6.4

CVSS3.1

CVE-2025-2537 - Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site S…

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled ThickBox JavaScript library (version 3.1) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attack…

πŸ“… Published: July 3, 2025, 12:23 p.m. πŸ”„ Last Modified: April 22, 2026, 1:15 a.m.

4.9

CVSS3.1

CVE-2025-49595 - n8n Vulnerable to Denial of Service via Malformed Binary Data Requests

n8n is a workflow automation platform. Prior to version 1.99.0, there is a denial of Service vulnerability in /rest/binary-data endpoint when processing empty filesystem URIs (filesystem:// or filesystem-v2://). This allows authenticated attackers to cause service unavailability through malformed f…

πŸ“… Published: July 3, 2025, 12:16 p.m. πŸ”„ Last Modified: Sept. 4, 2025, 4:49 p.m.

5.4

CVSS3.1

CVE-2025-3702 - WordPress Melapress File Monitor plugin < 2.2.0 - Broken Access Control vulnerability

Missing Authorization vulnerability in Melapress Melapress File Monitor website-file-changes-monitor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Melapress File Monitor: from n/a through < 2.2.0.

πŸ“… Published: July 3, 2025, 12:14 p.m. πŸ”„ Last Modified: April 23, 2026, 3:29 p.m.

6.5

CVSS3.1

CVE-2025-49032 - WordPress Gutenberg Blocks plugin <= 3.3.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress Gutenberg Blocks advanced-gutenberg allows Stored XSS.This issue affects Gutenberg Blocks: from n/a through <= 3.3.1.

πŸ“… Published: July 3, 2025, 12:09 p.m. πŸ”„ Last Modified: April 23, 2026, 3:31 p.m.

5.1

CVSS4.0

CVE-2025-40723 - Stored Cross-Site Scripting (XSS) vulnerability on Flatboard

Stored Cross-Site Scripting (XSS) vulnerability in versions prior to Flatboard 3.2.2 of Flatboard Pro, consisting of a stored XSS due to lack of proper validation of user input, through theΒ footer_text and announcement parameters in config.php.

πŸ“… Published: July 3, 2025, 11:44 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-40722 - Stored Cross-Site Scripting (XSS) vulnerability on Flatboard

Stored Cross-Site Scripting (XSS) vulnerability in versions prior to Flatboard 3.2.2 of Flatboard Pro, consisting of a stored XSS due to lack of proper validation of user input, through theΒ replace parameter in /config.php/tags.

πŸ“… Published: July 3, 2025, 11:44 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.6

CVSS3.1

CVE-2025-27461 - CVE-2025-27461

During startup, the device automatically logs in the EPC2 Windows user without requesting a password.

πŸ“… Published: July 3, 2025, 11:34 a.m. πŸ”„ Last Modified: Feb. 6, 2026, 2:39 p.m.

7.6

CVSS3.1

CVE-2025-27460 - CVE-2025-27460

The hard drives of the device are not encrypted using a full volume encryption feature such as BitLocker. This allows an attacker with physical access to the device to use an alternative operating system to interact with the hard drives, completely circumventing the Windows login. The attacker can …

πŸ“… Published: July 3, 2025, 11:34 a.m. πŸ”„ Last Modified: Feb. 6, 2026, 2:39 p.m.

4.4

CVSS3.1

CVE-2025-27459 - CVE-2025-27459

The VNC application stores its passwords encrypted within the registry but uses DES for encryption. As DES is broken, the original passwords can be recovered.

πŸ“… Published: July 3, 2025, 11:33 a.m. πŸ”„ Last Modified: Jan. 29, 2026, 7:28 p.m.

6.5

CVSS3.1

CVE-2025-27458 - CVE-2025-27458

The VNC authentication mechanism bases on a challenge-response system where both server and client use the same password for encryption. The challenge is sent from the server to the client, is encrypted by the client and sent back. The server does the same encryption locally and if the responses ma…

πŸ“… Published: July 3, 2025, 11:33 a.m. πŸ”„ Last Modified: Feb. 6, 2026, 2:39 p.m.
Total resulsts: 349182
Page 4802 of 34,919
Β« previous page Β» next page
Filters