6.1

CVSS3.1

CVE-2025-10146 - Download Manager <= 3.3.23 - Reflected Cross-Site Scripting via `user_ids` Parameter

The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the โ€˜user_idsโ€™ parameter in all versions up to, and including, 3.3.23 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary weโ€ฆ

๐Ÿ“… Published: Sept. 19, 2025, 4:27 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 1 a.m.

5.4

CVSS3.1

CVE-2025-8487 - Kubio AI Page Builder <= 2.6.3 - Missing Authorization to Authenticated (Subscriber+) Limited Plugiโ€ฆ

The Kubio AI Page Builder plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the kubio-image-hub-install-plugin AJAX action in all versions up to, and including, 2.6.3. This makes it possible for authenticated attackers, with Subscriber-levelโ€ฆ

๐Ÿ“… Published: Sept. 19, 2025, 3:34 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 2:30 p.m.

9.8

CVSS3.1

CVE-2025-10690 - Goza - Nonprofit Charity WordPress Theme <= 3.2.2 - Missing Authorization to Unauthenticated Arbitrโ€ฆ

The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to unauthorized arbitrary file uploads due to a missing capability check on the 'beplus_import_pack_install_plugin' function in all versions up to, and including, 3.2.2. This makes it possible for unauthenticated attackeโ€ฆ

๐Ÿ“… Published: Sept. 19, 2025, 2:27 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 5 p.m.

7.2

CVSS3.1

CVE-2025-7937 - Supermicro BMC firmware update validation bypass

There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X12STW . An attacker can update the system firmware with a specially crafted image.

๐Ÿ“… Published: Sept. 19, 2025, 2:09 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2025-6198 - Supermicro BMC firmware update validation bypass

There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X13SEM-F . An attacker can update the system firmware with a specially crafted image.

๐Ÿ“… Published: Sept. 19, 2025, 1:45 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS3.1

CVE-2025-59715 -

SMSEagle before 6.11 allows reflected XSS via a username or contact phone number.

๐Ÿ“… Published: Sept. 19, 2025, midnight ๐Ÿ”„ Last Modified: Sept. 23, 2025, 4:55 p.m.

6.5

CVSS3.1

CVE-2025-59714 -

In Internet2 Grouper 5.17.1 before 5.20.5, group admins who are not Grouper sysadmins can configure loader jobs.

๐Ÿ“… Published: Sept. 19, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 8, 2025, 4:24 p.m.

6.8

CVSS3.1

CVE-2025-59713 -

Snipe-IT before 8.1.18 allows unsafe deserialization.

๐Ÿ“… Published: Sept. 19, 2025, midnight ๐Ÿ”„ Last Modified: Sept. 23, 2025, 4:57 p.m.

6.5

CVSS3.1

CVE-2025-57396 -

Tandoor Recipes 2.0.0-alpha-1, fixed in 2.0.0-alpha-2, is vulnerable to privilege escalation. This is due to the rework of the API, which resulted in the User Profile API Endpoint containing two boolean values indicating whether a user is staff or administrative. Consequently, any user can escalateโ€ฆ

๐Ÿ“… Published: Sept. 19, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 3, 2025, 4:58 p.m.

8.8

CVSS3.1

CVE-2025-54815 -

Server-side template injection (SSTI) vulnerability in PPress 0.0.9 allows attackers to execute arbitrary code via crafted themes.

๐Ÿ“… Published: Sept. 19, 2025, midnight ๐Ÿ”„ Last Modified: Sept. 25, 2025, 7:33 p.m.
Total resulsts: 349182
Page 3771 of 34,919
ยซ previous page ยป next page
Filters