5.3

CVSS4.0

CVE-2025-64483 - Wazuh API – Agent Configuration Has Improper Access Control in Agent Enrollment Endpoint

Wazuh is a security detection, visibility, and compliance open source project. From version 4.9.0 to before 4.13.0, the Wazuh API – Agent Configuration in certain configurations allows authenticated users with read-only API roles to retrieve agent enrollment credentials through the /utils/configura…

📅 Published: Nov. 21, 2025, 5:55 p.m. 🔄 Last Modified: Nov. 21, 2025, 6:15 p.m.

7.7

CVSS4.0

CVE-2025-13470 - RNP 0.18.0 Vulnerable PKESK session keys

In RNP version 0.18.0 a refactoring regression causes the symmetric session key used for Public-Key Encrypted Session Key (PKESK) packets to be left uninitialized except for zeroing, resulting in it always being an all-zero byte array. Any data encrypted using public-key encryption in this rel…

📅 Published: Nov. 21, 2025, 5:05 p.m. 🔄 Last Modified: Nov. 21, 2025, 6:15 p.m.

5.3

CVSS3.1

CVE-2025-12747 - Tainacan <= 1.0.0 - Unauthenticated Information Exposure

The Tainacan plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.0 via uploaded files marked as private being exposed in wp-content without adequate protection. This makes it possible for unauthenticated attackers to extract potentially sensitive in…

📅 Published: Nov. 21, 2025, 4:28 p.m. 🔄 Last Modified: Nov. 21, 2025, 5:15 p.m.

7.2

CVSS3.1

CVE-2025-12973 - S2B AI Assistant – ChatBot, ChatGPT, OpenAI, Content & Image Generator <= 1.7.8 - Authenticated (Ed…

The S2B AI Assistant – ChatBot, ChatGPT, OpenAI, Content & Image Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the storeFile() function in all versions up to, and including, 1.7.8. This makes it possible for authenticated attackers, wi…

📅 Published: Nov. 21, 2025, 4:28 p.m. 🔄 Last Modified: Nov. 21, 2025, 5:15 p.m.

7.4

CVSS3.1

CVE-2025-13357 - Vault Terraform Provider Applied Incorrect Defaults for LDAP Auth Method

Vault’s Terraform Provider incorrectly set the default deny_null_bind parameter for the LDAP auth method to false by default, potentially resulting in an insecure configuration. If the underlying LDAP server allowed anonymous or unauthenticated binds, this could result in authentication bypass. Thi…

📅 Published: Nov. 21, 2025, 3:02 p.m. 🔄 Last Modified: Nov. 21, 2025, 3:15 p.m.

10

CVSS3.1

CVE-2025-41115 - Incorrect privilege assignment

SCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage users and teams in Grafana by introducing automated user lifecycle management. In Grafana versions 12.x where SCIM provisioning is enabled and configured, a vulnerability in user i…

📅 Published: Nov. 21, 2025, 2:25 p.m. 🔄 Last Modified: Nov. 22, 2025, 4:55 a.m.

4.3

CVSS3.1

CVE-2025-13432 - Terraform Enterprise state versions can be created by users with specific permissions without suffi…

Terraform state versions can be created by a user with specific but insufficient permissions in a Terraform Enterprise workspace. This may allow for the alteration of infrastructure if a subsequent plan operation is approved by a user with approval permission or auto-applied. This vulnerability, CV…

📅 Published: Nov. 21, 2025, 2:20 p.m. 🔄 Last Modified: Nov. 21, 2025, 3:15 p.m.

9.8

CVSS3.1

CVE-2025-11127 - Mstoreapp Mobile (App <= 2.08, Multivendor <= 9.0.1) - Unauthenticated Privilege Escalation

The Mstoreapp Mobile App WordPress plugin through 2.08 and Mstoreapp Mobile Multivendor through 9.0.1 do not properly verify users identify when using an AJAX action, allowing unauthenticated users to retrieve a valid session for arbitrary users by knowing their email address.

📅 Published: Nov. 21, 2025, 1:41 p.m. 🔄 Last Modified: Nov. 21, 2025, 3:15 p.m.

0.0

CVE-2025-66115 - WordPress Easy Invoice plugin <= 2.1.4 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in MatrixAddons Easy Invoice easy-invoice allows PHP Local File Inclusion.This issue affects Easy Invoice: from n/a through <= 2.1.4.

📅 Published: Nov. 21, 2025, 12:30 p.m. 🔄 Last Modified: Nov. 21, 2025, 3:13 p.m.

0.0

CVE-2025-66114 - WordPress Show Variations as Single Products Woocommerce plugin <= 2.0 - Broken Access Control vuln…

Missing Authorization vulnerability in theme funda Show Variations as Single Products Woocommerce woo-show-single-variations-shop-category allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Show Variations as Single Products Woocommerce: from n/a through <= 2…

📅 Published: Nov. 21, 2025, 12:30 p.m. 🔄 Last Modified: Nov. 21, 2025, 3:13 p.m.
Total resulsts: 319163
Page 8 of 31,917
« previous page » next page
Filters