5.1
CVE-2025-64700 -
Cross-site request forgery vulnerability exists in GROWI v7.3.3 and earlier. If a user views a malicious page while logged in, the user may be tricked to do unintended operations.
8.5
CVE-2025-14305 - Acer|ListCheck.exe - Local Privilege Escalation
ListCheck.exe developed by Acer has a Local Privilege Escalation vulnerability. Authenticated local attackers can replace ListCheck.exe with a malicious executable of the same name, which will be executed by the system and result in privilege escalation.
7
CVE-2025-14304 - ASRock, ASRockRack, ASRockInd|Motherboard - Protection Mechanism Failure
Certain motherboard models developed by ASRock and its subsidiaries, ASRockRack and ASRockInd. has a Protection Mechanism Failure vulnerability. Because IOMMU was not properly enabled, unauthenticated physical attackers can use a DMA-capable PCIe device to read and write arbitrary physical memory b…
6.4
CVE-2025-13977 - Essential Addons for Elementor – Popular Elementor Templates & Widgets <= 6.5.3 - Authenticated (Co…
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple attack vectors in all versions up to, and including, 6.5.3. This is due to insufficient input sanitization and output escaping in the Event Calen…
7
CVE-2025-14303 - MSI|Motherboard - Protection Mechanism Failure
Certain motherboard models developed by MSI has a Protection Mechanism Failure vulnerability. Because IOMMU was not properly enabled, unauthenticated physical attackers can use a DMA-capable PCIe device to read and write arbitrary physical memory before the OS kernel and its security features are l…
7
CVE-2025-14302 - GIGABYTE|Motherboard - Protection Mechanism Failure
Certain motherboard models developed by GIGABYTE has a Protection Mechanism Failure vulnerability. Because IOMMU was not properly enabled, unauthenticated physical attackers can use a DMA-capable PCIe device to read and write arbitrary physical memory before the OS kernel and its security features …
4.8
CVE-2025-14801 - xiweicheng TMS create createComment cross site scripting
A security vulnerability has been detected in xiweicheng TMS up to 2.28.0. This affects the function createComment of the file /admin/blog/comment/create. Such manipulation of the argument content leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed…
4.3
CVE-2025-11369 - Essential Blocks <= 5.7.2 - Missing Authorization To Authenticated (Author+) Information Disclosure
The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to unauthorized access of data due to a missing or incorrect capability checks on the get_instagram_access_token_callback, google_map_api_key_save_callback and get_siteinfo functions in …
5.1
CVE-2025-11009 - Information Disclosure Vulnerability in GT Designer3
Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GT Designer3 Version1 (GOT2000) all versions and Mitsubishi Electric GT Designer3 Version1 (GOT1000) all versions allows a local unauthenticated attacker to obtain plaintext credentials from the project file for GT Desi…
8.4
CVE-2025-53524 - Fuji Electric Monitouch V-SFT-6 Out-of-bounds Write
Fuji Electric Monitouch V-SFT-6 is vulnerable to an out-of-bounds write while processing a specially crafted project file, which may allow an attacker to execute arbitrary code.