4.3

CVSS3.1

CVE-2025-69327 - WordPress Car Rental Manager plugin <= 1.0.9 - Broken Access Control vulnerability

Missing Authorization vulnerability in magepeopleteam Car Rental Manager car-rental-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Car Rental Manager: from n/a through <= 1.0.9.

πŸ“… Published: Jan. 6, 2026, 4:36 p.m. πŸ”„ Last Modified: April 24, 2026, 6:28 p.m.

7.1

CVSS3.1

CVE-2025-69084 - WordPress Photo Gallery plugin <= 2.7.7.26 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gt3themes Photo Gallery gt3-photo-video-gallery allows Reflected XSS.This issue affects Photo Gallery: from n/a through <= 2.7.7.26.

πŸ“… Published: Jan. 6, 2026, 4:28 p.m. πŸ”„ Last Modified: April 23, 2026, 3:36 p.m.

7.1

CVSS3.1

CVE-2025-69085 - WordPress JobBank plugin <= 1.2.2 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins JobBank jobbank allows Reflected XSS.This issue affects JobBank: from n/a through <= 1.2.2.

πŸ“… Published: Jan. 6, 2026, 4:27 p.m. πŸ”„ Last Modified: April 23, 2026, 3:36 p.m.

8.1

CVSS3.1

CVE-2025-69086 - WordPress Issabella theme <= 1.1.2 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes Issabella issabella allows PHP Local File Inclusion.This issue affects Issabella: from n/a through <= 1.1.2.

πŸ“… Published: Jan. 6, 2026, 4:26 p.m. πŸ”„ Last Modified: April 23, 2026, 3:36 p.m.

7.6

CVSS3.1

CVE-2025-36589 -

Dell Unisphere for PowerMax, version(s) 9.2.4.x, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access to data and resources outside of the intended…

πŸ“… Published: Jan. 6, 2026, 4:20 p.m. πŸ”„ Last Modified: Jan. 22, 2026, 8:44 p.m.

5.9

CVSS4.0

CVE-2025-63082 - Joomla! Core - [20260101] - Inadequate content filtering for data URLs

Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags.

πŸ“… Published: Jan. 6, 2026, 4:01 p.m. πŸ”„ Last Modified: Jan. 30, 2026, 6:41 p.m.

5.9

CVSS4.0

CVE-2025-63083 - Joomla! Core - [20260102] - XSS vector in the pagebreak plugin

Lack of output escaping leads to a XSS vector in the pagebreak plugin.

πŸ“… Published: Jan. 6, 2026, 4:01 p.m. πŸ”„ Last Modified: Jan. 30, 2026, 6:41 p.m.

8.6

CVSS4.0

CVE-2020-36917 - iDS6 DSSPro Digital Signage System 6.2 Cleartext Password Disclosure via Cookie

iDS6 DSSPro Digital Signage System 6.2 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept authentication credentials through cleartext cookie transmission. Attackers can exploit the autoSave feature to capture user passwords during man-in-the-middle …

πŸ“… Published: Jan. 6, 2026, 3:53 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS4.0

CVE-2020-36914 - QiHang Media Web Digital Signage 3.0.9 Cookie Authentication Credentials Disclosure

QiHang Media Web Digital Signage 3.0.9 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept user authentication credentials through cleartext cookie transmission. Attackers can perform man-in-the-middle attacks to capture and potentially misuse stored …

πŸ“… Published: Jan. 6, 2026, 3:53 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2020-36925 - Arteco Web Client DVR/NVR Session ID Brute Force Authentication Bypass

Arteco Web Client DVR/NVR contains a session hijacking vulnerability with insufficient session ID complexity that allows remote attackers to bypass authentication. Attackers can brute force session IDs within a specific numeric range to obtain valid sessions and access live camera streams without a…

πŸ“… Published: Jan. 6, 2026, 3:52 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 347730
Page 2125 of 34,773
Β« previous page Β» next page
Filters