5.3

CVSS4.0

CVE-2025-10291 - linlinjava litemall cancel WxAftersaleController improper authorization

A weakness has been identified in linlinjava litemall up to 1.8.0. This affects the function WxAftersaleController of the file /wx/aftersale/cancel. Executing manipulation of the argument ID can lead to improper authorization. The attack can be executed remotely. The exploit has been made availableโ€ฆ

๐Ÿ“… Published: Sept. 12, 2025, 5:32 a.m. ๐Ÿ”„ Last Modified: Oct. 31, 2025, 2:27 p.m.

7.2

CVSS3.1

CVE-2025-8575 - LWS Cleaner <= 2.4.1.3 - Authenticated (Administrator+) Arbitrary File Deletion via 'lws_cl_delete_โ€ฆ

The LWS Cleaner plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'lws_cl_delete_file' function in all versions up to, and including, 2.4.1.3. This makes it possible for authenticated attackers, with Administrator-level access and above, tโ€ฆ

๐Ÿ“… Published: Sept. 12, 2025, 5:24 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-10148 - predictable WebSocket mask

curl's websocket code did not update the 32 bit mask pattern for each new outgoing frame as the specification says. Instead it used a fixed mask that persisted and was used throughout the entire connection. A predictable mask pattern allows for a malicious server to induce traffic between the twoโ€ฆ

๐Ÿ“… Published: Sept. 12, 2025, 5:10 a.m. ๐Ÿ”„ Last Modified: Jan. 20, 2026, 2:55 p.m.

7.5

CVSS3.1

CVE-2025-9086 - Out of bounds read for cookie path

1. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or otherwise made to speak with `http://target` (same hostname, but using clear text HTTP) using the same cookie set 3. The same cookie name is set - but with just a slash as path (`path=\"/\",`). โ€ฆ

๐Ÿ“… Published: Sept. 12, 2025, 5:10 a.m. ๐Ÿ”„ Last Modified: Jan. 20, 2026, 2:58 p.m.

6.9

CVSS4.0

CVE-2025-10288 - roncoo roncoo-pay list improper authentication

A vulnerability was found in roncoo roncoo-pay up to 9428382af21cd5568319eae7429b7e1d0332ff40. The impacted element is an unknown function of the file /user/info/list. Performing manipulation results in improper authentication. It is possible to initiate the attack remotely. The exploit has been maโ€ฆ

๐Ÿ“… Published: Sept. 12, 2025, 5:02 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-10094 - Improper Validation of Specified Quantity in Input in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed authenticated users to disrupt access to token listings and related administrative operations by creating tokens with excessively large namโ€ฆ

๐Ÿ“… Published: Sept. 12, 2025, 4:57 a.m. ๐Ÿ”„ Last Modified: Sept. 20, 2025, 2:56 a.m.

2.3

CVSS4.0

CVE-2025-10287 - roncoo roncoo-pay orderQuery direct request

A vulnerability has been found in roncoo roncoo-pay up to 9428382af21cd5568319eae7429b7e1d0332ff40. The affected element is an unknown function of the file /auth/orderQuery. Such manipulation of the argument orderNo leads to direct request. The attack may be performed from remote. A high complexityโ€ฆ

๐Ÿ“… Published: Sept. 12, 2025, 4:32 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-10278 - YunaiV ruoyi-vue-pro transfer improper authorization

A flaw has been found in YunaiV ruoyi-vue-pro up to 2025.09. Impacted is an unknown function of the file /crm/contact/transfer. This manipulation of the argument ids/newOwnerUserId causes improper authorization. The attack is possible to be carried out remotely. The exploit has been published and mโ€ฆ

๐Ÿ“… Published: Sept. 12, 2025, 3:32 a.m. ๐Ÿ”„ Last Modified: Nov. 14, 2025, 8:14 p.m.

6.1

CVSS3.1

CVE-2025-9881 - Ultimate Blogroll <= 2.5.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The Ultimate Blogroll plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scโ€ฆ

๐Ÿ“… Published: Sept. 12, 2025, 3:22 a.m. ๐Ÿ”„ Last Modified: April 20, 2026, 7:45 p.m.

6.4

CVSS3.1

CVE-2025-9877 - Embed Google Datastudio <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Embed Google Datastudio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'egds' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticateโ€ฆ

๐Ÿ“… Published: Sept. 12, 2025, 3:22 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 7:15 p.m.
Total resulsts: 349182
Page 3894 of 34,919
ยซ previous page ยป next page
Filters