7.5

CVSS3.1

CVE-2025-3083 - Malformed MongoDB wire protocol messages may cause mongos to crash

Specifically crafted MongoDB wire protocol messages can cause mongos to crash during command validation. This can occur without using an authenticated connection. This issue affects MongoDB v5.0 versions prior to 5.0.31, ย MongoDB v6.0 versions prior toย 6.0.20 and MongoDB v7.0 versions prior to 7.0.โ€ฆ

๐Ÿ“… Published: April 1, 2025, 11:12 a.m. ๐Ÿ”„ Last Modified: Sept. 22, 2025, 2:15 p.m.

9.8

CVSS3.1

CVE-2025-2237 - WP RealEstate <= 1.6.26 - Unauthenticated Privilege Escalation via 'process_register'

The WP RealEstate plugin for WordPress, used by the Homeo theme, is vulnerable to privilege escalation in all versions up to, and including, 1.6.26. This is due to insufficient role restrictions in the 'process_register' function. This makes it possible for unauthenticated attackers to register an โ€ฆ

๐Ÿ“… Published: April 1, 2025, 11:12 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 7:23 p.m.

9.8

CVSS3.1

CVE-2024-13553 - SMS Alert Order Notifications โ€“ WooCommerce <= 3.7.9 - Unauthenticated Account Takeover/Privilege Eโ€ฆ

The SMS Alert Order Notifications โ€“ WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.7.9. This is due to the plugin using the Host header to determine if the plugin is in a playground environment. This makes it possiโ€ฆ

๐Ÿ“… Published: April 1, 2025, 11:12 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:51 p.m.

6.4

CVSS3.1

CVE-2025-2906 - Contempo Real Estate Core <= 3.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Sโ€ฆ

The Contempo Real Estate Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 3.6.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contโ€ฆ

๐Ÿ“… Published: April 1, 2025, 11:12 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:46 p.m.

3.1

CVSS3.1

CVE-2025-3082 - User may override a view's collation and gain unauthorized access to underlying data

A user authorized to access a view may be able to alter the intended collation, allowing them to access to a different or unintended view of underlying data. This issue affects MongoDB Server v5.0 version prior to 5.0.31, MongoDB Server v6.0 version prior to 6.0.20, MongoDB Server v7.0 version prioโ€ฆ

๐Ÿ“… Published: April 1, 2025, 11:08 a.m. ๐Ÿ”„ Last Modified: Sept. 22, 2025, 2:20 p.m.

9.8

CVSS3.1

CVE-2024-56325 - Apache Pinot: Authentication bypass issue. If the path does not contain / and contain . authenticatโ€ฆ

Authentication Bypass Issue If the path does not contain / and contain., authentication is not required. Expected Normal Request and Response Example curl -X POST -H "Content-Type: application/json" -d {\"username\":\"hack2\",\"password\":\"hack\",\"component\":\"CONTROLLER\",\"role\":\"ADMIN\",โ€ฆ

๐Ÿ“… Published: April 1, 2025, 9:07 a.m. ๐Ÿ”„ Last Modified: Oct. 27, 2025, 5:11 p.m.

8.8

CVSS3.1

CVE-2025-27130 -

Welcart e-Commerce 2.11.6 and earlier versions contains an untrusted data deserialization vulnerability. If this vulnerability is exploited, arbitrary code may be executed by a remote unauthenticated attacker who can access websites created using the product.

๐Ÿ“… Published: April 1, 2025, 8:57 a.m. ๐Ÿ”„ Last Modified: July 8, 2025, 5:09 p.m.

6.5

CVSS3.1

CVE-2025-29868 - Apache Answer: Using externally referenced images can leak user privacy.

Private Data Structure Returned From A Public Method vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.2. If a user uses an externally referenced image, when a user accesses this image, the provider of the image may obtain private information about the ip address of thโ€ฆ

๐Ÿ“… Published: April 1, 2025, 7:56 a.m. ๐Ÿ”„ Last Modified: April 15, 2025, 1:07 p.m.

10

CVSS4.0

CVE-2025-30065 - Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schemโ€ฆ

Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are recommended to upgrade to version 1.15.1, which fixes the issue.

๐Ÿ“… Published: April 1, 2025, 7:53 a.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 6:29 p.m.

8.8

CVSS3.1

CVE-2025-2891 - WP Pro Real Estate 7 <= 3.5.4 - Authenticated (Custom) Arbitrary File Upload

The Real Estate 7 WordPress theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'template-submit-listing.php' file in all versions up to, and including, 3.5.4. This makes it possible for authenticated attackers, with Seller-level access and above,โ€ฆ

๐Ÿ“… Published: April 1, 2025, 7:29 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:55 p.m.
Total resulsts: 343975
Page 5560 of 34,398
ยซ previous page ยป next page
Filters