6.4

CVSS3.1

CVE-2025-24329 - OAM service path traversal issue caused by a crafted SOAP message archive field within the RAN manaโ€ฆ

Sending a crafted SOAP "provision" operation message archive field within the Mobile Network Operator (MNO) internal Radio Access Network (RAN) management network can cause path traversal issue in Nokia Single RAN baseband software with versions earlier than release 24R1-SR 1.0 MP. This issue has bโ€ฆ

๐Ÿ“… Published: July 2, 2025, 8:27 a.m. ๐Ÿ”„ Last Modified: July 3, 2025, 3:13 p.m.

4.2

CVSS3.1

CVE-2025-24328 - OAM service stack overflow caused by crafted SOAP message within the MNO internal RAN management neโ€ฆ

Sending a crafted SOAP "set" operation message within the Mobile Network Operator (MNO) internal Radio Access Network (RAN) management network can cause Nokia Single RAN baseband OAM service component restart with software versions earlier than release 24R1-SR 1.0 MP. This issue has been corrected โ€ฆ

๐Ÿ“… Published: July 2, 2025, 7:39 a.m. ๐Ÿ”„ Last Modified: July 3, 2025, 3:13 p.m.

9.8

CVSS3.1

CVE-2024-13786 - Education Center | LMS & Online Courses WordPress Theme <= 3.6.10 - PHP Object Injection

The education theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.6.10 via deserialization of untrusted input in the 'themerex_callback_view_more_posts' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP โ€ฆ

๐Ÿ“… Published: July 2, 2025, 6:40 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:24 p.m.

5.5

CVSS3.1

CVE-2025-6017 - Rhacm: users with clusterreader role can see credentials from managed-clusters

A flaw was found in Red Hat Advanced Cluster Management through versions 2.10, before 2.10.7, 2.11, before 2.11.4, and 2.12, before 2.12.4. This vulnerability allows an unprivileged user to view confidential managed cluster credentials through the UI. This information should only be accessible to aโ€ฆ

๐Ÿ“… Published: July 2, 2025, 6:33 a.m. ๐Ÿ”„ Last Modified: Nov. 20, 2025, 9:07 p.m.

5.3

CVSS3.1

CVE-2024-13451 - Contact Form by Bit Form <= 2.17.5 - Unauthenticated Sensitive Information Exposure

The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.17.4 via file uploads due to insufficient directory listing prevenโ€ฆ

๐Ÿ“… Published: July 2, 2025, 5:29 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:16 p.m.

7.5

CVSS3.1

CVE-2025-6464 - Forminator Forms โ€“ Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated PHPโ€ฆ

The Forminator Forms โ€“ Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.44.2 via deserialization of untrusted input in the 'entry_delete_upload_files' function. This makes it possible for unauthenticaโ€ฆ

๐Ÿ“… Published: July 2, 2025, 5:29 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:58 p.m.

2.1

CVSS4.0

CVE-2025-52463 -

Cross-site request forgery vulnerability exists in Active! mail 6 BuildInfo: 6.60.06008562 and earlier. If this vulnerability is exploited, unintended E-mail may be sent when a user accesses a specially crafted URL while being logged in.

๐Ÿ“… Published: July 2, 2025, 5:02 a.m. ๐Ÿ”„ Last Modified: July 3, 2025, 3:13 p.m.

5.1

CVSS4.0

CVE-2025-52462 -

Cross-site scripting vulnerability exists in Active! mail 6 BuildInfo: 6.30.01004145 to 6.60.06008562. If this vulnerability is exploited, an arbitrary script may be executed on the logged-in user's web browser when the user is accessing a specially crafted URL.

๐Ÿ“… Published: July 2, 2025, 5:02 a.m. ๐Ÿ”„ Last Modified: July 3, 2025, 3:13 p.m.

8.8

CVSS3.1

CVE-2025-6463 - Forminator Forms โ€“ Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated Arbโ€ฆ

The Forminator Forms โ€“ Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'entry_delete_upload_files' function in all versions up to, and including, 1.44.2. This makes it possible for unautheโ€ฆ

๐Ÿ“… Published: July 2, 2025, 4:24 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:59 p.m.

6.1

CVSS3.1

CVE-2024-11405 - WP Front-end login and register <= 2.1.0 - Reflected Cross-Site Scripting

The WP Front-end login and register plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the email and wpmp_reset_password_token parameters in all versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenโ€ฆ

๐Ÿ“… Published: July 2, 2025, 3:47 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:29 p.m.
Total resulsts: 344062
Page 4308 of 34,407
ยซ previous page ยป next page
Filters