9.8

CVSS3.1

CVE-2025-2266 - Checkout Mestres do WP for WooCommerce 8.6.5 - 8.7.5 - Unauthenticated Arbitrary Options Update

The Checkout Mestres do WP for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the cwmpUpdateOptions() function in versions 8.6.5 to 8.7.5. This makes it possible for unauthenticated attac…

πŸ“… Published: March 29, 2025, 7:03 a.m. πŸ”„ Last Modified: April 1, 2025, 8:26 p.m.

7.3

CVSS3.1

CVE-2025-2803 - So-Called Air Quotes <= 0.1 - Unauthenticated Arbitrary Shortcode Execution

The So-Called Air Quotes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 0.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for una…

πŸ“… Published: March 29, 2025, 7:03 a.m. πŸ”„ Last Modified: April 8, 2026, 5:04 p.m.

5.3

CVSS3.1

CVE-2025-2840 - DAP to Autoresponders Email Syncing <= 1.0 - Unauthenticated Information Exposure

The DAP to Autoresponders Email Syncing plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0 through the publicly accessible phpinfo.php script. This makes it possible for unauthenticated attackers to view potentially sensitive information c…

πŸ“… Published: March 29, 2025, 7:03 a.m. πŸ”„ Last Modified: April 8, 2026, 4:48 p.m.

6.3

CVSS4.0

CVE-2025-1217 - Header parser of http stream wrapper does not handle folded headers

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when http request module parses HTTP response obtained from a server, folded headers are parsed incorrectly, which may lead to misinterpreting the response and using incorrect headers, MIME…

πŸ“… Published: March 29, 2025, 5:19 a.m. πŸ”„ Last Modified: Nov. 3, 2025, 9:18 p.m.

4.3

CVSS3.1

CVE-2024-51477 - IBM InfoSphere Information Server information disclosure

IBM InfoSphere Information Server 11.7 could allow an authenticated to obtain sensitive username information due to an observable response discrepancy.

πŸ“… Published: March 28, 2025, 11:51 p.m. πŸ”„ Last Modified: Sept. 1, 2025, 1 a.m.

4.4

CVSS3.1

CVE-2024-7577 - IBM InfoSphere Information Server information disclosure

IBM InfoSphere Information Server 11.7 could disclose sensitive user credentials from log files during new installation of the product.

πŸ“… Published: March 28, 2025, 11:50 p.m. πŸ”„ Last Modified: Sept. 1, 2025, 12:59 a.m.

5.3

CVSS3.1

CVE-2024-43186 - IBM InfoSphere Information Server information disclosure

IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that is stored locally under certain conditions.

πŸ“… Published: March 28, 2025, 11:49 p.m. πŸ”„ Last Modified: Sept. 1, 2025, 1 a.m.

6.3

CVSS4.0

CVE-2025-2782 - WatchGuard Terminal Services Agent Local Privilege Escalation via Non-Standard Installation Directo…

The WatchGuard Terminal Services Agent on Windows does not properly configure directory permissions when installed in a non-default directory. This could allow an authenticated local attacker to escalate to SYSTEM privileges on a vulnerable system. This issue affects Terminal Services Agent: fro…

πŸ“… Published: March 28, 2025, 10:24 p.m. πŸ”„ Last Modified: April 1, 2025, 8:26 p.m.

6.3

CVSS4.0

CVE-2025-2781 - WatchGuard Mobile VPN with SSL Local Privilege Escalation via Non-Standard Installation Directory

The WatchGuard Mobile VPN with SSL Client on Windows does not properly configure directory permissions when installed in a non-default directory. This could allow an authenticated local attacker to escalate to SYSTEM privileges on a vulnerable system. This issue affects Mobile VPN with SSL Clien…

πŸ“… Published: March 28, 2025, 10:23 p.m. πŸ”„ Last Modified: April 1, 2025, 8:26 p.m.

6.9

CVSS4.0

CVE-2025-2927 - ESAFENET CDG getFileTypeList.jsp sql injection

A vulnerability was found in ESAFENET CDG 5.6.3.154.205. It has been classified as critical. Affected is an unknown function of the file /parameter/getFileTypeList.jsp. The manipulation of the argument typename leads to sql injection. It is possible to launch the attack remotely. The exploit has be…

πŸ“… Published: March 28, 2025, 8:31 p.m. πŸ”„ Last Modified: April 14, 2025, 5:09 p.m.
Total resulsts: 343850
Page 5608 of 34,385
Β« previous page Β» next page
Filters