7.5

CVSS3.1

CVE-2025-32398 -

A NULL Pointer Dereference in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devices that use the library by sending a malicious RPC packet.

📅 Published: May 7, 2025, 7:05 a.m. 🔄 Last Modified: May 13, 2025, 8:20 p.m.

7.5

CVSS3.1

CVE-2025-32397 -

An Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devices that use the library by sending a malicious RPC packet.

📅 Published: May 7, 2025, 7:05 a.m. 🔄 Last Modified: May 13, 2025, 8:20 p.m.

7.5

CVSS3.1

CVE-2025-32396 -

An Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to induce a crash in IO devices that use the library by sending a malicious RPC packet.

📅 Published: May 7, 2025, 7:05 a.m. 🔄 Last Modified: May 13, 2025, 8:20 p.m.

3.1

CVSS3.1

CVE-2025-1400 - Out-of-bounds Read in libplctag library

Out-of-bounds Read vulnerability in unpack_response (conn.c) in libplctag from 2.0 through 2.6.3 allows Overread Buffers via network.

📅 Published: May 7, 2025, 7:04 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

3.1

CVSS3.1

CVE-2025-1399 - Out-of-bounds Read in libplctag library

Out-of-bounds Read vulnerability in unpack_response (session.c) in libplctag from 2.0 through 2.6.3 allows Overread Buffers via network.

📅 Published: May 7, 2025, 7:04 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-3766 - Login Lockdown & Protection <= 2.11 - Missing Authorization to Authenticated (Subscriber+) Arbitrar…

The Login Lockdown & Protection plugin for WordPress is vulnerable to unauthorized nonce access due to a missing capability check on the ajax_run_tool function in all versions up to, and including, 2.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to …

📅 Published: May 7, 2025, 4:22 a.m. 🔄 Last Modified: April 20, 2026, 11 p.m.

6.1

CVSS3.1

CVE-2025-4054 - Relevanssi <= 4.24.3 (Free) and <= 2.27.4 (Premium) - Unauthenticated Stored Cross-Site Scripting v…

The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the highlights functionality in all versions up to, and including, 4.24.3 (Free) and <= 2.27.4 (Premium), due to insufficient input sanitization and output escaping. This makes it possible for una…

📅 Published: May 7, 2025, 2:23 a.m. 🔄 Last Modified: April 22, 2026, 1:45 a.m.

6.4

CVSS3.1

CVE-2025-4220 - Xavin's List Subpages <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Xavin&#039;s List Subpages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xls' shortcode in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticate…

📅 Published: May 7, 2025, 1:43 a.m. 🔄 Last Modified: April 20, 2026, 11 p.m.

6.4

CVSS3.1

CVE-2025-3860 - CarDealerPress <= 6.8.2505.00 - Authenticated (Contributor+) Stored Cross-Site Scripting via salecl…

The CarDealerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘saleclass' parameter in all versions up to, and including, 6.8.2505.00 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level…

📅 Published: May 7, 2025, 1:43 a.m. 🔄 Last Modified: April 21, 2026, 9 p.m.

6.4

CVSS3.1

CVE-2025-4055 - Multiple Post Type Order <= 1.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via m…

The Multiple Post Type Order plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mpto' shortcode in all versions up to, and including, 1.10.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentica…

📅 Published: May 7, 2025, 1:43 a.m. 🔄 Last Modified: April 21, 2026, 9 p.m.
Total resulsts: 347945
Page 5403 of 34,795
« previous page » next page
Filters