3.8

CVSS3.1

CVE-2025-8889 - Compress Then Upload < 1.0.5 - Admin+ Arbitrary File Upload

The Compress & Upload WordPress plugin before 1.0.5 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

πŸ“… Published: Sept. 9, 2025, 6 a.m. πŸ”„ Last Modified: Jan. 30, 2026, 8:38 p.m.

6.4

CVSS3.1

CVE-2025-9058 - Mikado Core <= 1.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Mikado Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level …

πŸ“… Published: Sept. 9, 2025, 5:25 a.m. πŸ”„ Last Modified: April 20, 2026, 7:45 p.m.

6.4

CVSS3.1

CVE-2025-9061 - Wilmer Core <= 2.4.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Wilmer Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 2.4.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level …

πŸ“… Published: Sept. 9, 2025, 5:25 a.m. πŸ”„ Last Modified: April 21, 2026, 7:15 p.m.

5

CVSS3.1

CVE-2025-9489 - WP-Members Membership Plugin <= 3.5.4.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution…

The The WP-Members Membership Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.5.4.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it …

πŸ“… Published: Sept. 9, 2025, 4:25 a.m. πŸ”„ Last Modified: April 20, 2026, 7:45 p.m.

5.1

CVSS4.0

CVE-2025-43777 -

Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.19 exposes "Internal Server Error" in the response body when a lo…

πŸ“… Published: Sept. 9, 2025, 3 a.m. πŸ”„ Last Modified: Dec. 12, 2025, 8:29 p.m.

6.9

CVSS4.0

CVE-2025-10123 - D-Link DIR-823X set_static_leases sub_415028 command injection

A vulnerability was determined in D-Link DIR-823X up to 250416. Affected by this vulnerability is the function sub_415028 of the file /goform/set_static_leases. Executing manipulation of the argument Hostname can lead to command injection. The attack can be launched remotely. The exploit has been p…

πŸ“… Published: Sept. 9, 2025, 2:32 a.m. πŸ”„ Last Modified: Sept. 24, 2025, 6:43 p.m.

5.1

CVSS4.0

CVE-2025-10122 - Maccms10 Database.php rep sql injection

A vulnerability was found in Maccms10 2025.1000.4050. Affected is the function rep of the file application/admin/controller/Database.php. Performing manipulation of the argument where results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.

πŸ“… Published: Sept. 9, 2025, 2:32 a.m. πŸ”„ Last Modified: Oct. 8, 2025, 2:23 p.m.

9.1

CVSS3.1

CVE-2025-42958 - Missing Authentication check in SAP NetWeaver

Due to a missing authentication check in the SAP NetWeaver application on IBM i-series, the application allows high privileged unauthorized users to read, modify, or delete sensitive information, as well as access administrative or privileged functionalities. This results in a high impact on the co…

πŸ“… Published: Sept. 9, 2025, 2:11 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:49 p.m.

10

CVSS3.1

CVE-2025-42944 - Insecure Deserialization vulnerability in SAP Netweaver (RMI-P4)

Due to a deserialization vulnerability in SAP NetWeaver, an unauthenticated attacker could exploit the system through the RMI-P4 module by submitting malicious payload to an open port. The deserialization of such untrusted Java objects could lead to arbitrary OS command execution, posing a high imp…

πŸ“… Published: Sept. 9, 2025, 2:11 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-42938 - Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform

Due to a Cross-Site Scripting (XSS) vulnerability in the SAP NetWeaver ABAP Platform, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated user clicks on this link, the injected input is processed during the websiteοΏ½s page generation, resu…

πŸ“… Published: Sept. 9, 2025, 2:11 a.m. πŸ”„ Last Modified: Sept. 9, 2025, 9:31 p.m.
Total resulsts: 349182
Page 3952 of 34,919
Β« previous page Β» next page
Filters