3.1

CVSS3.1

CVE-2025-3082 - User may override a view's collation and gain unauthorized access to underlying data

A user authorized to access a view may be able to alter the intended collation, allowing them to access to a different or unintended view of underlying data. This issue affects MongoDB Server v5.0 version prior to 5.0.31, MongoDB Server v6.0 version prior to 6.0.20, MongoDB Server v7.0 version prio…

📅 Published: April 1, 2025, 11:08 a.m. 🔄 Last Modified: Sept. 22, 2025, 2:20 p.m.

9.8

CVSS3.1

CVE-2024-56325 - Apache Pinot: Authentication bypass issue. If the path does not contain / and contain . authenticat…

Authentication Bypass Issue If the path does not contain / and contain., authentication is not required. Expected Normal Request and Response Example curl -X POST -H "Content-Type: application/json" -d {\"username\":\"hack2\",\"password\":\"hack\",\"component\":\"CONTROLLER\",\"role\":\"ADMIN\",…

📅 Published: April 1, 2025, 9:07 a.m. 🔄 Last Modified: Oct. 27, 2025, 5:11 p.m.

8.8

CVSS3.1

CVE-2025-27130 -

Welcart e-Commerce 2.11.6 and earlier versions contains an untrusted data deserialization vulnerability. If this vulnerability is exploited, arbitrary code may be executed by a remote unauthenticated attacker who can access websites created using the product.

📅 Published: April 1, 2025, 8:57 a.m. 🔄 Last Modified: July 8, 2025, 5:09 p.m.

6.5

CVSS3.1

CVE-2025-29868 - Apache Answer: Using externally referenced images can leak user privacy.

Private Data Structure Returned From A Public Method vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.2. If a user uses an externally referenced image, when a user accesses this image, the provider of the image may obtain private information about the ip address of th…

📅 Published: April 1, 2025, 7:56 a.m. 🔄 Last Modified: April 15, 2025, 1:07 p.m.

10

CVSS4.0

CVE-2025-30065 - Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schem…

Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are recommended to upgrade to version 1.15.1, which fixes the issue.

📅 Published: April 1, 2025, 7:53 a.m. 🔄 Last Modified: Feb. 26, 2026, 6:29 p.m.

8.8

CVSS3.1

CVE-2025-2891 - WP Pro Real Estate 7 <= 3.5.4 - Authenticated (Custom) Arbitrary File Upload

The Real Estate 7 WordPress theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'template-submit-listing.php' file in all versions up to, and including, 3.5.4. This makes it possible for authenticated attackers, with Seller-level access and above,…

📅 Published: April 1, 2025, 7:29 a.m. 🔄 Last Modified: April 22, 2026, 2 a.m.

2.3

CVSS4.0

CVE-2025-27427 - Apache ActiveMQ Artemis: Address routing-type can be updated by user without the createAddress perm…

A vulnerability exists in Apache ActiveMQ Artemis whereby a user with the createDurableQueue or createNonDurableQueue permission on an address can augment the routing-type supported by that address even if said user doesn't have the createAddress permission for that particular address. When combine…

📅 Published: April 1, 2025, 7:26 a.m. 🔄 Last Modified: July 14, 2025, 12:08 p.m.

6.4

CVSS3.1

CVE-2025-1512 - PowerPack Elementor Addons (Free Widgets, Extensions and Templates) <= 2.9.0 - Authenticated (Contr…

The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Cursor Extension in all versions up to, and including, 2.9.0 due to insufficient input sanitization and output escaping. This makes it possible fo…

📅 Published: April 1, 2025, 6:52 a.m. 🔄 Last Modified: April 21, 2026, 9:45 p.m.

5.5

CVSS3.1

CVE-2025-1267 - Groundhogg <= 3.7.4.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via label Parame…

The Groundhogg plugin for Wordpress is vulnerable to Stored Cross-Site Scripting via the ‘label' parameter in versions up to, and including, 3.7.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access, to in…

📅 Published: April 1, 2025, 6:52 a.m. 🔄 Last Modified: April 21, 2026, 9:45 p.m.

6.4

CVSS3.1

CVE-2024-12189 - WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder <=…

The WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom widgets in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. This make…

📅 Published: April 1, 2025, 6:52 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 6081 of 34,919
« previous page » next page
Filters