7.1

CVSS3.1

CVE-2025-31028 - WordPress WP Hide Categories plugin <= 1.0 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Huseyin Berberoglu WP Hide Categories wp-hide-categories allows Reflected XSS.This issue affects WP Hide Categories: from n/a through <= 1.0.

๐Ÿ“… Published: April 11, 2025, 8:42 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:27 p.m.

7.1

CVSS3.1

CVE-2025-31021 - WordPress Mobile Smart plugin <= v1.3.16 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dolby_uk Mobile Smart mobile-smart allows Reflected XSS.This issue affects Mobile Smart: from n/a through <= v1.3.16.

๐Ÿ“… Published: April 11, 2025, 8:42 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:27 p.m.

7.5

CVSS3.1

CVE-2025-31015 - WordPress SMTP Service, Email Delivery Solved! โ€” MailHawk plugin <= 1.3.1 - Local File Inclusion Vuโ€ฆ

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Adrian Tobey WordPress SMTP Service, Email Delivery Solved! โ€” MailHawk mailhawk allows PHP Local File Inclusion.This issue affects WordPress SMTP Service, Email Delivery Solved! โ€ฆ

๐Ÿ“… Published: April 11, 2025, 8:42 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:27 p.m.

7.5

CVSS3.1

CVE-2025-31014 - WordPress Material Dashboard plugin <= 1.4.5 - Local File Inclusion Vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Hossein Material Dashboard material-dashboard allows PHP Local File Inclusion.This issue affects Material Dashboard: from n/a through <= 1.4.5.

๐Ÿ“… Published: April 11, 2025, 8:42 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:27 p.m.

7.2

CVSS3.1

CVE-2025-3434 - SMTP for Amazon SES โ€“ YaySMTP <= 1.8 - Unauthenticated Stored Cross-Site Scripting via Email Logs

The SMTP for Amazon SES โ€“ YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Email Logs in all versions up to, and including, 1.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripโ€ฆ

๐Ÿ“… Published: April 11, 2025, 8:21 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 9:30 p.m.

8

CVSS3.0

CVE-2025-32107 -

OS command injection vulnerability exists in Deco BE65 Pro firmware versions prior to "Deco BE65 Pro(JP)_V1_1.1.2 Build 20250123". If this vulnerability is exploited, an arbitrary OS command may be executed by the user who can log in to the device.

๐Ÿ“… Published: April 11, 2025, 8:17 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-3512 - Buffer overflow in QTextMarkdownImporter

There is a Heap-based Buffer Overflow vulnerability in QTextMarkdownImporter. This requires an incorrectly formatted markdown file to be passed to QTextMarkdownImporter to trigger the overflow.This issue affects Qt from 6.8.0 to 6.8.4. Versions up to 6.6.0 are known to be unaffected, and the fix isโ€ฆ

๐Ÿ“… Published: April 11, 2025, 7:39 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS4.0

CVE-2025-1386 - Query smuggling in ch-go library

When using the ch-go library, under a specific condition when the query includes a large, uncompressed malicious external data, it is possible for an attacker in control of such data to smuggle another query packet into the connection stream.

๐Ÿ“… Published: April 11, 2025, 4:27 a.m. ๐Ÿ”„ Last Modified: Dec. 19, 2025, 6:47 p.m.

8.1

CVSS3.1

CVE-2025-2636 - InstaWP Connect <= 0.1.0.85 - Unauthenticated Local PHP File Inclusion

The InstaWP Connect โ€“ 1-click WP Staging & Migration plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.1.0.85 via the 'instawp-database-manager' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files onโ€ฆ

๐Ÿ“… Published: April 11, 2025, 4:21 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 9:30 p.m.

5.3

CVSS4.0

CVE-2025-0128 - PAN-OS: Firewall Denial of Service (DoS) Using a Specially Crafted Packet

A denial-of-service (DoS) vulnerability in the Simple Certificate Enrollment Protocol (SCEP) authentication feature of Palo Alto Networks PAN-OSยฎ software enables an unauthenticated attacker to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causesโ€ฆ

๐Ÿ“… Published: April 11, 2025, 2:03 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 5912 of 34,919
ยซ previous page ยป next page
Filters