6.1

CVSS3.1

CVE-2025-2166 - CM FAQ – Simplify support with an intuitive FAQ management tool <= 1.2.5 - Reflected Cross-Site Sc…

The CM FAQ – Simplify support with an intuitive FAQ management tool plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.2.5. This makes it possible for unauthenticate…

πŸ“… Published: March 14, 2025, 4:22 a.m. πŸ”„ Last Modified: April 21, 2026, 10 p.m.

9.8

CVSS3.1

CVE-2024-11284 - WP JobHunt <= 7.1 - Unauthenticated Privilege Escalation via Password Reset/Account Takeover

The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.9. This is due to the plugin not properly validating a user's identity prior to updating their password through the account_settings_save_callback() function. This …

πŸ“… Published: March 14, 2025, 4:22 a.m. πŸ”„ Last Modified: April 8, 2026, 5:05 p.m.

4.3

CVSS3.1

CVE-2025-1528 - Search and filter pro <= 2.5.19 - Missing Authorization to Authenticated (Subscriber+) Post Meta Ex…

The Search & Filter Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_meta_values' function in all versions up to, and including, 2.5.19. This makes it possible for authenticated attackers, with Subscriber-level access and above, to …

πŸ“… Published: March 14, 2025, 4:22 a.m. πŸ”„ Last Modified: April 21, 2026, 10 p.m.

5.3

CVSS3.1

CVE-2025-1285 - Resido - Real Estate WordPress Theme <= 3.6 - Missing Authorization to Unauthenticated Server-Side …

The Resido - Real Estate WordPress Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the delete_api_key and save_api_key AJAX actions in all versions up to, and including, 3.6. This makes it possible for unauthenticated attackers to issue requests t…

πŸ“… Published: March 14, 2025, 4:22 a.m. πŸ”„ Last Modified: April 21, 2026, 10 p.m.

9.8

CVSS3.1

CVE-2024-11285 - WP JobHunt <= 7.1 - Unauthenticated Privilege Escalation via Email Update/Account Takeover

The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 7.1. This is due to the plugin not properly validating a user's identity prior to updating their details like email via the account_settings_callback() function. This…

πŸ“… Published: March 14, 2025, 4:22 a.m. πŸ”„ Last Modified: April 8, 2026, 4:35 p.m.

9.8

CVSS3.1

CVE-2025-29386 -

In Tenda AC9 v1.0 V15.03.05.14_multi, the mac parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.

πŸ“… Published: March 14, 2025, midnight πŸ”„ Last Modified: March 19, 2025, 7:15 p.m.

9.8

CVSS3.1

CVE-2025-29385 -

In Tenda AC9 v1.0 V15.03.05.14_multi, the cloneType parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.

πŸ“… Published: March 14, 2025, midnight πŸ”„ Last Modified: March 19, 2025, 7:15 p.m.

9.8

CVSS3.1

CVE-2025-29031 -

Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the fromAddressNat function.

πŸ“… Published: March 14, 2025, midnight πŸ”„ Last Modified: March 19, 2025, 7:15 p.m.

7.1

CVSS3.1

CVE-2025-29387 -

In Tenda AC9 v1.0 V15.03.05.14_multi, the wanSpeed parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.

πŸ“… Published: March 14, 2025, midnight πŸ”„ Last Modified: March 17, 2025, 7:51 p.m.

9.8

CVSS3.1

CVE-2025-29384 -

In Tenda AC9 v1.0 V15.03.05.14_multi, the wanMTU parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.

πŸ“… Published: March 14, 2025, midnight πŸ”„ Last Modified: March 19, 2025, 7:15 p.m.
Total resulsts: 349182
Page 6344 of 34,919
Β« previous page Β» next page
Filters