2.4

CVSS4.0

CVE-2025-36744 - SolarEdge SE3680H - Information Exposure during Bootloader Loop

SolarEdge SE3680H has unauthenticated disclosure of sensitive information during the bootloader loop. While the device repeatedly initializes and waits for boot instructions, the bootloader emits diagnostic output this behavior can leak operating system information.

📅 Published: Dec. 12, 2025, 3:05 p.m. 🔄 Last Modified: Dec. 23, 2025, 5:20 p.m.

8.6

CVSS4.0

CVE-2025-36745 - SolarEdge SE3680H contains Linux Kernel vulnerabilities

SolarEdge SE3680H  ships with an outdated Linux kernel containing unpatched vulnerabilities in core subsystems. An attacker with network or local access can exploit these flaws to achieve remote code execution, privilege escalation, or disclosure of sensitive information.

📅 Published: Dec. 12, 2025, 3:05 p.m. 🔄 Last Modified: Dec. 23, 2025, 5:21 p.m.

7.2

CVSS4.0

CVE-2025-58770 - TCG2 TPM RT Not Locked Issue

APTIOV contains a vulnerability in BIOS where a user may cause “Improper Handling of Insufficient Permissions or Privileges” by local access. Successful exploitation of this vulnerability can lead to escalation of authorization and potentially impact Integrity and Availability.

📅 Published: Dec. 12, 2025, 3:03 p.m. 🔄 Last Modified: Jan. 12, 2026, 3:18 p.m.

2.4

CVSS4.0

CVE-2025-36755 - CleverDisplay BlueOne unauthorized BIOS access through physical USB keyboard

The CleverDisplay BlueOne hardware player is designed with its USB interfaces physically enclosed and inaccessible under normal operating conditions. Researchers demonstrated that, after cicumventing the device’s protective enclosure, it was possible to connect a USB keyboard and press ESC during b…

📅 Published: Dec. 12, 2025, 2:58 p.m. 🔄 Last Modified: Dec. 14, 2025, 9:16 p.m.

8.8

CVSS3.1

CVE-2025-13506 - Improper Authorization in Nebim Neyir's Nebim V3 ERP

Execution with Unnecessary Privileges vulnerability in Nebim Neyir Computer Industry and Services Inc. Nebim V3 ERP allows Expanding Control over the Operating System from the Database.This issue affects Nebim V3 ERP: from 2.0.59 before 3.0.1.

📅 Published: Dec. 12, 2025, 12:19 p.m. 🔄 Last Modified: Dec. 14, 2025, 9:16 p.m.

6.4

CVSS3.1

CVE-2025-14030 - AI Feeds <= 1.0.22 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'aife_post_meta' …

The AI Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'aife_post_meta' shortcode in all versions up to, and including, 1.0.22 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level acces…

📅 Published: Dec. 12, 2025, 11:15 a.m. 🔄 Last Modified: Dec. 14, 2025, 9:16 p.m.

4.3

CVSS3.1

CVE-2025-12407 - Events Manager – Calendar, Bookings, Tickets, and more! <= 7.2.2.2 - Cross-Site Request Forgery to …

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.2.2. This is due to missing or incorrect nonce validation on the 'location_delete' action. This makes it possible for unauthenticate…

📅 Published: Dec. 12, 2025, 11:15 a.m. 🔄 Last Modified: Dec. 14, 2025, 9:16 p.m.

5.3

CVSS3.1

CVE-2025-12408 - Events Manager <= 7.2.2.2 - Unauthenticated Information Exposure

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 7.2.2.2 via the 'get_location' action due to insufficient restrictions on which locations can be included. This makes it possible for unauthen…

📅 Published: Dec. 12, 2025, 11:15 a.m. 🔄 Last Modified: Dec. 14, 2025, 9:16 p.m.

6.4

CVSS3.1

CVE-2025-12965 - Magical Posts Display <= 1.2.54 - Authenticated (Author+) Stored Cross-Site Scripting via Magical P…

The Magical Posts Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mpac_title_tag' parameter in the Magical Posts Accordion widget in all versions up to, and including, 1.2.54 due to insufficient input sanitization and output escaping on user-supplied HTML tag name…

📅 Published: Dec. 12, 2025, 11:15 a.m. 🔄 Last Modified: Dec. 14, 2025, 9:16 p.m.

4.3

CVSS3.1

CVE-2025-14159 - Secure Copy Content Protection and Content Locking <= 4.9.2 - Cross-Site Request Forgery to Data Ex…

The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.9.2. This is due to missing nonce validation on the 'ays_sccp_results_export_file' AJAX action. This makes it possible for unauthenticated …

📅 Published: Dec. 12, 2025, 11:15 a.m. 🔄 Last Modified: Dec. 14, 2025, 9:16 p.m.
Total resulsts: 343040
Page 2024 of 34,304
« previous page » next page
Filters