7.1

CVSS4.0

CVE-2025-13823 - Micro820®, Micro850®, Micro870® – Specialized Fuzzing Vulnerabilities

A security issue was found in the IPv6 stack in the Micro850 and Micro870 controllers when the controllers received multiple malformed packets during fuzzing. The controllers will go into recoverable fault with fault code 0xFE60. To recover the controller, clear the fault.

📅 Published: Dec. 15, 2025, 3:17 p.m. 🔄 Last Modified: Dec. 15, 2025, 9:33 p.m.

6.9

CVSS4.0

CVE-2025-34412 - Convercent Whistleblowing Platform Protection Mechanism Failure Insecure Default Browser & Session …

The Convercent Whistleblowing Platform operated by EQS Group contains a protection mechanism failure in its browser and session handling. By default, affected deployments omit HTTP security headers such as Content-Security-Policy, Referrer-Policy, Permissions-Policy, Cross-Origin-Embedder-Policy, C…

📅 Published: Dec. 15, 2025, 2:44 p.m. 🔄 Last Modified: Dec. 15, 2025, 6:22 p.m.

6.9

CVSS4.0

CVE-2025-34411 - Convercent Whistleblowing Platform Unauthenticated GetLegalEntity Endpoint Enables Customer Enumera…

The Convercent Whistleblowing Platform operated by EQS Group exposes an unauthenticated API endpoint at /GetLegalEntity that returns internal customer legal-entity names based on a supplied searchText fragment. A remote unauthenticated attacker can query the endpoint using common legal-suffix terms…

📅 Published: Dec. 15, 2025, 2:43 p.m. 🔄 Last Modified: Dec. 15, 2025, 6:22 p.m.

8.7

CVSS4.0

CVE-2025-34181 - NetSupport Manager < 14.12.0001 Authenticated Path Traversal Arbitrary File Write RCE

NetSupport Manager < 14.12.0001 contains an arbitrary file write vulnerability in its Connectivity Server/Gateway PUTFILE request handler. An attacker with a valid Gateway Key can supply a crafted filename containing directory traversal sequences to write files to arbitrary locations on the server.…

📅 Published: Dec. 15, 2025, 2:42 p.m. 🔄 Last Modified: Dec. 15, 2025, 9:33 p.m.

8.4

CVSS4.0

CVE-2025-34180 - NetSupport Manager < 14.12.0001 Gateway Key Reversible Encoding Credential Recovery

NetSupport Manager < 14.12.0001 relies on a shared Gateway Key for authentication between Manager/Control, Client, and Connectivity Server components. The key is stored using a reversible encoding scheme. An attacker who obtains access to a deployed client configuration file can decode the stored …

📅 Published: Dec. 15, 2025, 2:41 p.m. 🔄 Last Modified: Dec. 15, 2025, 9:33 p.m.

8.7

CVSS4.0

CVE-2025-34179 - NetSupport Manager < 14.12.0001 Unauthenticated SQLi Local File Disclosure

NetSupport Manager < 14.12.0001 contains an unauthenticated SQL injection vulnerability in its Connectivity Server/Gateway HTTPS request handling. The server evaluates request URIs using an unsanitized SQLite query against the FileLinks table in gateway.db. By injecting SQL through the LinkName/URI…

📅 Published: Dec. 15, 2025, 2:41 p.m. 🔄 Last Modified: Dec. 15, 2025, 9:33 p.m.

9.8

CVSS3.1

CVE-2025-14156 - Fox LMS – WordPress LMS Plugin 1.0.4.7 - 1.0.5.1 - Unauthenticated Privilege Escalation via 'create…

The Fox LMS – WordPress LMS Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.5.1. This is due to the plugin not properly validating the 'role' parameter when creating new users via the `/fox-lms/v1/payments/create-order` REST API endpoint. …

📅 Published: Dec. 15, 2025, 2:25 p.m. 🔄 Last Modified: Dec. 15, 2025, 9:33 p.m.

5.3

CVSS3.1

CVE-2025-13950 - OneSignal – Web Push Notifications <= 3.6.1 - Missing Authorization to Unauthenticated Plugin Setti…

The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the settings handling functionality in all versions up to, and including, 3.6.1. This is due to the plugin processing POST requests without verifying u…

📅 Published: Dec. 15, 2025, 2:25 p.m. 🔄 Last Modified: Dec. 15, 2025, 9:33 p.m.

6.4

CVSS3.1

CVE-2025-13728 - FluentAuth - Auth Security Plugin <= 2.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripti…

The FluentAuth – The Ultimate Authorization & Security Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `fluent_auth_reset_password` shortcode in all versions up to, and including, 2.0.3 due to insufficient input sanitization and output escapin…

📅 Published: Dec. 15, 2025, 2:25 p.m. 🔄 Last Modified: Dec. 15, 2025, 6:22 p.m.

7.5

CVSS3.1

CVE-2025-14383 - Booking Calendar <= 10.14.8 - Unauthenticated SQL Injection via dates_to_check

The Booking Calendar plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'dates_to_check' parameter in all versions up to, and including, 10.14.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This m…

📅 Published: Dec. 15, 2025, 2:25 p.m. 🔄 Last Modified: Dec. 15, 2025, 9:33 p.m.
Total resulsts: 322763
Page 43 of 32,277
« previous page » next page
Filters