8.8

CVSS3.1

CVE-2025-55061 - Priority - CWE-434 Unrestricted Upload of File with Dangerous Type

CWE-434 Unrestricted Upload of File with Dangerous Type

πŸ“… Published: Dec. 29, 2025, 5:14 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-55060 - Priority - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

πŸ“… Published: Dec. 29, 2025, 5:11 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-15197 - code-projects/anirbandutta9 Content Management System/News-Buzz editposts.php unrestricted upload

A security flaw has been discovered in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This vulnerability affects unknown code of the file /admin/editposts.php. Performing manipulation of the argument image results in unrestricted upload. The attack may be initiated remotel…

πŸ“… Published: Dec. 29, 2025, 5:02 p.m. πŸ”„ Last Modified: Jan. 7, 2026, 8:50 p.m.

6.9

CVSS4.0

CVE-2025-15196 - code-projects Assessment Management login.php sql injection

A vulnerability was identified in code-projects Assessment Management 1.0. This affects an unknown part of the file login.php. Such manipulation of the argument userid leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.

πŸ“… Published: Dec. 29, 2025, 4:32 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:12 a.m.

5.3

CVSS3.1

CVE-2025-53627 - Meshtastic firmware allows forged DMs with no PKC to show up as encrypted

Meshtastic is an open source mesh networking solution. The Meshtastic firmware (starting from version 2.5) introduces asymmetric encryption (PKI) for direct messages, but when the `pki_encrypted` flag is missing, the firmware silently falls back to legacy AES-256-CTR channel encryption. This was an…

πŸ“… Published: Dec. 29, 2025, 4:18 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:11 p.m.

0.0

CVE-2025-68868 - WordPress Wp Text Slider Widget plugin <= 1.0 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codeaffairs Wp Text Slider Widget wp-text-slider-widget allows Stored XSS.This issue affects Wp Text Slider Widget: from n/a through <= 1.0.

πŸ“… Published: Dec. 29, 2025, 4:12 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2025-68870 - WordPress CookieHint WP plugin <= 1.0.0 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in reDim GmbH CookieHint WP cookiehint-wp allows PHP Local File Inclusion.This issue affects CookieHint WP: from n/a through <= 1.0.0.

πŸ“… Published: Dec. 29, 2025, 4:09 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2025-68876 - WordPress Invelity SPS connect plugin <= 1.0.8 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in INVELITY Invelity SPS connect invelity-sps-connect allows Reflected XSS.This issue affects Invelity SPS connect: from n/a through <= 1.0.8.

πŸ“… Published: Dec. 29, 2025, 4:05 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2025-68877 - WordPress CedCommerce Integration for Good Market plugin <= 1.0.6 - Local File Inclusion vulnerabil…

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cedcommerce CedCommerce Integration for Good Market ced-good-market-integration allows PHP Local File Inclusion.This issue affects CedCommerce Integration for Good Market: from n…

πŸ“… Published: Dec. 29, 2025, 4:03 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-15195 - code-projects Assessment Management add-module.php sql injection

A vulnerability was determined in code-projects Assessment Management 1.0. Affected by this issue is some unknown functionality of the file /admin/add-module.php. This manipulation of the argument linked[] causes sql injection. The attack can be initiated remotely. The exploit has been publicly dis…

πŸ“… Published: Dec. 29, 2025, 4:02 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:12 a.m.
Total resulsts: 345149
Page 1982 of 34,515
Β« previous page Β» next page
Filters