8.2

CVSS3.1

CVE-2025-23388 - Unauthenticated stack overflow in /v3-public/authproviders API

A Stack-based Buffer Overflow vulnerability in SUSE rancher allows for denial of service.This issue affects rancher: from 2.8.0 before 2.8.13, from 2.9.0 before 2.9.7, from 2.10.0 before 2.10.3.

๐Ÿ“… Published: April 11, 2025, 10:48 a.m. ๐Ÿ”„ Last Modified: July 12, 2025, 3:26 p.m.

8.4

CVSS3.1

CVE-2025-23389 - Rancher does not Properly Validate Account Bindings in SAML Authentication Enables User Impersonatiโ€ฆ

A Improper Access Control vulnerability in SUSE rancher allows a local user to impersonate other identities through SAML Authentication on first login. This issue affects rancher: from 2.8.0 before 2.8.13, from 2.9.0 before 2.9.7, from 2.10.0 before 2.10.3.

๐Ÿ“… Published: April 11, 2025, 10:46 a.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

9.1

CVSS3.1

CVE-2025-23391 - Rancher: Restricted Administrator can change Administrator's passwords

A Incorrect Privilege Assignment vulnerability in SUSE rancher allows a Restricted Administrator to change the password of Administrators and take over their accounts. This issue affects rancher: from 2.8.0 before 2.8.14, from 2.9.0 before 2.9.8, from 2.10.0 before 2.10.4.

๐Ÿ“… Published: April 11, 2025, 10:38 a.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

8.8

CVSS3.0

CVE-2025-31932 -

Deserialization of untrusted data issue exists in BizRobo! all versions. If this vulnerability is exploited, an arbitrary code is executed on the Management Console. The vendor provides the workaround information and recommends to apply it to the deployment environment.

๐Ÿ“… Published: April 11, 2025, 9:38 a.m. ๐Ÿ”„ Last Modified: April 11, 2025, 3:39 p.m.

3.7

CVSS3.0

CVE-2025-31362 -

Use of hard-coded cryptographic key issue exists in BizRobo! all versions. Credentials inside robot files may be obtained if the encryption key is available. The vendor provides the workaround information and recommends to apply it to the deployment environment.

๐Ÿ“… Published: April 11, 2025, 9:38 a.m. ๐Ÿ”„ Last Modified: April 11, 2025, 3:39 p.m.

6.5

CVSS3.1

CVE-2025-2128 - Cost Calculator Builder <= 3.2.67 - Authenticated (Subscriber+) SQL Injection via order_ids Parametโ€ฆ

The Cost Calculator Builder plugin for WordPress is vulnerable to time-based SQL Injection via the โ€˜order_idsโ€™ parameter in all versions up to, and including, 3.2.67 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makesโ€ฆ

๐Ÿ“… Published: April 11, 2025, 9:21 a.m. ๐Ÿ”„ Last Modified: April 11, 2025, 3:39 p.m.

0.0

CVE-2025-32681 - WordPress Error Log Viewer By WP Guru plugin <= 1.0.5 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Guru Error Log Viewer error-log-viewer-wp allows Blind SQL Injection.This issue affects Error Log Viewer: from n/a through <= 1.0.5.

๐Ÿ“… Published: April 11, 2025, 8:43 a.m. ๐Ÿ”„ Last Modified: April 1, 2026, 5:22 p.m.

0.0

CVE-2025-32672 - WordPress Ultimate Bootstrap Elements for Elementor plugin <= 1.4.9 - Local File Inclusion Vulnerabโ€ฆ

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in g5theme Ultimate Bootstrap Elements for Elementor ultimate-bootstrap-elements-for-elementor allows PHP Local File Inclusion.This issue affects Ultimate Bootstrap Elements for Eleโ€ฆ

๐Ÿ“… Published: April 11, 2025, 8:43 a.m. ๐Ÿ”„ Last Modified: April 1, 2026, 5:22 p.m.

0.0

CVE-2025-32671 - WordPress Print Science Designer plugin <= 1.3.155 - Arbitrary File Download vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in John Weissberg Print Science Designer print-science-designer allows Path Traversal.This issue affects Print Science Designer: from n/a through <= 1.3.155.

๐Ÿ“… Published: April 11, 2025, 8:43 a.m. ๐Ÿ”„ Last Modified: April 1, 2026, 5:22 p.m.

0.0

CVE-2025-32663 - WordPress FAT Cooming Soon plugin <= 1.1 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in roninwp FAT Cooming Soon fat-coming-soon allows PHP Local File Inclusion.This issue affects FAT Cooming Soon: from n/a through <= 1.1.

๐Ÿ“… Published: April 11, 2025, 8:43 a.m. ๐Ÿ”„ Last Modified: April 1, 2026, 5:22 p.m.
Total resulsts: 342272
Page 5215 of 34,228
ยซ previous page ยป next page
Filters