6.2

CVSS3.1

CVE-2025-33013 - IBM MQ Operator information disclosure

IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, 3.6.0, and MQ Operator SC2 3.2.0 through 3.2.13 Container could disclose sensitive information to a local user due to improper clearing of heap memory before release.

📅 Published: July 24, 2025, 2:55 p.m. 🔄 Last Modified: July 25, 2025, 3:29 p.m.

5.9

CVSS3.1

CVE-2025-36005 - IBM MQ Operator information disclosure

IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, 3.6.0, and MQ Operator SC2 3.2.0 through 3.2.13 Internet Pass-Thru could allow a malicious user to obtain sensitive information from another TLS session connection by the p…

📅 Published: July 24, 2025, 2:52 p.m. 🔄 Last Modified: July 25, 2025, 3:29 p.m.

9.8

CVSS3.1

CVE-2025-4784 - SQLi in Moderec's Tourtella

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Moderec Tourtella allows SQL Injection.This issue affects Tourtella: before 26.05.2025.

📅 Published: July 24, 2025, 1:27 p.m. 🔄 Last Modified: July 28, 2025, 2:43 p.m.

9.8

CVSS3.1

CVE-2025-4822 - SQLi in Bayraktar Solar Energies' ScadaWatt Otopilot

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bayraktar Solar Energies ScadaWatt Otopilot allows SQL Injection.This issue affects ScadaWatt Otopilot: before 27.05.2025.

📅 Published: July 24, 2025, 12:56 p.m. 🔄 Last Modified: July 25, 2025, 3:29 p.m.

10

CVSS3.1

CVE-2025-5243 - Arbitrary File Upload in SMG Software's Information Portal

Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SMG Software Information Portal allows Code Injection, Upload a Web Shell to a Web Server, Code Inclusion.This issue affects Information Porta…

📅 Published: July 24, 2025, 12:45 p.m. 🔄 Last Modified: July 25, 2025, 3:29 p.m.

6.9

CVSS4.0

CVE-2025-40680 - Encryption of sensitive data in CapillaryScope missing

Lack of sensitive data encryption in CapillaryScope v2.5.0 of Capillary io, which stores both the proxy credentials and the JWT session token in plain text within different registry keys on the Windows operating system. Any authenticated local user with read access to the registry can extract these…

📅 Published: July 24, 2025, 12:14 p.m. 🔄 Last Modified: July 25, 2025, 3:29 p.m.

6.4

CVSS3.1

CVE-2025-7959 - Station Pro <= 2.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via width and heigh…

The Station Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width' and 'height’ parameter in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level…

📅 Published: July 24, 2025, 9:22 a.m. 🔄 Last Modified: July 25, 2025, 3:29 p.m.

6.1

CVSS3.1

CVE-2025-7690 - Affiliate Plus <= 1.3.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The Affiliate Plus plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.2. This is due to missing or incorrect nonce validation on the 'affiplus_settings' page. This makes it possible for unauthenticated attackers to perform an unauthorized acti…

📅 Published: July 24, 2025, 9:22 a.m. 🔄 Last Modified: July 25, 2025, 3:29 p.m.

4.3

CVSS3.1

CVE-2025-7835 - iThoughts Advanced Code Editor <= 1.2.10 - Cross-Site Request Forgery to Settings Update

The iThoughts Advanced Code Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.10. This is due to missing or incorrect nonce validation on the 'ithoughts_ace_update_options' AJAX action. This makes it possible for unauthenticated attack…

📅 Published: July 24, 2025, 9:22 a.m. 🔄 Last Modified: July 25, 2025, 3:29 p.m.

6.1

CVSS3.1

CVE-2025-6588 - FunnelCockpit <= 1.4.2 - Reflected Cross-Site Scripting via `error` Parameter

The FunnelCockpit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘error’ parameter in all versions up to, and including, 1.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scrip…

📅 Published: July 24, 2025, 9:22 a.m. 🔄 Last Modified: July 25, 2025, 3:29 p.m.
Total resulsts: 303715
Page 70 of 30,372
« previous page » next page
Filters