0.0
CVE-2025-47439 - WordPress Download Monitor plugin <= 5.0.22 - Local File Inclusion Vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Chill Download Monitor download-monitor allows PHP Local File Inclusion.This issue affects Download Monitor: from n/a through <= 5.0.22.
0.0
CVE-2025-35980 -
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2025. Notes: none.
7.5
CVE-2025-33093 - IBM Sterling Partner Engagement Manager information disclosure
IBM Sterling Partner Engagement Manager 6.1.0, 6.2.0, 6.2.2 JWT secret is stored in public Helm Charts and is not stored as a Kubernetes secret.
9.8
CVE-2025-4104 - Frontend Dashboard 1.0 - 2.2.6 - Missing Authorization to Unauthenticated Privilege Escalation via β¦
The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the fed_wp_ajax_fed_login_form_post() function in versions 1.0 to 2.2.6. This makes it possible for unauthenticated attackers to reset the administratorβs email and password, and eβ¦
5.4
CVE-2025-39361 - WordPress Royal Elementor Addons plugin <= 1.7.1017 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Stored XSS.This issue affects Royal Elementor Addons: from n/a through <= 1.7.1017.
6.9
CVE-2025-27533 - Apache ActiveMQ: Unchecked buffer length can cause excessive memory allocation
Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ. During unmarshalling of OpenWire commands the size value of buffers was not properly validated which could lead to excessive memory allocation and be exploited to cause a denial of service (DoS) by depleting process memoβ¦
4
CVE-2025-20980 -
Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to cause memory corruption.
8.4
CVE-2025-20979 -
Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to execute arbitrary code.
6.2
CVE-2025-20978 -
Improper access control in PENUP prior to version 3.9.19.32 allows local attackers to access files with PENUP privilege.
3.3
CVE-2025-20977 -
Use of implicit intent for sensitive communication in translation in Samsung Notes prior to version 4.4.29.23 allows local attackers to get sensitive information. User interaction is required for triggering this vulnerability.