6.4

CVSS3.1

CVE-2025-9075 - ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patte…

The ZoloBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Gutenberg blocks in versions up to, and including, 2.3.10. This is due to insufficient input sanitization and output escaping on user-supplied attributes within multiple block components including Google M…

πŸ“… Published: Oct. 1, 2025, 3:25 a.m. πŸ”„ Last Modified: April 21, 2026, 7 p.m.

4

CVSS3.1

CVE-2025-10735 - Block For Mailchimp – Easy Mailchimp Form Integration <= 1.1.12 - Unauthenticated Blind Server-Side…

The Block For Mailchimp – Easy Mailchimp Form Integration plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 1.1.12 via the mcbSubmit_Form_Data(). This makes it possible for unauthenticated attackers to make web requests to arbitrary locati…

πŸ“… Published: Oct. 1, 2025, 3:25 a.m. πŸ”„ Last Modified: April 22, 2026, 2:15 p.m.

5.9

CVSS3.1

CVE-2025-10744 - File Manager, Code editor, backup by Managefy <= 1.6.1 - Unauthenticated Information Exposure

The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.1 through publicly exposed log files. This makes it possible for unauthenticated attackers to view information like full paths and ful…

πŸ“… Published: Oct. 1, 2025, 3:25 a.m. πŸ”„ Last Modified: April 22, 2026, 10:15 p.m.

6.5

CVSS3.1

CVE-2025-61044 -

TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the agentName parameter in the setEasyMeshAgentCfg function.

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Oct. 16, 2025, 8:15 p.m.

6.3

CVSS3.1

CVE-2025-61188 -

Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. This vulnerability allows attackers to upload files with system-whitelisted extensions to the system directory /opt, instead of the /opt/upFiles directory specified by the web server.

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Oct. 7, 2025, 2:43 p.m.

4.3

CVSS3.1

CVE-2025-59687 -

IMPAQTR Aurora before 1.36 allows Insecure Direct Object Reference attacks against the users list, organization details, bookmarks, and notifications of an arbitrary organization.

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-59686 -

Kazaar 1.25.12 allows /api/v1/org-id/orders/order-id/documents calls with a modified order-id.

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-57444 -

An authenticated cross-site scripting (XSS) vulnerability in the Administrative interface of Radware AlteonOS Web UI Management v33.0.4.50 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Description parameter.

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-57389 -

A reflected cross-site scripting (XSS) vulnerability in the /admin/system/packages endpoint of Luci OpenWRT v18.06.2 allows attackers to execute arbitrary Javascript in the context of a user's browser via a crafted payload. This vulnerability was fixed in OpenWRT v19.07.0.

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2025-46205 -

A heap-use-after free in the PdfTokenizer::ReadDictionary function of podofo v0.10.0 to v0.10.5 allows attackers to cause a Denial of Service (DoS) by supplying a crafted PDF file. NOTE: this is disputed by the Supplier because there is no available file to reproduce the issue.

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Oct. 27, 2025, 5:15 a.m.
Total resulsts: 349182
Page 3606 of 34,919
Β« previous page Β» next page
Filters