8.1

CVSS3.1

CVE-2025-68975 - WordPress Eagle Booking plugin <= 1.3.4.3 - Insecure Direct Object References (IDOR) vulnerability

Authorization Bypass Through User-Controlled Key vulnerability in Eagle-Themes Eagle Booking eagle-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Eagle Booking: from n/a through <= 1.3.4.3.

πŸ“… Published: Dec. 30, 2025, 10:47 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-68974 - WordPress WordPress Social Login and Register plugin <= 7.7.0 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in miniOrange WordPress Social Login and Register miniorange-login-openid allows PHP Local File Inclusion.This issue affects WordPress Social Login and Register: from n/a through <=…

πŸ“… Published: Dec. 30, 2025, 10:47 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS4.0

CVE-2025-15244 - PHPEMS Purchase Request race condition

A vulnerability has been found in PHPEMS up to 11.0. This impacts an unknown function of the component Purchase Request Handler. The manipulation leads to race condition. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is said to be dif…

πŸ“… Published: Dec. 30, 2025, 10:32 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:16 a.m.

6.9

CVSS4.0

CVE-2025-15243 - code-projects Simple Stock System login.php sql injection

A flaw has been found in code-projects Simple Stock System 1.0. This affects an unknown function of the file /market/login.php. Executing a manipulation of the argument Username can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used.

πŸ“… Published: Dec. 30, 2025, 10:02 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 7:17 a.m.

2.3

CVSS4.0

CVE-2025-15242 - PHPEMS Coupon race condition

A vulnerability was detected in PHPEMS up to 11.0. The impacted element is an unknown function of the component Coupon Handler. Performing a manipulation results in race condition. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitability is regarded as di…

πŸ“… Published: Dec. 30, 2025, 9:32 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 7:17 a.m.

9.1

CVSS3.1

CVE-2025-15359 - DVP-12SE11T - Out-of-bound memory write Vulnerability

DVP-12SE11T - Out-of-bound memory write Vulnerability

πŸ“… Published: Dec. 30, 2025, 9:07 a.m. πŸ”„ Last Modified: Jan. 5, 2026, 4:54 p.m.

7.5

CVSS3.1

CVE-2025-15358 - DVP-12SE11T - Denial of Service Vulnerability

DVP-12SE11T - Denial of Service Vulnerability

πŸ“… Published: Dec. 30, 2025, 9:04 a.m. πŸ”„ Last Modified: Jan. 6, 2026, 9:04 p.m.

5.1

CVSS4.0

CVE-2025-15241 - CloudPanel Community Edition HTTP Header users redirect

A security vulnerability has been detected in CloudPanel Community Edition up to 2.5.1. The affected element is an unknown function of the file /admin/users of the component HTTP Header Handler. Such manipulation of the argument Referer leads to open redirect. It is possible to launch the attack re…

πŸ“… Published: Dec. 30, 2025, 9:02 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2025-15103 - DVP-12SE11T - Authentication Bypass via Partial Password Disclosure

DVP-12SE11T - Authentication Bypass via Partial Password Disclosure

πŸ“… Published: Dec. 30, 2025, 8:55 a.m. πŸ”„ Last Modified: Jan. 6, 2026, 9:04 p.m.

9.1

CVSS3.1

CVE-2025-15102 - DVP-12SE11T - Password Protection Bypass

DVP-12SE11T - Password Protection Bypass

πŸ“… Published: Dec. 30, 2025, 8:48 a.m. πŸ”„ Last Modified: Jan. 6, 2026, 9:06 p.m.
Total resulsts: 345291
Page 1963 of 34,530
Β« previous page Β» next page
Filters