9.8

CVSS3.1

CVE-2025-4564 - TicketBAI Facturas para WooCommerce <= 3.18 - Unauthenticated Arbitrary File Deletion

The TicketBAI Facturas para WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation via the 'delpdf' action in all versions up to, and including, 3.18. This makes it possible for unauthenticated attackers to delete arbitrary files on the se…

πŸ“… Published: May 15, 2025, 11:13 a.m. πŸ”„ Last Modified: April 22, 2026, 3 p.m.

4.3

CVSS3.1

CVE-2025-3446 - Members Without Guest Invite Permissions Can Add Guests to Teams

Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to check the correct permissions which allows authenticated users who only have permission to invite non-guest users to a team to add guest users to that team via the API to add a single user to a team.

πŸ“… Published: May 15, 2025, 10:43 a.m. πŸ”„ Last Modified: Sept. 29, 2025, 9:05 p.m.

5.8

CVSS3.1

CVE-2025-31947 - Repeated LDAP login failures can lock an LDAP account

Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to lockout LDAP users following repeated login failures, which allows attackers to lock external LDAP accounts through repeated login failures through Mattermost.

πŸ“… Published: May 15, 2025, 10:41 a.m. πŸ”„ Last Modified: Oct. 6, 2025, 3:30 p.m.

6.9

CVSS4.0

CVE-2025-32738 -

Missing authentication for critical function issue exists in I-O DATA network attached hard disk 'HDL-T Series' firmware Ver.1.21 and earlier. If exploited, a remote unauthenticated attacker may change the product settings.

πŸ“… Published: May 15, 2025, 8:48 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-32002 -

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in I-O DATA network attached hard disk 'HDL-T Series' firmware Ver.1.21 and earlier when 'Remote Link3 function' is enabled. If exploited, a remote unauthenticated attacker may execute an arbitra…

πŸ“… Published: May 15, 2025, 8:48 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.2

CVSS3.1

CVE-2025-4737 -

Insufficient encryption vulnerability in the mobile application (com.transsion.aivoiceassistant) may lead to the risk of sensitive information leakage.

πŸ“… Published: May 15, 2025, 7:58 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.9

CVSS3.1

CVE-2025-27525 - Information Exposure vulnerability in JP1/IT Desktop Management 2 - Smart Device Manager

Information Exposure vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affects JP1/IT Desktop Management 2 - Smart Device Manager: from 12-00 before 12-00-08, from 11-10 through 11-10-08, from 11-00 through 11-00-05, from 10-50 through 10-50-06.

πŸ“… Published: May 15, 2025, 6:45 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-27524 - Weak encryption vulnerability in JP1/IT Desktop Management 2 - Smart Device Manager

Weak encryption vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affects JP1/IT Desktop Management 2 - Smart Device Manager: from 12-00 before 12-00-08, from 11-10 through 11-10-08, from 11-00 through 11-00-05, from 10-50 through 10-50-06.

πŸ“… Published: May 15, 2025, 6:27 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS3.1

CVE-2025-27523 - XXE vulnerability in JP1/IT Desktop Management 2 - Smart Device Manager

XXE vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affects JP1/IT Desktop Management 2 - Smart Device Manager: from 12-00 before 12-00-08, from 11-10 through 11-10-08, from 11-00 through 11-00-05, from 10-50 through 10-50-06.

πŸ“… Published: May 15, 2025, 6:22 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS3.1

CVE-2025-3742 - Responsive Lightbox & Gallery < 2.5.1 - Contributor+ Stored XSS

The Responsive Lightbox & Gallery WordPress plugin before 2.5.1 does not validate and escape some of its attributes before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

πŸ“… Published: May 15, 2025, 6 a.m. πŸ”„ Last Modified: June 4, 2025, 4:25 p.m.
Total resulsts: 349182
Page 5405 of 34,919
Β« previous page Β» next page
Filters