6.1

CVSS3.1

CVE-2025-7669 - Avishi WP PayPal Payment Button <= 2.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The Avishi WP PayPal Payment Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0. This is due to missing or incorrect nonce validation on the 'avishi-wp-paypal-payment-button/index.php' page. This makes it possible for unauthenticated at…

📅 Published: July 19, 2025, 2:22 a.m. 🔄 Last Modified: April 21, 2026, 4 a.m.

6.4

CVSS3.1

CVE-2025-7653 - EPay.bg Payments <= 0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The EPay.bg Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'epay' shortcode in all versions up to, and including, 0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacke…

📅 Published: July 19, 2025, 2:22 a.m. 🔄 Last Modified: April 21, 2026, 4 a.m.

6.4

CVSS3.1

CVE-2025-7658 - Temporarily Hidden Content <= 1.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Temporarily Hidden Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'temphc-start' shortcode in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for a…

📅 Published: July 19, 2025, 2:22 a.m. 🔄 Last Modified: April 21, 2026, 4 a.m.

6.4

CVSS3.1

CVE-2025-7661 - Partnerský systém Martinus <= 1.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Partnerský systém Martinus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'martinus' shortcode in all versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authe…

📅 Published: July 19, 2025, 2:22 a.m. 🔄 Last Modified: April 22, 2026, 1:15 a.m.

6.4

CVSS3.1

CVE-2025-7655 - Live Stream Badger <= 1.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Live Stream Badger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'livestream' shortcode in all versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticat…

📅 Published: July 19, 2025, 2:22 a.m. 🔄 Last Modified: April 22, 2026, 5:15 p.m.

5.5

CVSS3.1

CVE-2025-38351 - KVM: x86/hyper-v: Skip non-canonical addresses during PV TLB flush

In the Linux kernel, the following vulnerability has been resolved: KVM: x86/hyper-v: Skip non-canonical addresses during PV TLB flush In KVM guests with Hyper-V hypercalls enabled, the hypercalls HVCALL_FLUSH_VIRTUAL_ADDRESS_LIST and HVCALL_FLUSH_VIRTUAL_ADDRESS_LIST_EX allow a guest to request …

📅 Published: July 19, 2025, midnight 🔄 Last Modified: Nov. 18, 2025, 12:51 p.m.

7.8

CVSS3.1

CVE-2025-38350 - net/sched: Always pass notifications when child class becomes empty

In the Linux kernel, the following vulnerability has been resolved: net/sched: Always pass notifications when child class becomes empty Certain classful qdiscs may invoke their classes' dequeue handler on an enqueue operation. This may unexpectedly empty the child qdisc and thus make an in-flight…

📅 Published: July 19, 2025, midnight 🔄 Last Modified: Dec. 16, 2025, 5:34 p.m.

4

CVSS3.1

CVE-2025-52924 -

In One Identity OneLogin before 2025.2.0, the SQL connection "application name" is set based on the value of an untrusted X-RequestId HTTP request header.

📅 Published: July 19, 2025, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-54313 - eslint-config-prettier: Eslint-config-prettier Supply Chain Compromise

eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.

📅 Published: July 19, 2025, midnight 🔄 Last Modified: Feb. 26, 2026, 5:50 p.m.

7.5

CVSS3.0

CVE-2025-27210 -

An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CON, PRN, and AUX. This vulnerability affects Windows users of `path.join` API.

📅 Published: July 18, 2025, 10:54 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346565
Page 4330 of 34,657
« previous page » next page
Filters