4.3

CVSS3.1

CVE-2025-2168 - Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Pro…

The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.1. This is due to missing or incorrect nonce…

📅 Published: May 1, 2025, 3:23 a.m. 🔄 Last Modified: April 22, 2026, 4:15 a.m.

8.8

CVSS3.1

CVE-2025-1304 - NewsBlogger <= 0.2.5.1 - Authenticated (Subscriber+) Arbitrary File Upload

The NewsBlogger theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the newsblogger_install_and_activate_plugin() function in all versions up to, and including, 0.2.5.1. This makes it possible for authenticated attackers, with subscriber-level access and…

📅 Published: May 1, 2025, 3:23 a.m. 🔄 Last Modified: April 21, 2026, 9:15 p.m.

8.8

CVSS3.1

CVE-2025-1305 - NewsBlogger <= 0.2.5.4 - Cross-Site Request Forgery to Arbitrary Plugin Installation

The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2.5.4. This is due to missing or incorrect nonce validation on the newsblogger_install_and_activate_plugin() function. This makes it possible for unauthenticated attackers to uplo…

📅 Published: May 1, 2025, 3:23 a.m. 🔄 Last Modified: April 21, 2026, 9:15 p.m.

8.7

CVSS4.0

CVE-2025-4148 - Netgear EX6200 sub_503FC buffer overflow

A vulnerability was found in Netgear EX6200 1.0.3.94 and classified as critical. Affected by this issue is the function sub_503FC. The manipulation of the argument host leads to buffer overflow. The attack may be launched remotely. The vendor was contacted early about this disclosure but did not re…

📅 Published: May 1, 2025, 3 a.m. 🔄 Last Modified: May 12, 2025, 7:38 p.m.

8.1

CVSS3.1

CVE-2025-2816 - Page View Count 2.8.0 - 2.8.4 - Missing Authorization to Authenticated (Subscriber+) Limited Option…

The Page View Count plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the yellow_message_dontshow() function in versions 2.8.0 to 2.8.4. This makes it possible for authenticated attackers, with Subscribe…

📅 Published: May 1, 2025, 2:23 a.m. 🔄 Last Modified: May 12, 2025, 7:38 p.m.

8.7

CVSS4.0

CVE-2025-4147 - Netgear EX6200 sub_47F7C buffer overflow

A vulnerability has been found in Netgear EX6200 1.0.3.94 and classified as critical. Affected by this vulnerability is the function sub_47F7C. The manipulation of the argument host leads to buffer overflow. The attack can be launched remotely. The vendor was contacted early about this disclosure b…

📅 Published: May 1, 2025, 2 a.m. 🔄 Last Modified: May 12, 2025, 7:38 p.m.

8.7

CVSS4.0

CVE-2025-4146 - Netgear EX6200 sub_41940 buffer overflow

A vulnerability, which was classified as critical, was found in Netgear EX6200 1.0.3.94. Affected is the function sub_41940. The manipulation of the argument host leads to buffer overflow. It is possible to launch the attack remotely. The vendor was contacted early about this disclosure but did not…

📅 Published: May 1, 2025, 1 a.m. 🔄 Last Modified: May 12, 2025, 7:38 p.m.

5.3

CVSS4.0

CVE-2025-4144 - PKCE bypass via downgrade attack

PKCE was implemented in the OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp . However, it was found that an attacker could cause the check to be skipped. Fixed in: https://github.com/cloudflare/workers-oauth-provider/pul…

📅 Published: May 1, 2025, 12:50 a.m. 🔄 Last Modified: May 12, 2025, 7:39 p.m.

6

CVSS4.0

CVE-2025-4143 - Missing validation of redirect_uri on authorize endpoint

The OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp , did not correctly validate that redirect_uri was on the allowed list of redirect URIs for the given client registration. Fixed in:  https://github.com/cloudflare/workers-oa…

📅 Published: May 1, 2025, 12:19 a.m. 🔄 Last Modified: May 12, 2025, 7:39 p.m.

8.7

CVSS4.0

CVE-2025-4145 - Netgear EX6200 sub_3D0BC buffer overflow

A vulnerability, which was classified as critical, has been found in Netgear EX6200 1.0.3.94. This issue affects the function sub_3D0BC. The manipulation of the argument host leads to buffer overflow. The attack may be initiated remotely. The vendor was contacted early about this disclosure but did…

📅 Published: May 1, 2025, midnight 🔄 Last Modified: May 12, 2025, 7:39 p.m.
Total resulsts: 348147
Page 5486 of 34,815
« previous page » next page
Filters