626 - Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark

MONGO dissector infinite loop in Wireshark 4.4.0 to 4.4.9 and 4.2.0 to 4.2.13 allows denial of service

πŸ“… Published: Oct. 10, 2025, 10:33 p.m. πŸ”„ Last Modified: March 27, 2026, 1:56 p.m.

5.3

CVSS3.1

CVE-2025-9554 - Owl Carousel 2 - Critical - Unsupported - SA-CONTRIB-2025-104

Vulnerability in Drupal Owl Carousel 2.This issue affects Owl Carousel 2: *.*.

πŸ“… Published: Oct. 10, 2025, 10:25 p.m. πŸ”„ Last Modified: Dec. 5, 2025, 12:41 a.m.

7.5

CVSS3.1

CVE-2025-62162 - cel-rust May Panic During Parsing of Invalid CEL Expressions

cel-rust is a Common Expression Language interpreter written in Rust. Starting in version 0.10.0 and prior to version 0.11.4, parsing certain malformed CEL expressions can cause the parser to panic, terminating the process. When the crate is used to evaluate untrusted expressions (e.g., user-suppli…

πŸ“… Published: Oct. 10, 2025, 10:25 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-9553 - API Key manager - Critical - Unsupported - SA-CONTRIB-2025-103

Vulnerability in Drupal API Key manager.This issue affects API Key manager: *.*.

πŸ“… Published: Oct. 10, 2025, 10:25 p.m. πŸ”„ Last Modified: Dec. 5, 2025, 12:45 a.m.
Total resulsts: 349182
Page 3475 of 34,919
Β« previous page Β» next page
Filters