0.0

CVE-2025-4436 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: May 8, 2025, 3:30 p.m. πŸ”„ Last Modified: May 20, 2025, 11:15 p.m.

0.0

CVE-2025-4132 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: May 8, 2025, 3:10 p.m. πŸ”„ Last Modified: May 12, 2025, 9:15 a.m.

5.9

CVSS3.1

CVE-2025-4207 - PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails…

Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte over-read can elicit process termination. This affects the database server and also libpq. Versions before PostgreSQL 17.5, 16.9, 15.13, 1…

πŸ“… Published: May 8, 2025, 2:22 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2024-6648 - Path Traversal in AP Page Builder

Absolute Path Traversal vulnerability in AP Page Builder versions prior to 4.0.0 could allow an unauthenticated remote user to modify the 'product_item_path' within the 'config' JSON file, allowing them to read any file on the system.

πŸ“… Published: May 8, 2025, 12:16 p.m. πŸ”„ Last Modified: May 13, 2025, 6:28 p.m.

6.3

CVSS4.0

CVE-2025-3506 - Potentially senitive path exposed via unauthenticated http route

Files to be deployed with agents are accessible without authentication in Checkmk 2.1.0, Checkmk 2.2.0, Checkmk 2.3.0 and <Checkmk 2.4.0b6 allows attacker to access files that could contain secrets.

πŸ“… Published: May 8, 2025, 11:24 a.m. πŸ”„ Last Modified: Aug. 25, 2025, 2:51 p.m.

6.1

CVSS3.1

CVE-2025-2806 - tagDiv Composer <= 5.3 - Reflected Cross-Site Scripting via 'data'

The tagDiv Composer plugin for WordPress, used by the Newspaper theme, is vulnerable to Reflected Cross-Site Scripting via the β€˜data’ parameter in all versions up to, and including, 5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers …

πŸ“… Published: May 8, 2025, 11:23 a.m. πŸ”„ Last Modified: April 21, 2026, 9 p.m.

6.4

CVSS3.1

CVE-2025-3468 - NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.9.1 - Authenticated (Custom) S…

The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the clean_html and form_fields parameters in all versions up to, and including, 8.9.1 due to insufficient input sanitization and output escaping. This makes it p…

πŸ“… Published: May 8, 2025, 11:13 a.m. πŸ”„ Last Modified: April 21, 2026, 9 p.m.

6.4

CVSS3.1

CVE-2025-3862 - Contest Gallery <= 26.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Paramet…

Contest Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜id’ parameter in all versions up to, and including, 26.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and abo…

πŸ“… Published: May 8, 2025, 11:13 a.m. πŸ”„ Last Modified: April 21, 2026, 9 p.m.

6.3

CVSS3.1

CVE-2025-4208 - NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.9.1 - Authenticated (Custom) L…

The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Limited Code Execution in all versions up to, and including, 8.9.1 via the get_table_records function. This is due to the unsanitized use of user-supplied input in call_user_func(). This makes …

πŸ“… Published: May 8, 2025, 11:13 a.m. πŸ”„ Last Modified: April 22, 2026, 5:30 p.m.

8.7

CVSS4.0

CVE-2025-3759 - Missing Authentication for Changing Device Configuration in WF2220

EndpointΒ /cgi-bin-igd/netcore_set.cgiΒ which is used for changing device configuration is accessible without authentication. This poses a significant security threat allowing for e.g: administrator account hijacking or AP password changing. The vendor was contacted early about this disclosure but di…

πŸ“… Published: May 8, 2025, 10:05 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 348124
Page 5385 of 34,813
Β« previous page Β» next page
Filters