3.3
CVE-2025-0672 - Authentication Bypass in Multiple WSO2 Products via Stale FIDO Credential Association
An authentication bypass vulnerability exists in multiple WSO2 products when FIDO authentication is enabled. When a user account is deleted, the system does not automatically remove associated FIDO registration data. If a new user account is later created using the same username, the system may ass…
4.3
CVE-2025-58246 - WordPress <= 6.8.2 - (Contributor+) Sensitive Data Exposure Vulnerability
Insertion of Sensitive Information Into Sent Data vulnerability in WordPress allows Retrieve Embedded Sensitive Data. The WordPress Core security team is aware of the issue and is already working on a fix. This is a low-severity vulnerability. Contributor-level privileges required in order to explo…
6.1
CVE-2025-0209 - Reflected Cross-Site Scripting (XSS) in WSO2 Identity Server Account Registration Flow
A reflected cross-site scripting (XSS) vulnerability exists in the account registration flow of WSO2 Identity Server due to improper output encoding. A malicious actor can exploit this vulnerability by injecting a crafted payload that is reflected in the server response, enabling the execution of a…
6.8
CVE-2025-0663 - Potential cross-tenant account takeover vulnerability in Multiple WSO2 Products via Adaptive Authen…
A cross-tenant authentication vulnerability exists in multiple WSO2 products due to improper cryptographic design in Adaptive Authentication. A single cryptographic key is used across all tenants to sign authentication cookies, allowing a privileged user in one tenant to forge authentication cookie…
9.6
CVE-2025-10894 - Nx: nx/devkit: malicious versions of nx and plugins published to npm
Malicious code was inserted into the Nx (build system) package and several related plugins. The tampered package was published to the npm software registry, via a supply-chain attack. Affected versions contain code that scans the file system, collects credentials, and posts them to GitHub as a repo…
4.3
CVE-2024-6429 - Content Spoofing in Multiple WSO2 Products via Error Message Injection
A content spoofing vulnerability exists in multiple WSO2 products due to improper error message handling. Under certain conditions, error messages are passed through URL parameters without validation, allowing malicious actors to inject arbitrary content into the UI. By exploiting this vulnerabili…
0.0
CVE-2025-10895 -
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
6.8
CVE-2025-5717 - Authenticated Remote Code Execution in Multiple WSO2 Products via Event Processor Admin Service
An authenticated remote code execution (RCE) vulnerability exists in multiple WSO2 products due to improper input validation in the event processor admin service. A user with administrative access to the SOAP admin services can exploit this flaw by deploying a Siddhi execution plan containing malic…
4.8
CVE-2025-4760 - Authenticated Stored Cross-Site Scripting (XSS) in Multiple WSO2 Products via API Document Upload i…
An authenticated stored cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to improper validation of user-supplied input during API document upload in the Publisher portal. A user with publisher privileges can upload a crafted API document containing malicious JavaScript,…
6.3
CVE-2017-20200 - Coinomi cleartext transmission
A vulnerability has been found in Coinomi up to 1.7.6. This issue affects some unknown processing. Such manipulation leads to cleartext transmission of sensitive information. The attack can be launched remotely. This attack is characterized by high complexity. The exploitability is assessed as diff…