0.0

CVE-2025-47439 - WordPress Download Monitor plugin <= 5.0.22 - Local File Inclusion Vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Chill Download Monitor download-monitor allows PHP Local File Inclusion.This issue affects Download Monitor: from n/a through <= 5.0.22.

πŸ“… Published: May 7, 2025, 2:19 p.m. πŸ”„ Last Modified: April 1, 2026, 5:23 p.m.

0.0

CVE-2025-35980 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2025. Notes: none.

πŸ“… Published: May 7, 2025, 1:20 p.m. πŸ”„ Last Modified: Oct. 29, 2025, 5:55 p.m.

7.5

CVSS3.1

CVE-2025-33093 - IBM Sterling Partner Engagement Manager information disclosure

IBM Sterling Partner Engagement Manager 6.1.0, 6.2.0, 6.2.2 JWT secret is stored in public Helm Charts and is not stored as a Kubernetes secret.

πŸ“… Published: May 7, 2025, 11:04 a.m. πŸ”„ Last Modified: Nov. 13, 2025, 7:31 p.m.

9.8

CVSS3.1

CVE-2025-4104 - Frontend Dashboard 1.0 - 2.2.6 - Missing Authorization to Unauthenticated Privilege Escalation via …

The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the fed_wp_ajax_fed_login_form_post() function in versions 1.0 to 2.2.6. This makes it possible for unauthenticated attackers to reset the administrator’s email and password, and e…

πŸ“… Published: May 7, 2025, 9:21 a.m. πŸ”„ Last Modified: May 7, 2025, 2:13 p.m.

5.4

CVSS3.1

CVE-2025-39361 - WordPress Royal Elementor Addons plugin <= 1.7.1017 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Stored XSS.This issue affects Royal Elementor Addons: from n/a through <= 1.7.1017.

πŸ“… Published: May 7, 2025, 9:03 a.m. πŸ”„ Last Modified: April 1, 2026, 5:22 p.m.

6.9

CVSS4.0

CVE-2025-27533 - Apache ActiveMQ: Unchecked buffer length can cause excessive memory allocation

Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ. During unmarshalling of OpenWire commands the size value of buffers was not properly validated which could lead to excessive memory allocation and be exploited to cause a denial of service (DoS) by depleting process memo…

πŸ“… Published: May 7, 2025, 8:59 a.m. πŸ”„ Last Modified: Nov. 3, 2025, 8:18 p.m.

4

CVSS3.1

CVE-2025-20980 -

Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to cause memory corruption.

πŸ“… Published: May 7, 2025, 8:34 a.m. πŸ”„ Last Modified: Oct. 2, 2025, 4:42 p.m.

8.4

CVSS3.1

CVE-2025-20979 -

Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to execute arbitrary code.

πŸ“… Published: May 7, 2025, 8:24 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

6.2

CVSS3.1

CVE-2025-20978 -

Improper access control in PENUP prior to version 3.9.19.32 allows local attackers to access files with PENUP privilege.

πŸ“… Published: May 7, 2025, 8:24 a.m. πŸ”„ Last Modified: May 7, 2025, 2:13 p.m.

3.3

CVSS3.1

CVE-2025-20977 -

Use of implicit intent for sensitive communication in translation in Samsung Notes prior to version 4.4.29.23 allows local attackers to get sensitive information. User interaction is required for triggering this vulnerability.

πŸ“… Published: May 7, 2025, 8:24 a.m. πŸ”„ Last Modified: July 16, 2025, 7:33 p.m.
Total resulsts: 343923
Page 4996 of 34,393
Β« previous page Β» next page
Filters