7.1

CVSS4.0

CVE-2025-9256 - Uniong|WebITR - Arbitrary File Reading through Path Traversal

WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary system files.

📅 Published: Aug. 22, 2025, 11:34 a.m. 🔄 Last Modified: Nov. 6, 2025, 10:06 p.m.

8.7

CVSS4.0

CVE-2025-9255 - Uniong|WebITR - SQL Injection

WebITR developed by Uniong has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.

📅 Published: Aug. 22, 2025, 11:25 a.m. 🔄 Last Modified: Nov. 6, 2025, 10:06 p.m.

9.3

CVSS4.0

CVE-2025-9254 - Uniong|WebITR - Missing Authentication

WebITR developed by Uniong has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to log into the system as arbitrary users by exploiting a specific functionality.

📅 Published: Aug. 22, 2025, 11:21 a.m. 🔄 Last Modified: Nov. 6, 2025, 10:06 p.m.

4.3

CVSS3.1

CVE-2025-9331 - Spacious <= 1.9.11 - Missing Authorization to Autheticated (Subscriber+) Demo Data Import

The Spacious theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'welcome_notice_import_handler' function in all versions up to, and including, 1.9.11. This makes it possible for authenticated attackers, with Subscriber-level access and ab…

📅 Published: Aug. 22, 2025, 11:14 a.m. 🔄 Last Modified: April 22, 2026, 5 p.m.

0

CVSS4.0

CVE-2025-9340 - native encrypt/decrypt operations in JCE may corrupt data if same byte array used for input and out…

Out-of-bounds Write vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java bc-fips on All (API modules). This vulnerability is associated with program files org/bouncycastle/jcajce/provider/BaseCipher. This issue affects Bouncy Castle for Java: from BC-FJA 2.1.0 through 2.1.0.

📅 Published: Aug. 22, 2025, 9:39 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS4.0

CVE-2025-9341 - Garbage collection can delay for AES CBC Native support, resulting in heap exhaustion

Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS bc-fips on All (API modules), Legion of the Bouncy Castle Inc. Bouncy Castle for Java LTS bcprov-lts8on on All (API modules) allows Excessive Allocation. This vulnerability is associated …

📅 Published: Aug. 22, 2025, 9:09 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS3.1

CVE-2025-8678 - WP Crontrol - 1.17.0 - 1.19.1 - Authenticated (Administrator+) Blind Server-Side Request Forgery

The WP Crontrol plugin for WordPress is vulnerable to blind Server-Side Request Forgery in versions 1.17.0 to 1.19.1 via the 'wp_remote_request' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations origi…

📅 Published: Aug. 22, 2025, 7:24 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.4

CVSS4.0

CVE-2025-57699 -

Western Digital Kitfox for Windows provided by Western Digital Corporation registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the system drive may execute arbitrary code with the SYSTEM privilege.

📅 Published: Aug. 22, 2025, 6:37 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS3.1

CVE-2025-8281 - WP Talroo <= 2.4 - Reflected XSS

The WP Talroo WordPress plugin through 2.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin and unauthenticated users.

📅 Published: Aug. 22, 2025, 6 a.m. 🔄 Last Modified: Jan. 16, 2026, 9:05 p.m.

6.8

CVSS4.0

CVE-2025-41452 - Post auth nginx configuration injection in Danfoss AK-SM8xxA Series

Post-authenticated external control of system web interface configuration setting vulnerability in Danfoss AK-SM8xxA Series prior to 4.3.1, which could allow for a denial of service attack induced by improper handling of exceptional conditions

📅 Published: Aug. 22, 2025, 2:40 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4165 of 34,919
« previous page » next page
Filters