4.3

CVSS3.1

CVE-2025-8446 - Blaze Demo Importer <= 1.0.12 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin…

The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized limited plugin install due to a missing capability check on the 'blaze_demo_importer_install_plugin' function in all versions up to, and including, 1.0.12. This makes it possible for authenticated attackers, with Subscriber-…

📅 Published: Sept. 16, 2025, 11:17 a.m. 🔄 Last Modified: April 21, 2026, 7:15 p.m.

7.5

CVSS3.1

CVE-2025-41249 - CVE-2025-41249: Spring Framework Annotation Detection Vulnerability

The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions. Your application may be affected by t…

📅 Published: Sept. 16, 2025, 10:15 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-41248 - CVE-2025-41248: Spring Security authorization bypass for method security annotations on parameteriz…

The Spring Security annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue when using @PreAuthorize and other method security annotations, resulting in an authorization byp…

📅 Published: Sept. 16, 2025, 10:10 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS4.0

CVE-2025-10016 - Local Privilege Escalation in Sparkle Autoupdate Daemon

The Sparkle framework includes a helper tool Autoupdate. Due to lack of authentication of connecting clients a local unprivileged attacker can request installation of crafted malicious PKG file by racing to connect to the daemon when other app spawns it as root. This results in local privilege esc…

📅 Published: Sept. 16, 2025, 10:03 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-10015 - TCC Bypass via Downloader XPC Service in Sparkle

The Sparkle framework includes an XPC service Downloader.xpc, by default this service is private to the application its bundled with. A local unprivileged attacker can register this XPC service globally which will inherit TCC permissions of the application. Lack of validation of connecting client …

📅 Published: Sept. 16, 2025, 10:03 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.7

CVSS3.1

CVE-2025-26711 -

There is an unauthorized access vulnerability in ZTE T5400. Due to improper permission control of the Web module interface, an unauthorized attacker can obtain sensitive information through the interface.

📅 Published: Sept. 16, 2025, 9:35 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

3.5

CVSS3.1

CVE-2025-26710 -

There is an an information disclosure vulnerability in ZTE T5400. Due to improper configuration of the access control mechanism, attackers can obtain information through interfaces without authorization, causing the risk of information disclosure.

📅 Published: Sept. 16, 2025, 9:14 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

2.3

CVSS4.0

CVE-2025-10316 - Cross-Site Scripting in extension "Form to Database" (form_to_database)

The extension "Form to Database" is susceptible to Cross-Site Scripting. This issue affects the following versions: before 2.2.5, from 3.0.0 before 3.2.2, from 4.0.0 before 4.2.3, from 5.0.0 before 5.0.2.

📅 Published: Sept. 16, 2025, 9:09 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-4688 - SQLi in BGS Interactive's SINAV.LINK Exam Result Module

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BGS Interactive SINAV.LINK Exam Result Module allows SQL Injection.This issue affects SINAV.LINK Exam Result Module: before 1.2.

📅 Published: Sept. 16, 2025, 8:38 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-2404 - XSS in Ubit Information Technologies' STOYS

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ubit Information Technologies STOYS allows Cross-Site Scripting (XSS).This issue affects STOYS: from 2 before 20250916.

📅 Published: Sept. 16, 2025, 8:33 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3827 of 34,919
« previous page » next page
Filters