7.5

CVSS3.1

CVE-2025-27819 - Apache Kafka: Possible RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration

In CVE-2023-25194, we announced the RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration in Kafka Connect API. But not only Kafka Connect API is vulnerable to this attack, the Apache Kafka brokers also have this vulnerability. To exploit this vulnerability, the attacker needs toโ€ฆ

๐Ÿ“… Published: June 10, 2025, 7:54 a.m. ๐Ÿ”„ Last Modified: July 11, 2025, 4:52 p.m.

8.8

CVSS3.1

CVE-2025-27818 - Apache Kafka: Possible RCE attack via SASL JAAS LdapLoginModule configuration

A possible security vulnerability has been identified in Apache Kafka. This requires access to a alterConfig to theย cluster resource, or Kafka Connect worker, and the ability to create/modify connectors on it with an arbitrary Kafka client SASL JAAS config and a SASL-based security protocol, which โ€ฆ

๐Ÿ“… Published: June 10, 2025, 7:52 a.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 5:51 p.m.

0.0

CVE-2025-5945 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

๐Ÿ“… Published: June 10, 2025, 7:31 a.m. ๐Ÿ”„ Last Modified: June 10, 2025, 9:15 a.m.

9.9

CVSS3.1

CVE-2025-1041 - Avaya Call Management System RCE vulnerability

An improper input validation discovered in Avaya Call Management System could allow an unauthorized remote command via a specially crafted web request. Affected versions include 18.x, 19.x prior to 19.2.0.7, and 20.x prior to 20.0.1.0.

๐Ÿ“… Published: June 10, 2025, 6:05 a.m. ๐Ÿ”„ Last Modified: July 30, 2025, 5:59 p.m.

8.8

CVSS3.1

CVE-2025-4954 - Axle Demo Importer <= 1.0.3 - Author+ Arbitrary File Upload

The Axle Demo Importer WordPress plugin through 1.0.3 does not validate files to be uploaded, which could allow authenticated users (author and above) to upload arbitrary files such as PHP on the server

๐Ÿ“… Published: June 10, 2025, 6 a.m. ๐Ÿ”„ Last Modified: July 2, 2025, 4:11 p.m.

7.5

CVSS3.1

CVE-2025-4840 - Likes and Dislikes Plugin <= 1.0.0 - Unauthenticated SQL Injection

The inprosysmedia-likes-dislikes-post WordPress plugin through 1.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

๐Ÿ“… Published: June 10, 2025, 6 a.m. ๐Ÿ”„ Last Modified: July 2, 2025, 4:14 p.m.

6.9

CVSS4.0

CVE-2025-5952 - Zend.To NSSDropoff.php exec os command injection

A vulnerability, which was classified as critical, has been found in Zend.To up to 6.10-6 Beta. This issue affects the function exec of the file NSSDropoff.php. The manipulation of the argument file_1 leads to os command injection. The attack may be initiated remotely. The exploit has been discloseโ€ฆ

๐Ÿ“… Published: June 10, 2025, 5 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-5935 - Open5GS AMF/MME emm-sm.c common_register_state denial of service

A vulnerability was found in Open5GS up to 2.7.3. It has been declared as problematic. Affected by this vulnerability is the function common_register_state of the file src/mme/emm-sm.c of the component AMF/MME. The manipulation of the argument ran_ue_id leads to denial of service. The attack can beโ€ฆ

๐Ÿ“… Published: June 10, 2025, 4:33 a.m. ๐Ÿ”„ Last Modified: July 12, 2025, 4:01 p.m.

6.4

CVSS3.1

CVE-2025-3076 - Elementor Pro <= 3.29.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the โ€˜button_textโ€™ parameter in all versions up to, and including, 3.29.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contrโ€ฆ

๐Ÿ“… Published: June 10, 2025, 4:23 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:35 p.m.

8.8

CVSS3.1

CVE-2025-4601 - RH - Real Estate WordPress Theme <= 4.4.0 - Authenticated (Subscriber+) Privilege Escalation

The "RH - Real Estate WordPress Theme" theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.4.0. This is due to the theme not properly restricting user roles that can be updated as part of the inspiry_update_profile() function. This makes it possible forโ€ฆ

๐Ÿ“… Published: June 10, 2025, 3:41 a.m. ๐Ÿ”„ Last Modified: April 20, 2026, 10:45 p.m.
Total resulsts: 349182
Page 5100 of 34,919
ยซ previous page ยป next page
Filters