6.7

CVSS3.1

CVE-2025-1862 - Authenticated Arbitrary File Upload in Multiple WSO2 Products via BPEL Uploader SOAP Service Leadin…

An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user-supplied filenames in the BPEL uploader SOAP service endpoint. A malicious actor with administrative privileges can upload arbitrary files to a user-controlled location on the server. By lev…

📅 Published: Sept. 26, 2025, 8:18 a.m. 🔄 Last Modified: Feb. 26, 2026, 5:47 p.m.

3.7

CVSS3.1

CVE-2025-1396 - Username Enumeration in Multiple WSO2 Products with Multi-Attribute Login Enabled

A username enumeration vulnerability exists in multiple WSO2 products when Multi-Attribute Login is enabled. In this configuration, the system returns a distinct "User does not exist" error message to the login form, regardless of the validate_username setting. This behavior allows malicious actors…

📅 Published: Sept. 26, 2025, 7:52 a.m. 🔄 Last Modified: Oct. 6, 2025, 1:44 p.m.

6.5

CVSS3.1

CVE-2025-54831 - Apache Airflow: Connection sensitive details exposed to users with READ permissions

Apache Airflow 3 introduced a change to the handling of sensitive information in Connections. The intent was to restrict access to sensitive connection fields to Connection Editing Users, effectively applying a "write-only" model for sensitive values. In Airflow 3.0.3, this model was unintentiona…

📅 Published: Sept. 26, 2025, 7:28 a.m. 🔄 Last Modified: Nov. 4, 2025, 10:16 p.m.

7.3

CVSS3.1

CVE-2025-35027 - Unitree Multiple Robotic Products Command Injection

Multiple robotic products by Unitree sharing a common firmware, including the Go2, G1, H1, and B2 devices, contain a command injection vulnerability. By setting a malicious string when configuring the on-board WiFi via a BLE module of an affected robot, then triggering a restart of the WiFi service…

📅 Published: Sept. 26, 2025, 6:53 a.m. 🔄 Last Modified: Jan. 12, 2026, 4:54 p.m.

4.4

CVSS3.1

CVE-2025-10490 - Zephyr Project Manager <= 3.3.202 - Authenticated (Admin+) Stored Cross-Site Scripting

The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.3.202 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level perm…

📅 Published: Sept. 26, 2025, 6:43 a.m. 🔄 Last Modified: April 21, 2026, 7 p.m.

6.4

CVSS3.1

CVE-2025-10136 - TweetThis Shortcode <= 1.8.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

The TweetThis Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tweetthis' shortcode in all versions up to, and including, 1.8.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticat…

📅 Published: Sept. 26, 2025, 6:43 a.m. 🔄 Last Modified: April 21, 2026, 3 a.m.

6.4

CVSS3.1

CVE-2025-10180 - Markdown Shortcode <= 0.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Markdown Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'markdown' shortcode in all versions up to, and including, 0.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…

📅 Published: Sept. 26, 2025, 6:43 a.m. 🔄 Last Modified: April 22, 2026, 1:30 p.m.

5.4

CVSS3.1

CVE-2025-10137 - Snow Monkey <= 29.1.5 - Unauthenticated Blind Server-Side Request Forgery

The Snow Monkey theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 29.1.5 via the request() function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be …

📅 Published: Sept. 26, 2025, 6:43 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-10307 - Backuply – Backup, Restore, Migrate and Clone <= 1.4.8 - Authenticated (Admin+) Arbitrary File Dele…

The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete backup functionality in all versions up to, and including, 1.4.8. This makes it possible for authenticated attackers, with Administr…

📅 Published: Sept. 26, 2025, 6:43 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2025-9490 - Popup Maker <= 1.20.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via title Parameter

The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 1.20.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and …

📅 Published: Sept. 26, 2025, 5:27 a.m. 🔄 Last Modified: April 21, 2026, 7 p.m.
Total resulsts: 349182
Page 3674 of 34,919
« previous page » next page
Filters