8.6

CVSS3.1

CVE-2025-49415 - WordPress FW Gallery plugin <= 8.0.0 - Arbitrary File Deletion Vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Fastw3b LLC FW Gallery fw-gallery allows Path Traversal.This issue affects FW Gallery: from n/a through <= 8.0.0.

πŸ“… Published: June 17, 2025, 3:01 p.m. πŸ”„ Last Modified: April 23, 2026, 3:31 p.m.

10

CVSS3.1

CVE-2025-49444 - WordPress Reformer for Elementor plugin <= 1.0.5 - Arbitrary File Upload Vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in merkulove Reformer for Elementor reformer-elementor allows Upload a Web Shell to a Web Server.This issue affects Reformer for Elementor: from n/a through <= 1.0.5.

πŸ“… Published: June 17, 2025, 3:01 p.m. πŸ”„ Last Modified: April 23, 2026, 3:31 p.m.

10

CVSS3.1

CVE-2025-49447 - WordPress FW Food Menu <= 6.0.0 - Arbitrary File Upload Vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in Fastw3b LLC FW Food Menu allows Using Malicious Files. This issue affects FW Food Menu : from n/a through 6.0.0.

πŸ“… Published: June 17, 2025, 3:01 p.m. πŸ”„ Last Modified: April 28, 2026, 4:13 p.m.

2.3

CVSS4.0

CVE-2025-4754 - Missing Session Revocation on Logout in ash_authentication_phoenix

Insufficient Session Expiration vulnerability in ash-project ash_authentication_phoenix allows Session Hijacking. This vulnerability is associated with program files lib/ash_authentication_phoenix/controller.ex. This issue affects ash_authentication_phoenix until 2.10.0.

πŸ“… Published: June 17, 2025, 2:31 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-34508 - ZendTo < 6.15-8 Path Traversal

A path traversal vulnerability exists in the file dropoff functionality of ZendTo versions 6.15-7 and prior. This could allow a remote, authenticated attacker to retrieve the files of other ZendTo users, retrieve files on the host system, or cause a denial of service.

πŸ“… Published: June 17, 2025, 2:14 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

1

CVSS4.0

CVE-2025-49842 - conda-forge-webservices Privilege Escalation Risk via Default Docker Root User

conda-forge-webservices is the web app deployed to run conda-forge admin commands and linting. Prior to version 2025.3.24, the conda_forge_webservice Docker container executes commands without specifying a user. By default, Docker containers run as the root user, which increases the risk of privile…

πŸ“… Published: June 17, 2025, 2:02 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-6069 - HTMLParser quadratic complexity when processing malformed inputs

The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service.

πŸ“… Published: June 17, 2025, 1:39 p.m. πŸ”„ Last Modified: April 21, 2026, 8:17 p.m.

8.6

CVSS4.0

CVE-2025-0320 - Citrix Secure Access - Local Privilege escalation allows a low-privileged user to gain SYSTEM privi…

Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Secure Access Client for Windows

πŸ“… Published: June 17, 2025, 1:25 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

7.3

CVSS4.0

CVE-2025-4879 - Citrix Workspace App for Windows - Local Privilege escalation allows a low-privileged user to gain …

Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges inΒ Citrix Workspace app for Windows

πŸ“… Published: June 17, 2025, 1:02 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

6.9

CVSS4.0

CVE-2025-4365 - NetScaler Console and NetScaler SDX (SVM) - Arbitrary file read

Arbitrary file read inΒ NetScaler Console and NetScaler SDX (SVM)

πŸ“… Published: June 17, 2025, 12:38 p.m. πŸ”„ Last Modified: Aug. 6, 2025, 5:50 p.m.
Total resulsts: 347969
Page 4889 of 34,797
Β« previous page Β» next page
Filters