8.8

CVSS3.1

CVE-2025-7689 - Hydra Booking 1.1.0 - 1.1.18 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalโ€ฆ

The Hydra Booking plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the tfhb_reset_password_callback() function in versions 1.1.0 to 1.1.18. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset the passworโ€ฆ

๐Ÿ“… Published: July 29, 2025, 9:23 a.m. ๐Ÿ”„ Last Modified: July 30, 2025, 6:17 a.m.

6.4

CVSS3.1

CVE-2025-6681 - Fan Page <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via width Parameter

The Fan Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the โ€˜widthโ€™ parameter in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and abovโ€ฆ

๐Ÿ“… Published: July 29, 2025, 9:23 a.m. ๐Ÿ”„ Last Modified: July 30, 2025, 6:15 a.m.

6.4

CVSS3.1

CVE-2025-8196 - Magical Addons For Elementor <= 1.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting viโ€ฆ

The Magical Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Custom Attributes in all versions up to, and including, 1.3.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenโ€ฆ

๐Ÿ“… Published: July 29, 2025, 9:23 a.m. ๐Ÿ”„ Last Modified: July 30, 2025, 11:10 a.m.

4.3

CVSS3.1

CVE-2025-6730 - Bonanza โ€“ WooCommerce Free Gifts Lite <= 1.0.0 - Missing Authorization to Authenticated (Subscriberโ€ฆ

The Bonanza โ€“ WooCommerce Free Gifts Lite plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the xlo_optin_call() function in all versions up to, and including, 1.0.0. This makes it possible for authenticated attackers, with Subscriber-levelโ€ฆ

๐Ÿ“… Published: July 29, 2025, 9:23 a.m. ๐Ÿ”„ Last Modified: July 30, 2025, 11:10 a.m.

6.4

CVSS3.1

CVE-2025-8216 - Sky Addons for Elementor <= 3.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Muโ€ฆ

The Sky Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Multiple widgets in all versions up to, and including, 3.1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,โ€ฆ

๐Ÿ“… Published: July 29, 2025, 9:23 a.m. ๐Ÿ”„ Last Modified: July 30, 2025, 11:10 a.m.

5.3

CVSS3.1

CVE-2025-26400 - SolarWinds Web Help Desk XML External Entity Injection (XXE) Vulnerability

SolarWinds Web Help Desk was reported to be affected by an XML External Entity Injection (XXE) vulnerability that could lead to information disclosure. A valid, low-privilege access is required unless the attacker had access to the local server to modify configuration files.

๐Ÿ“… Published: July 29, 2025, 8:07 a.m. ๐Ÿ”„ Last Modified: July 30, 2025, 6:15 a.m.

6.1

CVSS3.1

CVE-2025-53082 -

An 'Arbitrary File Deletion' in Samsung DMS(Data Management Server) allows attackers to delete arbitrary files from unintended locations on the filesystem. Exploitation is restricted to specific, authorized private IP addresses.

๐Ÿ“… Published: July 29, 2025, 5:08 a.m. ๐Ÿ”„ Last Modified: July 30, 2025, 11:10 a.m.

6.4

CVSS3.1

CVE-2025-53081 -

An 'Arbitrary File Creation' in Samsung DMS(Data Management Server) allows attackers to create arbitrary files in unintended locations on the filesystem. Exploitation is restricted to specific, authorized private IP addresses.

๐Ÿ“… Published: July 29, 2025, 5:06 a.m. ๐Ÿ”„ Last Modified: July 30, 2025, 11:10 a.m.

7.1

CVSS3.1

CVE-2025-53080 -

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Samsung DMS(Data Management Server) allows authenticated attackers to create arbitrary files in unintended locations on the filesystem

๐Ÿ“… Published: July 29, 2025, 5:05 a.m. ๐Ÿ”„ Last Modified: July 30, 2025, 6:15 a.m.

4.9

CVSS3.1

CVE-2025-53079 -

Absolute Path Traversal in Samsung DMS(Data Management Server) allows authenticated attacker (Administrator) to read sensitive files

๐Ÿ“… Published: July 29, 2025, 5:04 a.m. ๐Ÿ”„ Last Modified: July 30, 2025, 6:15 a.m.
Total resulsts: 303937
Page 41 of 30,394
ยซ previous page ยป next page
Filters