6.4

CVSS3.1

CVE-2025-3614 - ElementsKit Elementor Addons and Templates <= 3.5.2 - Authenticated (Contributor+) Stored Cross-Sitโ€ฆ

The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attribute of a custom widget in all versions up to, and including, 3.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated โ€ฆ

๐Ÿ“… Published: July 24, 2025, 10:23 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 10:30 p.m.

9.3

CVSS4.0

CVE-2025-32429 - XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 9.4-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2, it's possible for anyone to inject SQL using the parameter sort of the getdeleteddocuments.vm. It's injected as is as an ORDEโ€ฆ

๐Ÿ“… Published: July 24, 2025, 10:22 p.m. ๐Ÿ”„ Last Modified: Sept. 3, 2025, 5:43 p.m.

0.0

CVE-2014-125120 -

This CVE has the been REJECTED and will not be published by the CNA.

๐Ÿ“… Published: July 24, 2025, 9:11 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 2:12 p.m.

5.3

CVSS4.0

CVE-2025-8123 - deerwms deer-wms-2 edit sql injection

A vulnerability was found in deerwms deer-wms-2 up to 3.3. It has been classified as critical. Affected is an unknown function of the file /system/dept/edit. The manipulation of the argument ancestors leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosโ€ฆ

๐Ÿ“… Published: July 24, 2025, 9:02 p.m. ๐Ÿ”„ Last Modified: Aug. 28, 2025, 10:54 a.m.

7.1

CVSS3.1

CVE-2025-31952 - HCL iAutomate is affected by an insufficient session expiration

HCL iAutomate is affected by an insufficient session expiration. This allows tokens to remain valid indefinitely unless manually revoked, increasing the risk of unauthorized access.

๐Ÿ“… Published: July 24, 2025, 9:01 p.m. ๐Ÿ”„ Last Modified: Oct. 10, 2025, 4:36 p.m.

7.6

CVSS3.1

CVE-2025-31955 - HCL iAutomate is affected by a sensitive data exposure vulnerability

HCL iAutomate is affected by a sensitive data exposure vulnerability. This issue may allow unauthorized access to sensitive information within the system.

๐Ÿ“… Published: July 24, 2025, 8:59 p.m. ๐Ÿ”„ Last Modified: Oct. 10, 2025, 4:35 p.m.

9.3

CVSS4.0

CVE-2025-6260 - Network Thermostat X-Series WiFi Thermostats Missing Authentication for Critical Function

The embedded web server on the thermostat listed version ranges contain a vulnerability that allows unauthenticated attackers, either on the local area network or from the Internet via a router with port forwarding set up, to gain direct access to the thermostat's embedded web server and reset userโ€ฆ

๐Ÿ“… Published: July 24, 2025, 8:53 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS4.0

CVE-2025-7404 - Calibre Web 0.6.24 & Autocaliweb 0.7.0 - Blind C

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web, Autocaliweb allows Blind OS Command Injection.This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1.

๐Ÿ“… Published: July 24, 2025, 8:45 p.m. ๐Ÿ”„ Last Modified: Jan. 16, 2026, 2:48 p.m.

7.1

CVSS3.1

CVE-2025-31953 - HCL iAutomate is affected by hardcoded credentials

HCL iAutomate includes hardcoded credentials which may result in potential exposure of confidential data if intercepted or accessed by unauthorized parties.

๐Ÿ“… Published: July 24, 2025, 8:40 p.m. ๐Ÿ”„ Last Modified: Oct. 10, 2025, 4:35 p.m.

8.7

CVSS4.0

CVE-2025-6998 - Calibre Web 0.6.24 & Autocaliweb 0.7.0 - ReDoS

ReDoS in strip_whitespaces() function in cps/string_helper.py in Calibre Web and Autocaliweb allowsย unauthenticated remote attackers to cause denial of service via specially crafted username parameter that triggers catastrophic backtracking during login.ย This issue affects Calibre Web: 0.6.24 (Nicoโ€ฆ

๐Ÿ“… Published: July 24, 2025, 7:39 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4528 of 34,919
ยซ previous page ยป next page
Filters