9.3

CVSS4.0

CVE-2025-34110 - ColoradoFTP Server <= 1.3 Build 8 Path Traversal Information Disclosure

A directory traversal vulnerability exists in ColoradoFTP Server ≀ 1.3 Build 8 for Windows, allowing unauthenticated attackers to read or write arbitrary files outside the configured FTP root directory. The flaw is due to insufficient sanitation of user-supplied file paths in the FTP GET and PUT co…

πŸ“… Published: July 15, 2025, 1:01 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2025-7667 - Restrict File Access <= 1.1.2 - Cross-Site Request Forgery to Arbitrary File Deletion

The Restrict File Access plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the 'restrict-file-access' page. This makes it possible for unauthenticated attackers to to delete arbitrary…

πŸ“… Published: July 15, 2025, 11:20 a.m. πŸ”„ Last Modified: April 20, 2026, 8:30 p.m.

0.0

CVE-2025-53954 -

Not used

πŸ“… Published: July 15, 2025, 9:52 a.m. πŸ”„ Last Modified: July 16, 2025, 3:15 a.m.

0.0

CVE-2025-53955 -

Not used

πŸ“… Published: July 15, 2025, 9:52 a.m. πŸ”„ Last Modified: July 16, 2025, 3:15 a.m.

0.0

CVE-2025-53956 -

Not used

πŸ“… Published: July 15, 2025, 9:52 a.m. πŸ”„ Last Modified: July 16, 2025, 3:15 a.m.

0.0

CVE-2025-53957 -

Not used

πŸ“… Published: July 15, 2025, 9:52 a.m. πŸ”„ Last Modified: July 16, 2025, 3:15 a.m.

0.0

CVE-2025-53958 -

Not used

πŸ“… Published: July 15, 2025, 9:52 a.m. πŸ”„ Last Modified: July 16, 2025, 3:15 a.m.

0.0

CVE-2025-53953 -

Not used

πŸ“… Published: July 15, 2025, 9:52 a.m. πŸ”„ Last Modified: July 16, 2025, 3:15 a.m.

0.0

CVE-2025-53952 -

Not used

πŸ“… Published: July 15, 2025, 9:52 a.m. πŸ”„ Last Modified: July 16, 2025, 3:15 a.m.

5.5

CVSS3.1

CVE-2025-4369 - Companion Auto Update <= 3.9.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via upd…

The Companion Auto Update plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜update_delay_days’ parameter in all versions up to, and including, 3.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administ…

πŸ“… Published: July 15, 2025, 9:22 a.m. πŸ”„ Last Modified: April 21, 2026, 4:15 a.m.
Total resulsts: 349182
Page 4644 of 34,919
Β« previous page Β» next page
Filters