6.4

CVSS3.1

CVE-2025-10181 - Draft List <= 2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'drafts' shortcode in all versions up to, and including, 2.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, …

πŸ“… Published: Sept. 20, 2025, 4:27 a.m. πŸ”„ Last Modified: April 22, 2026, 10:15 p.m.

6.5

CVSS3.1

CVE-2025-10652 - Robcore Netatmo <= 1.7 - Authenticated (Contributor+) SQL Injection via robcore-netatmo Shortcode

The Robcore Netatmo plugin for WordPress is vulnerable to SQL Injection via the β€˜module_id’ attribute of the robcore-netatmo shortcode in all versions up to, and including, 1.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. …

πŸ“… Published: Sept. 20, 2025, 1:53 a.m. πŸ”„ Last Modified: April 21, 2026, 7:15 p.m.

6.9

CVSS4.0

CVE-2025-43808 -

The Commerce component in Liferay Portal 7.3.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and 7.3 service pack 3 through update 35 saves virtual products uploaded to Documents and Media with guest view permission, which al…

πŸ“… Published: Sept. 19, 2025, 8:37 p.m. πŸ”„ Last Modified: Dec. 15, 2025, 6:18 p.m.

5.2

CVSS4.0

CVE-2025-10568 - HyperX NGENUITY - Arbitrary Code Execution

HyperX NGENUITY software is potentially vulnerable to arbitrary code execution. HP is releasing updated software to address the potential vulnerability.

πŸ“… Published: Sept. 19, 2025, 7:39 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 5:16 p.m.

3.1

CVSS3.1

CVE-2025-9081 - IDOR in board file download allows any user to download any file by UUID

Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate access controls which allows any authenticated user to download sensitive files via board file download endpoint using UUID enumeration

πŸ“… Published: Sept. 19, 2025, 7:36 p.m. πŸ”„ Last Modified: Sept. 25, 2025, 8:14 p.m.

8.9

CVSS4.0

CVE-2025-59431 - MapServer - WFS XML Filter Query SQL injection

MapServer is a system for developing web-based GIS applications. Prior to 8.4.1, the XML Filter Query directive PropertyName is vulnerably to Boolean-based SQL injection. It seems like expression checking is bypassed by introducing double quote characters in the PropertyName. Allowing to manipulate…

πŸ“… Published: Sept. 19, 2025, 7:29 p.m. πŸ”„ Last Modified: Oct. 8, 2025, 6:26 p.m.

8

CVSS3.1

CVE-2025-9079 - Admin RCE via prepackaged plugins by way of misconfigured imports directory

Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.1, 10.9.x <= 10.9.3 fail to validate import directory path configuration which allows admin users to execute arbitrary code via malicious plugin upload to prepackaged plugins directory

πŸ“… Published: Sept. 19, 2025, 7:22 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:48 p.m.

5.1

CVSS4.0

CVE-2025-43809 -

Cross-Site Request Forgery (CSRF) vulnerability in the server (license) registration page in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.7, 2023.Q3.1 through 2023.Q3.9, 7.4 GA through update 92, and older unsupported versions all…

πŸ“… Published: Sept. 19, 2025, 7:15 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 3:06 p.m.

9.3

CVSS4.0

CVE-2022-4980 - General Bytes Crypto Application Server (CAS) Unauthenticated Creation of Admin Account via Default…

General Bytes Crypto Application Server (CAS) beginning with version 20201208 prior to 20220531.38 (backport) and 20220725.22 (mainline) contains an authentication bypass in the admin web interface. An unauthenticated attacker could invoke the same URL used by the product's default-installation / f…

πŸ“… Published: Sept. 19, 2025, 6:55 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2024-13990 - MicroWorld eScan AV Insecure Update Mechanism Allows Man-in-the-Middle Replacement of Updates

MicroWorld eScan AV's update mechanism failed to ensure authenticity and integrity of updates: update packages were delivered and accepted without robust cryptographic verification. As a result, an on-path attacker could perform a man-in-the-middle (MitM) attack and substitute malicious update payl…

πŸ“… Published: Sept. 19, 2025, 6:54 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3763 of 34,919
Β« previous page Β» next page
Filters