9.8

CVSS3.1

CVE-2025-6440 - WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload

The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress theme, is vulnerable to arbitrary file uploads due to missing file type validation in the 'wcdp_save_canvas_design_ajax' function in all versions up to, and including, 1.9.26. This mโ€ฆ

๐Ÿ“… Published: Oct. 24, 2025, 7:23 a.m. ๐Ÿ”„ Last Modified: Oct. 27, 2025, 10:13 p.m.

5.3

CVSS4.0

CVE-2025-9158 - Stored XSS in Request Tracker

The Request Tracker software is vulnerable to a Stored XSS vulnerability in calendar invitation parsing feature, which displays invitation data without HTML sanitization.ย XSS vulnerability allows an attacker to send a specifically crafted e-mail enabling JavaScript code execution by displaying the โ€ฆ

๐Ÿ“… Published: Oct. 24, 2025, 6 a.m. ๐Ÿ”„ Last Modified: Oct. 27, 2025, 10:13 p.m.

6.8

CVSS3.1

CVE-2025-9978 - Jeg Elementor Kit < 2.7.0 - Author+ Stored XSS

The Jeg Kit for Elementor WordPress plugin before 2.7.0 does not sanitize SVG file contents when uploaded via xmlrpc.php, leading to a cross site scripting vulnerability.

๐Ÿ“… Published: Oct. 24, 2025, 6 a.m. ๐Ÿ”„ Last Modified: Oct. 27, 2025, 10:13 p.m.

5.5

CVSS3.1

CVE-2025-10874 - Orbit Fox < 3.0.2 - Author+ Server-Side Request Forgery

The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.2 does not limit URLs which may be used for the stock photo import feature, allowing the user to specify arbitrary URLs. This leads to a server-side request forgery as the user mayโ€ฆ

๐Ÿ“… Published: Oct. 24, 2025, 6 a.m. ๐Ÿ”„ Last Modified: Oct. 27, 2025, 10:13 p.m.

2.7

CVSS3.1

CVE-2025-10723 - PixelYourSite < 11.1.2 - Admin+ LFI

The PixelYourSite WordPress plugin before 11.1.2 does not validate some URL parameters before using them to generate paths passed to function/s, allowing any admins to perform LFI attacks

๐Ÿ“… Published: Oct. 24, 2025, 6 a.m. ๐Ÿ”„ Last Modified: Oct. 27, 2025, 10:13 p.m.

4.8

CVSS4.0

CVE-2025-61931 -

Pleasanter contains a stored cross-site scripting vulnerability in Body, Description and Comments, which allows an attacker to execute an arbitrary script in a logged-in user's web browser.

๐Ÿ“… Published: Oct. 24, 2025, 5:17 a.m. ๐Ÿ”„ Last Modified: Oct. 27, 2025, 10:13 p.m.

5.1

CVSS4.0

CVE-2025-58070 -

Pleasanter contains a stored cross-site scripting vulnerability in Preview for Attachments, which allows an attacker to execute an arbitrary script in a logged-in user's web browser.

๐Ÿ“… Published: Oct. 24, 2025, 5:17 a.m. ๐Ÿ”„ Last Modified: Oct. 27, 2025, 10:13 p.m.

7.5

CVSS3.1

CVE-2025-60551 -

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the next_page parameter in the function formDeviceReboot.

๐Ÿ“… Published: Oct. 24, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 28, 2025, 2:31 a.m.

7.5

CVSS3.1

CVE-2025-60555 -

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetWizardSelectMode.

๐Ÿ“… Published: Oct. 24, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 28, 2025, 2:31 a.m.

7.5

CVSS3.1

CVE-2025-60569 -

D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetRoute.

๐Ÿ“… Published: Oct. 24, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 28, 2025, 2:37 a.m.
Total resulsts: 316322
Page 82 of 31,633
ยซ previous page ยป next page
Filters