6.5

CVSS3.1

CVE-2025-3775 - ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (forme…

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.2 via the woolentor_template_proxy function. This makes it possible for u…

📅 Published: April 25, 2025, 4:23 a.m. 🔄 Last Modified: April 8, 2026, 4:51 p.m.

8.2

CVSS3.1

CVE-2025-43865 - React Router allows pre-render data spoofing on React-Router framework mode

React Router is a router for React. In versions on the 7.0 branch prior to version 7.5.2, it's possible to modify pre-rendered data by adding a header to the request. This allows to completely spoof its contents and modify all the values ​​of the data object passed to the HTML. This issue has been …

📅 Published: April 25, 2025, 12:18 a.m. 🔄 Last Modified: April 29, 2025, 1:52 p.m.

7.5

CVSS3.1

CVE-2025-43864 - React Router allows a DoS via cache poisoning by forcing SPA mode

React Router is a router for React. Starting in version 7.2.0 and prior to version 7.5.2, it is possible to force an application to switch to SPA mode by adding a header to the request. If the application uses SSR and is forced to switch to SPA, this causes an error that completely corrupts the pag…

📅 Published: April 25, 2025, 12:18 a.m. 🔄 Last Modified: April 29, 2025, 1:52 p.m.

7.5

CVSS3.1

CVE-2025-32982 -

NETSCOUT nGeniusONE before 6.4.0 b2350 has a Broken Authorization Schema for the report module.

📅 Published: April 25, 2025, midnight 🔄 Last Modified: May 27, 2025, 4:57 p.m.

6.4

CVSS3.1

CVE-2025-46544 -

In Sherpa Orchestrator 141851, a low-privileged user can elevate their privileges by creating new users and roles.

📅 Published: April 25, 2025, midnight 🔄 Last Modified: Oct. 15, 2025, 6:34 p.m.

6.5

CVSS3.1

CVE-2025-32979 -

NETSCOUT nGeniusONE before 6.4.0 b2350 allows Arbitrary File Creation by authenticated users.

📅 Published: April 25, 2025, midnight 🔄 Last Modified: May 27, 2025, 4:58 p.m.

6.8

CVSS3.1

CVE-2025-46599 -

CNCF K3s 1.32 before 1.32.4-rc1+k3s1 has a Kubernetes kubelet configuration change with the unintended consequence that, in some situations, ReadOnlyPort is set to 10255. For example, the default behavior of a K3s online installation might allow unauthenticated access to this port, exposing credent…

📅 Published: April 25, 2025, midnight 🔄 Last Modified: June 23, 2025, 7:31 p.m.

7

CVSS3.1

CVE-2025-28128 -

An issue in Mytel Telecom Online Account System v1.0 allows attackers to bypass the OTP verification process via a crafted request.

📅 Published: April 25, 2025, midnight 🔄 Last Modified: May 12, 2025, 7:29 p.m.

6.5

CVSS3.1

CVE-2025-28354 -

An issue in the Printer Manager Systm of Entrust Corp Printer Manager D3.18.4-3 and below allows attackers to execute a directory traversal via a crafted POST request.

📅 Published: April 25, 2025, midnight 🔄 Last Modified: April 29, 2025, 1:52 p.m.

9.8

CVSS3.1

CVE-2025-25775 -

Codeastro Bus Ticket Booking System v1.0 is vulnerable to SQL injection via the kodetiket parameter in /BusTicket-CI/tiket/cekorder.

📅 Published: April 25, 2025, midnight 🔄 Last Modified: May 28, 2025, 7:08 p.m.
Total resulsts: 344089
Page 5156 of 34,409
« previous page » next page
Filters