8.7

CVSS4.0

CVE-2025-9298 - Tenda M3 QuickIndex formQuickIndex stack-based overflow

A flaw has been found in Tenda M3 1.0.0.12. Affected is the function formQuickIndex of the file /goform/QuickIndex. Executing manipulation of the argument PPPOEPassword can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been published and may be used.

πŸ“… Published: Aug. 21, 2025, 12:32 p.m. πŸ”„ Last Modified: Aug. 25, 2025, 1:59 a.m.

8.7

CVSS4.0

CVE-2025-9297 - Tenda i22 wxportalauth formWeixinAuthInfoGet stack-based overflow

A vulnerability was detected in Tenda i22 1.0.0.3(4687). This impacts the function formWeixinAuthInfoGet of the file /goform/wxportalauth. Performing manipulation of the argument Type results in stack-based buffer overflow. The attack can be initiated remotely. The exploit is now public and may be …

πŸ“… Published: Aug. 21, 2025, 12:02 p.m. πŸ”„ Last Modified: Sept. 3, 2025, 2:59 p.m.

5.1

CVSS4.0

CVE-2025-9296 - Emlog Pro blogger.php unrestricted upload

A security vulnerability has been detected in Emlog Pro up to 2.5.18. This affects an unknown function of the file /admin/blogger.php?action=update_avatar. Such manipulation of the argument image leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclo…

πŸ“… Published: Aug. 21, 2025, 11:32 a.m. πŸ”„ Last Modified: Sept. 12, 2025, 1:10 p.m.

6.4

CVSS3.1

CVE-2025-8064 - Bible SuperSearch <= 6.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via selector_…

The Bible SuperSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜selector_height’ parameter in all versions up to, and including, 6.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-le…

πŸ“… Published: Aug. 21, 2025, 9:26 a.m. πŸ”„ Last Modified: April 22, 2026, 5 p.m.

4.3

CVSS3.1

CVE-2025-47870 - Team invite ID leaked to team admin with no member invite privileges

Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fail to sanitize the team invite ID in the POST /api/v4/teams/:teamId/restore endpoint which allows an team admin with no member invite privileges to get the team’s invite id.

πŸ“… Published: Aug. 21, 2025, 8:02 a.m. πŸ”„ Last Modified: Aug. 22, 2025, 6:09 p.m.

6.8

CVSS3.1

CVE-2025-49222 - Mattermost Shared Channel Upload Type Validation Bypass

Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2, 10.10.x <= 10.10.0 fail to validate upload types in remote cluster upload sessions which allows a system admin to upload non-attachment file types via shared channels that could potentially be placed in arb…

πŸ“… Published: Aug. 21, 2025, 7:59 a.m. πŸ”„ Last Modified: Aug. 22, 2025, 6:09 p.m.

6.8

CVSS3.1

CVE-2025-8023 - Path Traversal in Template Upload Allows Uploading Files Outside Target Directory

Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fails to sanitize path traversal sequences in template file destination paths, which allows a system admin to perform path traversal attacks via malicious path components, potentially enabling malicious file…

πŸ“… Published: Aug. 21, 2025, 7:51 a.m. πŸ”„ Last Modified: Aug. 25, 2025, 2:56 p.m.

3.8

CVSS3.1

CVE-2025-53971 - Channel and Team Membership APIs inadvertently allow loss of Member privileges.

Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate authorization for team scheme role modifications which allows Team Admins to demote Team Members to Guests via the PUT /api/v4/teams/team-id/members/user-id/schemeRoles API endpoint.

πŸ“… Published: Aug. 21, 2025, 7:31 a.m. πŸ”„ Last Modified: Aug. 22, 2025, 6:09 p.m.

3.5

CVSS3.1

CVE-2025-47700 - AI plugin APIs can be triggered using post actions

Mattermost Server versions 10.5.x <= 10.5.9 utilizing the Agents plugin fail to reject empty request bodies which allows users to trick users into clicking malicious links via post actions

πŸ“… Published: Aug. 21, 2025, 7:28 a.m. πŸ”„ Last Modified: Oct. 29, 2025, 6:40 p.m.

9.8

CVSS3.1

CVE-2025-8895 - WP Webhooks <= 3.3.5 - Unauthenticated Arbitrary File Copy

The WP Webhooks plugin for WordPress is vulnerable to arbitrary file copy due to missing validation of user-supplied input in all versions up to, and including, 3.3.5. This makes it possible for unauthenticated attackers to copy arbitrary files on the affected site's server to arbitrary locations. …

πŸ“… Published: Aug. 21, 2025, 7:26 a.m. πŸ”„ Last Modified: April 20, 2026, 8 p.m.
Total resulsts: 349182
Page 4185 of 34,919
Β« previous page Β» next page
Filters