6.5

CVSS3.1

CVE-2025-14817 - Factory Mode App Exists Privilege Escalation Issue Allowing Third-Party Apps to Open ADB

The component com.transsion.tranfacmode.entrance.main.MainActivity in com.transsion.tranfacmode has no permission control and can be accessed by third-party apps which can construct intents to directly open adb debugging functionality without user interaction.

📅 Published: Dec. 17, 2025, 6:20 a.m. 🔄 Last Modified: Dec. 17, 2025, 7:16 p.m.

6.1

CVSS3.1

CVE-2025-14154 - Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss <= 2.10.2…

The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Stored Cross-Site Scripting via guest display name in all versions up to, and including, 2.10.2 due to insufficient input sanitization and output escaping. This makes …

📅 Published: Dec. 17, 2025, 5:24 a.m. 🔄 Last Modified: Dec. 18, 2025, 3:08 p.m.

6.4

CVSS3.1

CVE-2025-14385 - WP Recipe Maker <= 10.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in all versions up to, and including, 10.2.3 due to insufficient input sanitization and output escaping on user-supplied attributes in the wprm-recipe-roundup-item shortcode. This makes it…

📅 Published: Dec. 17, 2025, 4:31 a.m. 🔄 Last Modified: Dec. 18, 2025, 3:08 p.m.

6.5

CVSS3.1

CVE-2025-13880 - WP Social Ninja - Embed Social Feeds, Customer Reviews, Chat Widgets (Google Reviews, YouTube Feed,…

The WP Social Ninja – Embed Social Feeds, Customer Reviews, Chat Widgets (Google Reviews, YouTube Feed, Photo Feeds, and More) plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the getAdvanceSettings and saveAdvanceSettings funct…

📅 Published: Dec. 17, 2025, 4:31 a.m. 🔄 Last Modified: Dec. 18, 2025, 3:08 p.m.

6.1

CVSS3.1

CVE-2025-13861 - HTML Forms – Simple WordPress Forms Plugin <= 1.6.0 - Unauthenticated Stored Cross-Site Scripting

The HTML Forms – Simple WordPress Forms Plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.0 due to insufficient sanitization of fabricated file upload field metadata before displaying it in the WordPress admin dashboard. This m…

📅 Published: Dec. 17, 2025, 4:31 a.m. 🔄 Last Modified: Dec. 18, 2025, 3:08 p.m.

9.3

CVSS4.0

CVE-2025-59374 -

"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. Only devices that m…

📅 Published: Dec. 17, 2025, 4:27 a.m. 🔄 Last Modified: Dec. 17, 2025, 8:50 p.m.

4.8

CVSS4.0

CVE-2025-11775 -

An out-of-bounds read vulnerability has been identified in the asComSvc service. This vulnerability can be triggered by sending specially crafted requests, which may lead to a service crash or partial loss of functionality. This vulnerability only affects ASUS motherboard series products. Refer to …

📅 Published: Dec. 17, 2025, 4:25 a.m. 🔄 Last Modified: Dec. 17, 2025, 9:45 p.m.

7

CVSS4.0

CVE-2025-11901 -

An uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel B460, B560, B660, B760, H410, H510, H610, H470, Z590, Z690, Z790, W480, W680 series chipsets. Exploitation requires physical access to internal expansion slots to install a specially crafted device and…

📅 Published: Dec. 17, 2025, 4:23 a.m. 🔄 Last Modified: Dec. 17, 2025, 9:46 p.m.

5.1

CVSS4.0

CVE-2025-64700 -

Cross-site request forgery vulnerability exists in GROWI v7.3.3 and earlier. If a user views a malicious page while logged in, the user may be tricked to do unintended operations.

📅 Published: Dec. 17, 2025, 4:06 a.m. 🔄 Last Modified: Dec. 17, 2025, 9:33 p.m.

8.5

CVSS4.0

CVE-2025-14305 - Acer|ListCheck.exe - Local Privilege Escalation

ListCheck.exe developed by Acer has a Local Privilege Escalation vulnerability. Authenticated local attackers can replace ListCheck.exe with a malicious executable of the same name, which will be executed by the system and result in privilege escalation.

📅 Published: Dec. 17, 2025, 3:30 a.m. 🔄 Last Modified: Dec. 17, 2025, 9:31 p.m.
Total resulsts: 323554
Page 72 of 32,356
« previous page » next page
Filters