6.4

CVSS3.1

CVE-2025-9131 - Ogulo – 360° Tour <= 1.0.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via slug Par…

The Ogulo – 360° Tour plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘slug’ parameter in all versions up to, and including, 1.0.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access…

📅 Published: Aug. 23, 2025, 4:25 a.m. 🔄 Last Modified: April 22, 2026, 5 p.m.

9.8

CVSS3.1

CVE-2025-7642 - Simpler Checkout 0.7.0 - 1.1.9 - Authentication Bypass

The Simpler Checkout plugin for WordPress is vulnerable to Authentication Bypass in versions 0.7.0 to 1.1.9. This is due to the plugin not properly verifying a user's identity prior to logging them in as an admin through the simplerwc_woocommerce_order_created() function. This makes it possible for…

📅 Published: Aug. 23, 2025, 4:25 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS4.0

CVE-2025-43766 -

The Liferay Portal 7.4.0 through 7.3.3.131, and Liferay DXP 2024.Q4.0, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows the upload of unrestricted files in the style books component that are processed within the environment…

📅 Published: Aug. 23, 2025, 4:17 a.m. 🔄 Last Modified: Dec. 12, 2025, 8:08 p.m.

5.1

CVSS4.0

CVE-2025-43767 -

Open Redirect vulnerability in /c/portal/edit_info_item parameter redirect in Liferay Portal 7.4.3.86 through 7.4.3.131, and Liferay DXP 2024.Q3.1 through 2024.Q3.9, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 update 86 through update 92 allows an attacker to exploit this sec…

📅 Published: Aug. 23, 2025, 3:41 a.m. 🔄 Last Modified: Dec. 12, 2025, 8:09 p.m.

5.1

CVSS4.0

CVE-2025-43768 -

Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 GA through update 92 allows authenticated users without any permissions to access sensitive information of admin user…

📅 Published: Aug. 23, 2025, 3:04 a.m. 🔄 Last Modified: Dec. 12, 2025, 8:10 p.m.

4.6

CVSS4.0

CVE-2025-43769 -

Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q3.1 through 2024.Q3.8, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows remote attackers to execute arbitrary web script or HTML via compone…

📅 Published: Aug. 23, 2025, 2:49 a.m. 🔄 Last Modified: Dec. 12, 2025, 8:10 p.m.

6.9

CVSS4.0

CVE-2025-43770 -

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.3, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows an remote non-authenticated …

📅 Published: Aug. 23, 2025, 1:03 a.m. 🔄 Last Modified: Dec. 12, 2025, 8:10 p.m.

9.6

CVSS3.1

CVE-2025-4609 -

Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 136.0.7103.113 allowed a remote attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

📅 Published: Aug. 22, 2025, 9:05 p.m. 🔄 Last Modified: Feb. 26, 2026, 5:48 p.m.

8.7

CVSS4.0

CVE-2025-9356 - Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 inboundFilterAdd stack-based overflow

A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected by this issue is the function inboundFilterAdd of the file /goform/inboundFilterAdd. Executing manipulation of the argument ruleName can lead…

📅 Published: Aug. 22, 2025, 9:02 p.m. 🔄 Last Modified: Sept. 2, 2025, 6:19 p.m.

8.7

CVSS4.0

CVE-2025-9355 - Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 scheduleAdd stack-based overflow

A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected by this vulnerability is the function scheduleAdd of the file /goform/scheduleAdd. Performing manipulation of the argument ruleName results in sta…

📅 Published: Aug. 22, 2025, 9:02 p.m. 🔄 Last Modified: Sept. 2, 2025, 6:20 p.m.
Total resulsts: 349182
Page 4159 of 34,919
« previous page » next page
Filters