6

CVSS4.0

CVE-2025-64346 - archives: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

archives is a Go library for extracting archives (tar, zip, etc.). Version 1.0.0 does not prevent a malicious user to feed a specially crafted archive to the library causing RCE, modification of files or other malignancies in the context of whatever the user is running this library as, through the โ€ฆ

๐Ÿ“… Published: Nov. 7, 2025, 5:32 a.m. ๐Ÿ”„ Last Modified: Nov. 7, 2025, 10:53 a.m.

4.3

CVSS3.1

CVE-2025-12527 - Page & Post Notes <= 1.3.4 - Missing Authorization to Authenticated (Subscriber+) Note Update/Deletโ€ฆ

The Page & Post Notes plugin for WordPress is vulnerable to unauthorized modification of notes due to a missing capability check on the 'yydev_notes_save_dashboard_data' function in all versions up to, and including, 1.3.4. This makes it possible for authenticated attackers, with Subscriber-level aโ€ฆ

๐Ÿ“… Published: Nov. 7, 2025, 5:29 a.m. ๐Ÿ”„ Last Modified: Nov. 7, 2025, 10:53 a.m.

4

CVSS3.1

CVE-2025-12520 - WP Airbnb Review Slider <= 4.2 - Authenticated (Admin+) Stored Cross-Site Scripting

The WP Airbnb Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.2 due to insufficient URL validation that allows users to pull in a malicious HTML file. This makes it possible for authenticated attackers, with โ€ฆ

๐Ÿ“… Published: Nov. 7, 2025, 5:29 a.m. ๐Ÿ”„ Last Modified: Nov. 7, 2025, 10:53 a.m.

7.8

CVSS3.1

CVE-2025-64343 - (conda) Constructor: Excessive permissions during and after installation

(conda) Constructor is a tool that enables users to create installers for conda package collections. In versions 3.12.2 and below, the installation directory inherits permissions from its parent directory. Outside of restricted directories, the permissions are very permissive and often allow writeโ€ฆ

๐Ÿ“… Published: Nov. 7, 2025, 5:20 a.m. ๐Ÿ”„ Last Modified: Nov. 7, 2025, 10:53 a.m.

7.2

CVSS4.0

CVE-2025-64339 - ClipBucket v5: Stored XSS Vulnerability in Manage Playlists

ClipBucket v5 is an open source video sharing platform. In versions 5.5.2-#146 and below, the Manage Playlists feature is vulnerable to stored Cross-site Scripting (XSS),specifically in the Playlist Name field. An authenticated low-privileged user can create a playlist with a malicious name containโ€ฆ

๐Ÿ“… Published: Nov. 7, 2025, 5:12 a.m. ๐Ÿ”„ Last Modified: Nov. 7, 2025, 10:53 a.m.

7.2

CVSS4.0

CVE-2025-64336 - ClipBucket v5's Manage Photo Feature is Vulnerable to Stored XSS Attack via Photo Title

ClipBucket v5 is an open source video sharing platform. In versions 5.5.2-#146 and below, the Manage Photos feature is vulnerable to stored Cross-site Scripting (XSS). An authenticated regular user can upload a photo with a malicious Photo Title containing HTML/JavaScript code. While the payload doโ€ฆ

๐Ÿ“… Published: Nov. 7, 2025, 4:32 a.m. ๐Ÿ”„ Last Modified: Nov. 7, 2025, 10:53 a.m.

6.5

CVSS3.1

CVE-2025-4522 - IDonate 2.0.0 - 2.1.9 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Uโ€ฆ

The IDonate โ€“ Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Insecure Direct Object Reference via the admin_post_donor_delete() function in versions 2.0.0 to 2.1.9. By supplying an arbitrary user_id parameter value to the wp_delete_user() function, authentโ€ฆ

๐Ÿ“… Published: Nov. 7, 2025, 4:28 a.m. ๐Ÿ”„ Last Modified: Nov. 7, 2025, 10:53 a.m.

8.8

CVSS3.1

CVE-2025-4519 - IDonate 2.1.5 - 2.1.9 - Missing Authorization to Authenticated (Subscriber+) Account Takeover/Priviโ€ฆ

The IDonate โ€“ Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the idonate_donor_password() function in versions 2.1.5 to 2.1.9. This makes it possible for authenticated attackers, with Subscriber-levโ€ฆ

๐Ÿ“… Published: Nov. 7, 2025, 4:28 a.m. ๐Ÿ”„ Last Modified: Nov. 7, 2025, 10:53 a.m.

9.8

CVSS3.1

CVE-2025-12352 - Gravity Forms <= 2.9.20 - Unauthenticated Arbitrary File Upload via 'copy_post_image'

The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the copy_post_image() function in all versions up to, and including, 2.9.20. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's seโ€ฆ

๐Ÿ“… Published: Nov. 7, 2025, 4:28 a.m. ๐Ÿ”„ Last Modified: Nov. 7, 2025, 10:53 a.m.

6.9

CVSS4.0

CVE-2025-64329 - containerd CRI server: Host memory exhaustion through Attach goroutine leak

containerd is an open-source container runtime. Versions 1.7.28 and below, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4, and 2.2.0-beta.0 through 2.2.0-rc.1 contain a bug in the CRI Attach implementation where a user can exhaust memory on the host due to goroutine leaks. This issue is fixโ€ฆ

๐Ÿ“… Published: Nov. 7, 2025, 4:15 a.m. ๐Ÿ”„ Last Modified: Nov. 7, 2025, 10:53 a.m.
Total resulsts: 317328
Page 4 of 31,733
ยซ previous page ยป next page
Filters