6.1

CVSS3.1

CVE-2026-21489 - iccDEV has Out-of-bounds Read and Integer Underflow (Wrap or Wraparound)

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below have Out-of-bounds Read and Integer Underflow (Wrap or Wraparound) vulnerabilities in its CIccCalculatorFunc::SequenceNeedTempReset function. This issue is fixed in version 2.3.1.…

📅 Published: Jan. 6, 2026, 1:57 p.m. 🔄 Last Modified: April 18, 2026, 5 p.m.

6.1

CVSS3.1

CVE-2026-21488 - iccDEV has Out-of-bounds Read, Heap-based Buffer Overflow and Improper Null Termination

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below are vulnerable to Out-of-bounds Read, Heap-based Buffer Overflow and Improper Null Termination through its CIccTagText::Read function. This issue is fixed in version 2.3.1.2.

📅 Published: Jan. 6, 2026, 1:52 p.m. 🔄 Last Modified: April 18, 2026, 8:15 a.m.

6.5

CVSS3.1

CVE-2025-9318 - Quiz and Survey Master (QSM) <= 10.3.1 - Authenticated (Subscriber+) SQL Injection via `is_linking`…

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based SQL Injection via the ‘is_linking’ parameter in all versions up to, and including, 10.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on …

📅 Published: Jan. 6, 2026, 9:20 a.m. 🔄 Last Modified: April 20, 2026, 7 p.m.

6.5

CVSS3.1

CVE-2025-9637 - Quiz and Survey Master (QSM) <= 10.3.1 - Missing Authorization to Unpublished, Private And Password…

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability and status checks on multiple functions in all versions up to, and including, 10.3.1. This makes it possible for unauthenticat…

📅 Published: Jan. 6, 2026, 9:20 a.m. 🔄 Last Modified: April 22, 2026, 4 a.m.

6.4

CVSS3.1

CVE-2025-14552 - MediaPress <= 1.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Plugin's Shortco…

The MediaPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mpp-uploader shortcode in all versions up to, and including, 1.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attac…

📅 Published: Jan. 6, 2026, 9:20 a.m. 🔄 Last Modified: April 22, 2026, 12:15 a.m.

6.5

CVSS3.1

CVE-2025-5919 - Appointment Booking and Scheduling Calendar Plugin – WP Timetics <= 1.0.36 - Missing Authorization …

The Appointment Booking and Scheduling Calendar Plugin – WP Timetics plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the update and register_routes functions in all versions up to, and including, 1.0.36. This makes it possible …

📅 Published: Jan. 6, 2026, 8:21 a.m. 🔄 Last Modified: April 20, 2026, 7 p.m.

5.3

CVSS3.1

CVE-2025-13964 - LearnPress – WordPress LMS Plugin <= 4.3.2 - Missing Authentication to Unauthenticated Course Modif…

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the catch_lp_ajax function in all versions up to, and including, 4.3.2. This makes it possible for unauthenticated attackers to modify course contents b…

📅 Published: Jan. 6, 2026, 8:21 a.m. 🔄 Last Modified: April 21, 2026, 5 p.m.

4.3

CVSS3.1

CVE-2025-9294 - Quiz And Survey Master <= 10.3.1 - Missing Authorization to Authenticated (Subscriber+) Quiz Result…

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the qsm_dashboard_delete_result function in all versions up to, and including, 10.3.1. This makes it possible for authenticated attacker…

📅 Published: Jan. 6, 2026, 8:21 a.m. 🔄 Last Modified: April 21, 2026, 12:45 a.m.

5.4

CVSS3.1

CVE-2025-13766 - MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.6 Missing Authorization …

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthorized modification and deletion of data due to a missing capability checks on multiple REST API endpoints in all versions up to, and including, 3.7.6. This makes it possible for auth…

📅 Published: Jan. 6, 2026, 8:21 a.m. 🔄 Last Modified: April 22, 2026, 8:30 p.m.

4.3

CVSS3.1

CVE-2025-13812 - GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress <= 7.6.…

The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the gamipress_ajax_get_posts and gamipress_ajax_get_users functions in all versions up to, and inclu…

📅 Published: Jan. 6, 2026, 7:22 a.m. 🔄 Last Modified: April 21, 2026, 5 p.m.
Total resulsts: 347742
Page 2130 of 34,775
« previous page » next page
Filters