6.5

CVSS3.1

CVE-2025-58703 - WordPress Skyword API Plugin Plugin <= 2.5.3 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skyword Skyword API Plugin skyword-plugin allows Stored XSS.This issue affects Skyword API Plugin: from n/a through <= 2.5.3.

πŸ“… Published: Sept. 22, 2025, 6:22 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.

6.5

CVSS3.1

CVE-2025-58704 - WordPress WP Delete User Accounts Plugin <= 1.2.4 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ren Ventura WP Delete User Accounts wp-delete-user-accounts allows Stored XSS.This issue affects WP Delete User Accounts: from n/a through <= 1.2.4.

πŸ“… Published: Sept. 22, 2025, 6:22 p.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.

5.5

CVSS3.1

CVE-2025-59418 - BunnyPad Vulnerable to Buffer Overflow When Opening Files of Size 20MB or Greater

BunnyPad is a note taking software. Prior to version 11.0.27000.0915, opening files greater than or equal to 20MB causes buffer overflow to occur. This issue has been patched in version 11.0.27000.0915. Users who wish not to upgrade should refrain from opening files larger than 10MB.

πŸ“… Published: Sept. 22, 2025, 6:02 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-10809 - Campcodes Online Learning Management System department.php sql injection

A security vulnerability has been detected in Campcodes Online Learning Management System 1.0. The affected element is an unknown function of the file /admin/department.php. Such manipulation of the argument d leads to sql injection. The attack can be executed remotely. The exploit has been disclos…

πŸ“… Published: Sept. 22, 2025, 6:02 p.m. πŸ”„ Last Modified: Sept. 25, 2025, 7:14 p.m.

6.9

CVSS4.0

CVE-2025-10808 - Campcodes Farm Management System uploadProduct.php sql injection

A weakness has been identified in Campcodes Farm Management System 1.0. Impacted is an unknown function of the file /uploadProduct.php. This manipulation of the argument Type causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and c…

πŸ“… Published: Sept. 22, 2025, 5:32 p.m. πŸ”„ Last Modified: Oct. 15, 2025, 4:01 p.m.

7.5

CVSS3.1

CVE-2025-59420 - Authlib: JWS/JWT accepts unknown crit headers (RFC violation β†’ possible authz bypass)

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.4, Authlib’s JWS verification accepts tokens that declare unknown critical header parameters (crit), violating RFC 7515 β€œmust‑understand” semantics. An attacker can craft a signed token with a critical h…

πŸ“… Published: Sept. 22, 2025, 5:28 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 6:17 p.m.

0.0

CVE-2025-59885 -

Not used

πŸ“… Published: Sept. 22, 2025, 5:25 p.m. πŸ”„ Last Modified: Sept. 23, 2025, 2:55 a.m.

0.0

CVE-2025-59880 -

Not used

πŸ“… Published: Sept. 22, 2025, 5:25 p.m. πŸ”„ Last Modified: Sept. 23, 2025, 2:55 a.m.

0.0

CVE-2025-59881 -

Not used

πŸ“… Published: Sept. 22, 2025, 5:25 p.m. πŸ”„ Last Modified: Sept. 23, 2025, 2:55 a.m.

0.0

CVE-2025-59882 -

Not used

πŸ“… Published: Sept. 22, 2025, 5:25 p.m. πŸ”„ Last Modified: Sept. 23, 2025, 2:55 a.m.
Total resulsts: 349182
Page 3749 of 34,919
Β« previous page Β» next page
Filters