8.1

CVSS3.1

CVE-2025-4380 - Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager <= 4.89 - Unauthenticated Local File I…

The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.89 via the 'bsa_template' parameter of the `bsa_preview_callback` function. This makes it possible for unauthenticated attackers to inc…

📅 Published: July 2, 2025, 3:47 a.m. 🔄 Last Modified: April 8, 2026, 4:44 p.m.

6.4

CVSS3.1

CVE-2025-6687 - Magic Buttons for Elementor <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via m…

The Magic Buttons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's magic-button shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on the 'icon' user supplied attributes. This makes it possib…

📅 Published: July 2, 2025, 3:47 a.m. 🔄 Last Modified: April 8, 2026, 5:20 p.m.

8.8

CVSS3.1

CVE-2025-6459 - Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager <= 4.89 - Cross-Site Request Forgery t…

The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.89. This is due to missing or incorrect nonce validation on the bsaCreateAdTemplate function. This makes it possible for unauthen…

📅 Published: July 2, 2025, 3:47 a.m. 🔄 Last Modified: April 8, 2026, 4:41 p.m.

7.5

CVSS3.1

CVE-2025-4381 - Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager <= 4.89 - Unauthenticated SQL Injection

The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via the ‘$id’ variable of the getSpace() function in all versions up to, and including, 4.89 due to insufficient escaping on the user supplied parameter and lack of sufficient prepar…

📅 Published: July 2, 2025, 3:47 a.m. 🔄 Last Modified: April 8, 2026, 4:33 p.m.

9.8

CVSS3.1

CVE-2025-4689 - Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager <= 4.89 - Unauthenticated Local File I…

The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclusion which leads to Remote Code Execution in all versions up to, and including, 4.89. This is due to the presence of a SQL Injection vulnerability and Local File Inclusion vulnerab…

📅 Published: July 2, 2025, 3:47 a.m. 🔄 Last Modified: April 8, 2026, 4:32 p.m.

6.3

CVSS3.1

CVE-2025-5692 - Lead Form Data Collection to CRM <= 3.1 - Missing Authorization to Authenticated (Subscriber+) Many…

The Lead Form Data Collection to CRM plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in the ~/includes/LB_admin_ajax.php file in all versions up to, and including, 3.1. This makes it possible for authenticated attackers, with Subscrib…

📅 Published: July 2, 2025, 2:03 a.m. 🔄 Last Modified: April 8, 2026, 4:42 p.m.

5.5

CVSS3.1

CVE-2025-38093 - arm64: dts: qcom: x1e80100: Add GPU cooling

In the Linux kernel, the following vulnerability has been resolved: arm64: dts: qcom: x1e80100: Add GPU cooling Unlike the CPU, the GPU does not throttle its speed automatically when it reaches high temperatures. With certain high GPU loads it is possible to reach the critical hardware shutdown t…

📅 Published: July 2, 2025, midnight 🔄 Last Modified: Nov. 20, 2025, 9:53 p.m.

5.5

CVSS3.1

CVE-2025-38092 - ksmbd: use list_first_entry_or_null for opinfo_get_list()

In the Linux kernel, the following vulnerability has been resolved: ksmbd: use list_first_entry_or_null for opinfo_get_list() The list_first_entry() macro never returns NULL. If the list is empty then it returns an invalid pointer. Use list_first_entry_or_null() to check if the list is empty.

📅 Published: July 2, 2025, midnight 🔄 Last Modified: Nov. 20, 2025, 9:58 p.m.

7.8

CVSS3.1

CVE-2025-38091 - drm/amd/display: check stream id dml21 wrapper to get plane_id

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: check stream id dml21 wrapper to get plane_id [Why & How] Fix a false positive warning which occurs due to lack of correct checks when querying plane_id in DML21. This fixes the warning when performing a mode1 re…

📅 Published: July 2, 2025, midnight 🔄 Last Modified: Nov. 20, 2025, 10:07 p.m.

9.8

CVSS3.1

CVE-2025-45814 -

Missing authentication checks in the query.fcgi endpoint of NS3000 v8.1.1.125110 , v7.2.8.124852 , and v7.x and NS2000 v7.02.08 allows attackers to execute a session hijacking attack.

📅 Published: July 2, 2025, midnight 🔄 Last Modified: Oct. 10, 2025, 7:45 p.m.
Total resulsts: 345165
Page 4420 of 34,517
« previous page » next page
Filters