5.5

CVSS3.1

CVE-2025-7387 - Lana Downloads Manager <= 1.10.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

The Lana Downloads Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the endpoint parameters in versions up to, and including, 1.10.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackerโ€ฆ

๐Ÿ“… Published: July 10, 2025, 5:24 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.6

CVSS3.1

CVE-2025-46406 -

A Privilege Context Switching Error (CWE-270) in the Command Center Server could allow a privileged Operator with high level access in one Division to perform limited privileged activities across the Division boundary. This issue affects Command Centre Server: 9.30 prior to 9.30.1874ย (MR1), 9.20โ€ฆ

๐Ÿ“… Published: July 10, 2025, 3:10 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-44003 -

Missing Release of Resource after Effective Lifetime (CWE-772) in the Gallagher T-Series Reader allows an attacker with physical access to the reader to perform a limited denial of service when 125 kHz Card Technology is enabled. This issue affects T-Series Readers: 9.20 prior to vCR9.20.250213a (โ€ฆ

๐Ÿ“… Published: July 10, 2025, 3:09 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-35983 -

Improper Certificate Validation (CWE-295) in the Controller 7000 OneLink implementation could allow an unprivileged attacker to perform a limited denial of service or perform privileged overrides during the initial configuration of the Controller, there is no risk for Controllers once they are connโ€ฆ

๐Ÿ“… Published: July 10, 2025, 3:09 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-5807 - Gwolle Guestbook <= 4.9.2 - Unauthenticated Stored Cross-Site Scripting via `gwolle_gb_content` Parโ€ฆ

The Gwolle Guestbook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the โ€˜gwolle_gb_contentโ€™ parameter in all versions up to, and including, 4.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitraโ€ฆ

๐Ÿ“… Published: July 10, 2025, 1:43 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-4406 - wpForo Forum <= 2.4.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Profile Avatar

The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.4.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above,โ€ฆ

๐Ÿ“… Published: July 10, 2025, 1:43 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.4

CVSS3.1

CVE-2025-27889 -

Wing FTP Server before 7.4.4 does not properly validate and sanitize the url parameter of the downloadpass.html endpoint, allowing injection of an arbitrary link. If a user clicks a crafted link, this discloses a cleartext password to the attacker.

๐Ÿ“… Published: July 10, 2025, midnight ๐Ÿ”„ Last Modified: July 17, 2025, 1:31 p.m.

5.5

CVSS3.1

CVE-2025-38303 - Bluetooth: eir: Fix possible crashes on eir_create_adv_data

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: eir: Fix possible crashes on eir_create_adv_data eir_create_adv_data may attempt to add EIR_FLAGS and EIR_TX_POWER without checking if that would fit.

๐Ÿ“… Published: July 10, 2025, midnight ๐Ÿ”„ Last Modified: April 11, 2026, 1:16 p.m.

5.5

CVSS3.1

CVE-2025-38335 - Input: gpio-keys - fix a sleep while atomic with PREEMPT_RT

In the Linux kernel, the following vulnerability has been resolved: Input: gpio-keys - fix a sleep while atomic with PREEMPT_RT When enabling PREEMPT_RT, the gpio_keys_irq_timer() callback runs in hard irq context, but the input_event() takes a spin_lock, which isn't allowed there as it is converโ€ฆ

๐Ÿ“… Published: July 10, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 16, 2025, 5:51 p.m.

5.5

CVSS3.1

CVE-2025-38319 - drm/amd/pp: Fix potential NULL pointer dereference in atomctrl_initialize_mc_reg_table

In the Linux kernel, the following vulnerability has been resolved: drm/amd/pp: Fix potential NULL pointer dereference in atomctrl_initialize_mc_reg_table The function atomctrl_initialize_mc_reg_table() and atomctrl_initialize_mc_reg_table_v2_2() does not check the return value of smu_atom_get_daโ€ฆ

๐Ÿ“… Published: July 10, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 19, 2025, 4:44 p.m.
Total resulsts: 345151
Page 4288 of 34,516
ยซ previous page ยป next page
Filters