9.3

CVSS4.0

CVE-2025-14307 - Insecure Temporary File Creation in Robocode's AutoExtract Component

An insecure temporary file creation vulnerability exists in the AutoExtract component of Robocode version 1.9.3.6. The createTempFile method fails to securely create temporary files, allowing attackers to exploit race conditions and potentially execute arbitrary code or overwrite critical files. Th…

πŸ“… Published: Dec. 9, 2025, 7:29 a.m. πŸ”„ Last Modified: Dec. 9, 2025, 7:29 a.m.

10

CVSS4.0

CVE-2025-14306 - Directory Traversal in Robocode's CacheCleaner Component

A directory traversal vulnerability exists in the CacheCleaner component of Robocode version 1.9.3.6. The recursivelyDelete method fails to properly sanitize file paths, allowing attackers to traverse directories and delete arbitrary files on the system. This vulnerability can be exploited by submi…

πŸ“… Published: Dec. 9, 2025, 7:19 a.m. πŸ”„ Last Modified: Dec. 9, 2025, 7:19 a.m.

8.6

CVSS4.0

CVE-2025-13428 - RCE in SecOps SOAR server via user-provided Python packages

A vulnerability exists in the SecOps SOAR server. The custom integrations feature allowed an authenticated user with an "IDE role" to achieve Remote Code Execution (RCE) in the server. The flaw stemmed from weak validation of uploaded Python package code. An attacker could upload a package containi…

πŸ“… Published: Dec. 9, 2025, 6:28 a.m. πŸ”„ Last Modified: Dec. 9, 2025, 6:28 a.m.

0.0

CVE-2025-13071 - Custom Admin Menu <= 1.0.0 - Reflected XSS

The Custom Admin Menu WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

πŸ“… Published: Dec. 9, 2025, 6 a.m. πŸ”„ Last Modified: Dec. 9, 2025, 6 a.m.

0.0

CVE-2025-13070 - CSV to SortTable <= 4.2 - Contributor+ LFI

The CSV to SortTable WordPress plugin through 4.2 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as contributor to perform LFI attacks.

πŸ“… Published: Dec. 9, 2025, 6 a.m. πŸ”„ Last Modified: Dec. 9, 2025, 6 a.m.

0.0

CVE-2025-13031 - WPeMatico RSS Feed Fetcher < 2.8.13 - Contributor+ Stored XSS

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.13 does not sanitize and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

πŸ“… Published: Dec. 9, 2025, 6 a.m. πŸ”„ Last Modified: Dec. 9, 2025, 6 a.m.

5.1

CVSS4.0

CVE-2025-14284 -

Versions of the package @tiptap/extension-link before 2.10.4 are vulnerable to Cross-site Scripting (XSS) due to unsanitized user input allowed in setting or toggling links. An attacker can execute arbitrary JavaScript code in the context of the application by injecting a javascript: URL payload in…

πŸ“… Published: Dec. 9, 2025, 5 a.m. πŸ”„ Last Modified: Dec. 9, 2025, 5 a.m.

7.2

CVSS3.1

CVE-2025-13604 - Login Security, FireWall, Malware removal by CleanTalk <= 2.168 - Unauthenticated Stored Cross-Site…

The Login Security, FireWall, Malware removal by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the page URL in all versions up to, and including, 2.168 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers …

πŸ“… Published: Dec. 9, 2025, 4:36 a.m. πŸ”„ Last Modified: Dec. 9, 2025, 4:36 a.m.

0.0

CVE-2025-40344 - ASoC: Intel: avs: Disable periods-elapsed work when closing PCM

In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: avs: Disable periods-elapsed work when closing PCM avs_dai_fe_shutdown() handles the shutdown procedure for HOST HDAudio stream while period-elapsed work services its IRQs. As the former frees the DAI's private conte…

πŸ“… Published: Dec. 9, 2025, 4:10 a.m. πŸ”„ Last Modified: Dec. 9, 2025, 4:10 a.m.

0.0

CVE-2025-40343 - nvmet-fc: avoid scheduling association deletion twice

In the Linux kernel, the following vulnerability has been resolved: nvmet-fc: avoid scheduling association deletion twice When forcefully shutting down a port via the configfs interface, nvmet_port_subsys_drop_link() first calls nvmet_port_del_ctrls() and then nvmet_disable_port(). Both functions…

πŸ“… Published: Dec. 9, 2025, 4:10 a.m. πŸ”„ Last Modified: Dec. 9, 2025, 4:10 a.m.
Total resulsts: 320917
Page 1 of 32,092
Β» next page
Filters