7.5

CVSS3.1

CVE-2025-2485 - Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.7 - Unauthenticated PHP Object Injec…

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.8.7 via deserialization of untrusted input from the 'dnd_upload_cf7_upload' function. This makes it possible for attackers to inject a PHP…

📅 Published: March 28, 2025, 6:51 a.m. 🔄 Last Modified: April 8, 2026, 5:02 p.m.

8.8

CVSS3.1

CVE-2025-2328 - Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.7 - Unauthenticated Arbitrary File D…

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'dnd_remove_uploaded_files' function in all versions up to, and including, 1.3.8.7. This makes it possible for unauthenticated atta…

📅 Published: March 28, 2025, 6:51 a.m. 🔄 Last Modified: April 8, 2026, 4:35 p.m.

4.3

CVSS3.1

CVE-2025-1762 - Event Tickets with Ticket Scanner < 2.5.4 - Arbitrary Tickets Deletion via CSRF

The Event Tickets with Ticket Scanner WordPress plugin before 2.5.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

📅 Published: March 28, 2025, 6 a.m. 🔄 Last Modified: April 17, 2025, 1:48 p.m.

5.9

CVSS4.0

CVE-2025-2027 -

A double free vulnerability has been identified in the ASUS System Analysis service. This vulnerability can be triggered by sending specially crafted local RPC requests, leading to the service crash and potentially memory manipulation in some rare circumstances. Refer to the 'Security Update for My…

📅 Published: March 28, 2025, 5:34 a.m. 🔄 Last Modified: March 28, 2025, 6:11 p.m.

6.1

CVSS3.1

CVE-2025-2804 - tagDiv Composer <= 5.3 - Reflected Cross-Site Scripting via 'account_id' and 'account_username'

The tagDiv Composer plugin for WordPress, used by the Newspaper theme, is vulnerable to Reflected Cross-Site Scripting via the 'account_id' and 'account_username' parameters in all versions up to, and including, 5.3 due to insufficient input sanitization and output escaping. This makes it possible …

📅 Published: March 28, 2025, 5:23 a.m. 🔄 Last Modified: April 8, 2026, 4:48 p.m.

9.8

CVSS3.1

CVE-2025-2294 - Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion

The Kubio AI Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.5.1 via thekubio_hybrid_theme_load_template function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the …

📅 Published: March 28, 2025, 4:22 a.m. 🔄 Last Modified: April 8, 2026, 4:44 p.m.

6.6

CVSS3.1

CVE-2025-2894 - Unitree Go1 Robot Dog Backdoor Control Channel

The Go1 also known as "The World's First Intelligence Bionic Quadruped Robot Companion of Consumer Level," contains an undocumented backdoor that can enable the manufacturer, and anyone in possession of the correct API key, complete remote control over the affected robotic device using the CloudSai…

📅 Published: March 28, 2025, 2:51 a.m. 🔄 Last Modified: Jan. 12, 2026, 4:10 p.m.

8.8

CVSS3.1

CVE-2025-24381 -

Dell Unity, version(s) 5.4 and prior, contain(s) an URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to a targeted application user being redirected to arbitrary web URLs. The vuln…

📅 Published: March 28, 2025, 2:23 a.m. 🔄 Last Modified: Feb. 26, 2026, 7:08 p.m.

7.8

CVSS3.1

CVE-2025-24386 -

Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privi…

📅 Published: March 28, 2025, 2:19 a.m. 🔄 Last Modified: Feb. 26, 2026, 7:08 p.m.

7.8

CVSS3.1

CVE-2025-24377 -

Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of privileg…

📅 Published: March 28, 2025, 2:16 a.m. 🔄 Last Modified: Feb. 26, 2026, 7:09 p.m.
Total resulsts: 344055
Page 5642 of 34,406
« previous page » next page
Filters