6.4

CVSS3.1

CVE-2025-8561 - Ova Advent <= 1.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Ova Advent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 1.1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with c…

📅 Published: Oct. 15, 2025, 5:23 a.m. 🔄 Last Modified: Oct. 20, 2025, 1:27 p.m.

7.3

CVSS3.1

CVE-2025-6042 - Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme <= 1.4.0 - Unauthe…

The Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.4.0. This is due to the plugin assigning the editor role by default. While limitations with respect to capabilities…

📅 Published: Oct. 15, 2025, 5:23 a.m. 🔄 Last Modified: Oct. 21, 2025, 9:41 a.m.

4.3

CVSS3.1

CVE-2025-11176 - Quick Featured Images <= 13.7.2 - Insecure Direct Object Reference to Image Manipulation

The Quick Featured Images plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 13.7.2 via the qfi_set_thumbnail and qfi_delete_thumbnail AJAX actions due to missing validation on a user controlled key. This makes it possible for authenticated …

📅 Published: Oct. 15, 2025, 5:23 a.m. 🔄 Last Modified: Oct. 20, 2025, 1:26 p.m.

5.7

CVSS4.0

CVE-2025-55079 - Missing check for thread priority

In Eclipse ThreadX before version 6.4.3, the thread module has a setting of maximum priority. In some cases the check of that maximum priority wasn't performed, allowing, as a result, to obtain a thread with higher priority than expected and causing a possible denial of service.

📅 Published: Oct. 15, 2025, 4:29 a.m. 🔄 Last Modified: Oct. 21, 2025, 9:41 a.m.

8.8

CVSS3.1

CVE-2025-11746 - XStore | Multipurpose WooCommerce Theme <= 9.5.4 - Authenticated (Subscriber+) Local File Inclusion

The XStore theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9.5.4 via theet_ajax_required_plugins_popup() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute arbitrary .php files …

📅 Published: Oct. 15, 2025, 2:26 a.m. 🔄 Last Modified: Oct. 20, 2025, 1:27 p.m.

9.2

CVSS4.0

CVE-2023-7305 - SmartBI RMIServlet Unrestricted File Upload RCE

SmartBI V8, V9, and V10 contain an unrestricted file upload vulnerability via the RMIServlet request handling logic. Under certain configurations or usage patterns, attackers can send specially crafted requests that cause the application to perform sensitive operations or execute arbitrary code on …

📅 Published: Oct. 15, 2025, 1:24 a.m. 🔄 Last Modified: Oct. 21, 2025, 9:41 a.m.

9.3

CVSS4.0

CVE-2011-10033 - WordPress Plugin is-human <= v1.4.2 Eval Injection RCE

The WordPress plugin is-human <= v1.4.2 contains an eval injection vulnerability in /is-human/engine.php that can be triggered via the 'type' parameter when the 'action' parameter is set to 'log-reset'. The root cause is unsafe use of eval() on user-controlled input, which can lead to execution of …

📅 Published: Oct. 15, 2025, 1:23 a.m. 🔄 Last Modified: Oct. 21, 2025, 9:41 a.m.

9.3

CVSS4.0

CVE-2018-25117 - VestaCP Debian Installer Malicious Backdoor Supply Chain Compromise

VestaCP commit a3f0fa1 (2018-05-31) up to commit ee03eff (2018-06-13) contain embedded malicious code that resulted in a supply-chain compromise. New installations created from the compromised installer since at least May 2018 were subject to installation of Linux/ChachaDDoS, a multi-stage DDoS bot…

📅 Published: Oct. 15, 2025, 1:23 a.m. 🔄 Last Modified: Oct. 21, 2025, 9:41 a.m.

9.2

CVSS4.0

CVE-2017-20205 - Valve Source SDK Stack-Based Buffer Overflow RCE

Valve's Source SDK (source-sdk-2013)'s ragdoll model parsing logic contains a stack-based buffer overflow vulnerability.The tokenizer function `nexttoken` copies characters from an input string into a fixed-size stack buffer without performing bounds checks. When `ParseKeyValue` processes a collisi…

📅 Published: Oct. 15, 2025, 1:23 a.m. 🔄 Last Modified: Oct. 21, 2025, 9:41 a.m.

9.3

CVSS4.0

CVE-2023-7304 - Ruijie RG-UAC nmc_sync.php Command Injection

Ruijie RG-UAC Application Management Gateway contains a command injection vulnerability via the 'nmc_sync.php' interface. An unauthenticated attacker able to reach the affected endpoint can inject shell commands via crafted request data, causing the application to execute arbitrary commands on the …

📅 Published: Oct. 15, 2025, 1:22 a.m. 🔄 Last Modified: Oct. 21, 2025, 9:41 a.m.
Total resulsts: 314824
Page 53 of 31,483
« previous page » next page
Filters