9.8

CVSS3.1

CVE-2025-10586 - Community Events <= 1.5.1 - Unauthenticated SQL Injection

The Community Events plugin for WordPress is vulnerable to SQL Injection via the โ€˜event_venueโ€™ parameter in all versions up to, and including, 1.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for โ€ฆ

๐Ÿ“… Published: Oct. 9, 2025, 1:48 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 1:15 p.m.

5.4

CVSS3.1

CVE-2025-11166 - WP Go Maps (formerly WP Google Maps) <= 9.0.46 - Cross-Site Request Forgery to Plugin Settings Updaโ€ฆ

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up to, and including, 9.0.46. This is due to the plugin exposing state-changing REST actions through an AJAX bridge without proper CSRF token validation, and having destrโ€ฆ

๐Ÿ“… Published: Oct. 9, 2025, 1:48 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 1:15 p.m.

8.7

CVSS4.0

CVE-2025-11525 - Tenda AC7 SetUpnpCfg stack-based overflow

A vulnerability has been found in Tenda AC7 15.03.06.44. Impacted is an unknown function of the file /goform/SetUpnpCfg. Such manipulation of the argument upnpEn leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

๐Ÿ“… Published: Oct. 9, 2025, 1:32 a.m. ๐Ÿ”„ Last Modified: Feb. 24, 2026, 6:54 a.m.

8.7

CVSS4.0

CVE-2025-11524 - Tenda AC7 SetDDNSCfg stack-based overflow

A flaw has been found in Tenda AC7 15.03.06.44. This issue affects some unknown processing of the file /goform/SetDDNSCfg. This manipulation of the argument ddnsEn causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been published and may be used.

๐Ÿ“… Published: Oct. 9, 2025, 1:02 a.m. ๐Ÿ”„ Last Modified: Feb. 24, 2026, 6:54 a.m.

5.3

CVSS4.0

CVE-2025-11523 - Tenda AC7 AdvSetLanip command injection

A vulnerability was detected in Tenda AC7 15.03.06.44. This vulnerability affects unknown code of the file /goform/AdvSetLanip. The manipulation of the argument lanIp results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used.

๐Ÿ“… Published: Oct. 9, 2025, 1:02 a.m. ๐Ÿ”„ Last Modified: Feb. 24, 2026, 6:54 a.m.

5.3

CVSS4.0

CVE-2025-11516 - code-projects Online Complaint Site complaint-details.php sql injection

A weakness has been identified in code-projects Online Complaint Site 1.0. Impacted is an unknown function of the file /cms/users/complaint-details.php. Executing manipulation of the argument cid can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made avaiโ€ฆ

๐Ÿ“… Published: Oct. 9, 2025, 12:32 a.m. ๐Ÿ”„ Last Modified: Oct. 14, 2025, 7:34 p.m.

5.3

CVSS4.0

CVE-2025-11515 - code-projects Online Complaint Site register-complaint.php sql injection

A security flaw has been discovered in code-projects Online Complaint Site 1.0. This issue affects some unknown processing of the file /cms/users/register-complaint.php. Performing manipulation of the argument cid results in sql injection. It is possible to initiate the attack remotely. The exploitโ€ฆ

๐Ÿ“… Published: Oct. 9, 2025, 12:02 a.m. ๐Ÿ”„ Last Modified: Oct. 10, 2025, 4:49 p.m.

5.3

CVSS4.0

CVE-2025-11514 - code-projects Online Complaint Site index.php sql injection

A vulnerability was identified in code-projects Online Complaint Site 1.0. This vulnerability affects unknown code of the file /cms/users/index.php. Such manipulation of the argument Username leads to sql injection. The attack may be performed from remote. The exploit is publicly available and mighโ€ฆ

๐Ÿ“… Published: Oct. 9, 2025, 12:02 a.m. ๐Ÿ”„ Last Modified: Oct. 10, 2025, 4:48 p.m.

5.5

CVSS3.1

CVE-2025-39956 - igc: don't fail igc_probe() on LED setup error

In the Linux kernel, the following vulnerability has been resolved: igc: don't fail igc_probe() on LED setup error When igc_led_setup() fails, igc_probe() fails and triggers kernel panic in free_netdev() since unregister_netdev() is not called. [1] This behavior can be tested using fault-injectioโ€ฆ

๐Ÿ“… Published: Oct. 9, 2025, midnight ๐Ÿ”„ Last Modified: Feb. 26, 2026, 10:51 p.m.

7.8

CVSS3.1

CVE-2025-39958 - iommu/s390: Make attach succeed when the device was surprise removed

In the Linux kernel, the following vulnerability has been resolved: iommu/s390: Make attach succeed when the device was surprise removed When a PCI device is removed with surprise hotplug, there may still be attempts to attach the device to the default domain as part of tear down via (__iommu_relโ€ฆ

๐Ÿ“… Published: Oct. 9, 2025, midnight ๐Ÿ”„ Last Modified: Feb. 26, 2026, 10:51 p.m.
Total resulsts: 349182
Page 3502 of 34,919
ยซ previous page ยป next page
Filters