6.5

CVSS3.1

CVE-2025-4522 - IDonate 2.0.0 - 2.1.9 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary U…

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Insecure Direct Object Reference via the admin_post_donor_delete() function in versions 2.0.0 to 2.1.9. By supplying an arbitrary user_id parameter value to the wp_delete_user() function, authent…

📅 Published: Nov. 7, 2025, 4:28 a.m. 🔄 Last Modified: Nov. 7, 2025, 10:53 a.m.

8.8

CVSS3.1

CVE-2025-4519 - IDonate 2.1.5 - 2.1.9 - Missing Authorization to Authenticated (Subscriber+) Account Takeover/Privi…

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the idonate_donor_password() function in versions 2.1.5 to 2.1.9. This makes it possible for authenticated attackers, with Subscriber-lev…

📅 Published: Nov. 7, 2025, 4:28 a.m. 🔄 Last Modified: Nov. 7, 2025, 10:53 a.m.

9.8

CVSS3.1

CVE-2025-12352 - Gravity Forms <= 2.9.20 - Unauthenticated Arbitrary File Upload via 'copy_post_image'

The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the copy_post_image() function in all versions up to, and including, 2.9.20. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's se…

📅 Published: Nov. 7, 2025, 4:28 a.m. 🔄 Last Modified: Nov. 7, 2025, 5:41 p.m.

6.9

CVSS4.0

CVE-2025-64329 - containerd CRI server: Host memory exhaustion through Attach goroutine leak

containerd is an open-source container runtime. Versions 1.7.28 and below, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4, and 2.2.0-beta.0 through 2.2.0-rc.1 contain a bug in the CRI Attach implementation where a user can exhaust memory on the host due to goroutine leaks. This issue is fix…

📅 Published: Nov. 7, 2025, 4:15 a.m. 🔄 Last Modified: Nov. 7, 2025, 5:42 p.m.

8.6

CVSS4.0

CVE-2025-64328 - FreePBX Administration GUI is Vulnerable to Authenticated Command Injection

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore module within the Administrative interface is vulnerable to a post-authentication command injection by an authenticated known user via the testconne…

📅 Published: Nov. 7, 2025, 3:32 a.m. 🔄 Last Modified: Nov. 7, 2025, 5:45 p.m.

8.1

CVSS3.1

CVE-2025-5483 - LC Wizard 1.2.10 - 1.3.0 - Missing Authorization to Unauthenticated Privilege Escalation

The LC Wizard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check in the ghl-wizard/inc/wp_user.php file in versions 1.2.10 to 1.3.0. This makes it possible for unauthenticated attackers to create new user accounts with the administrator role when the PRO fu…

📅 Published: Nov. 7, 2025, 3:27 a.m. 🔄 Last Modified: Nov. 7, 2025, 5:47 p.m.

5.3

CVSS3.1

CVE-2025-64323 - kgateway is missing xDS authorization

kgateway is a Cloud-Native API and AI Gateway. Versions 2.0.4 and below and 2.1.0-agw-cel-rbac through 2.1.0-rc.2 lack authentication, allowing any client with unrestricted network access to the xDS port to retrieve potentially sensitive configuration data including certificate data, backend servic…

📅 Published: Nov. 7, 2025, 3:18 a.m. 🔄 Last Modified: Nov. 7, 2025, 5:50 p.m.

4.6

CVSS4.0

CVE-2025-64187 - OctoPrint is vulnerable to XSS through Action Command Notifications and Prompts

OctoPrint provides a web interface for controlling consumer 3D printers. Versions 1.11.3 and below are affected by a vulnerability that allows injection of arbitrary HTML and JavaScript into Action Command notifications and prompts popups generated by the printer. An attacker who successfully convi…

📅 Published: Nov. 7, 2025, 3:11 a.m. 🔄 Last Modified: Nov. 7, 2025, 5:59 p.m.

8.8

CVSS3.1

CVE-2025-64184 - Dosage vulnerable to Directory Traversal through crafted HTTP responses

Dosage is a comic strip downloader and archiver. When downloading comic images in versions 3.1 and below, Dosage constructs target file names from different aspects of the remote comic (page URL, image URL, page content, etc.). While the basename is properly stripped of directory-traversing charact…

📅 Published: Nov. 7, 2025, 3:02 a.m. 🔄 Last Modified: Nov. 7, 2025, 6:02 p.m.

10

CVSS3.1

CVE-2025-64180 - Manager-io/Manager: Complete Bypass of SSRF Protection via Time-of-Check Time-of-Use (TOCTOU)

Manager-io/Manager is accounting software. In Manager Desktop and Server versions 25.11.1.3085 and below, a critical vulnerability permits unauthorized access to internal network resources. The flaw lies in the fundamental design of the DNS validation mechanism. A Time-of-Check Time-of-Use (TOCTOU)…

📅 Published: Nov. 7, 2025, 2:58 a.m. 🔄 Last Modified: Nov. 7, 2025, 10:53 a.m.
Total resulsts: 317991
Page 69 of 31,800
« previous page » next page
Filters