5.3

CVSS4.0

CVE-2025-59020 - TYPO3 CMS Allows Broken Access Control in Edit Document Controller

By exploiting the defVals parameter, attackers could bypass field‑level access checks during record creation in the TYPO3 backend. This gave them the ability to insert arbitrary data into prohibited exclude fields of a database table for which the user already has write permission for a reduced set…

πŸ“… Published: Jan. 13, 2026, 11:53 a.m. πŸ”„ Last Modified: Jan. 14, 2026, 7:15 p.m.

5.4

CVSS3.1

CVE-2025-14001 - WP Duplicate Page <= 1.8 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post Dup…

The WP Duplicate Page plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the 'duplicateBulkHandle' and 'duplicateBulkHandleHPOS' functions in all versions up to, and including, 1.8. This makes it possible for authenticated attackers, with Con…

πŸ“… Published: Jan. 13, 2026, 11:21 a.m. πŸ”„ Last Modified: April 21, 2026, 4:30 p.m.

8.7

CVSS4.0

CVE-2025-40944 -

A vulnerability has been identified in SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0) (All versions), SIMATIC ET 200MP IM 155-5 PN HF (6ES7155-5AA00-0AC0) (All versions >= V4.2.0), SIMATIC ET 200SP IM 155-6 MF HF (6ES7155-6MU00-0CN0) (All versions), SIMATIC ET 200SP IM 155-6 PN HA (incl. SIPLUS …

πŸ“… Published: Jan. 13, 2026, 9:44 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS4.0

CVE-2025-40942 -

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.4). Affected application contains a local privilege escalation vulnerability that could allow an attacker to run arbitrary code with elevated privileges.

πŸ“… Published: Jan. 13, 2026, 9:44 a.m. πŸ”„ Last Modified: Jan. 22, 2026, 8:58 p.m.

10

CVSS4.0

CVE-2025-40805 -

Affected devices do not properly enforce user authentication on specific API endpoints. This could facilitate an unauthenticated remote attacker to circumvent authentication and impersonate a legitimate user. Successful exploitation requires that the attacker has learned the identity of a legitimat…

πŸ“… Published: Jan. 13, 2026, 9:44 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-41717 - Config-Upload Code Injection

An unauthenticated remote attacker can trick a high privileged user into uploading a malicious payload via the config-upload endpoint, leading to code injection as root. This results in a total loss of confidentiality, availability and integrity due to improper control of code generation ('Code Inj…

πŸ“… Published: Jan. 13, 2026, 7:48 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2025-14829 - e-xact-hosted-payment <= 2.0 - Unauthenticated Arbitrary File Deletion

The E-xact | Hosted Payment | WordPress plugin through 2.0 is vulnerable to arbitrary file deletion due to insufficient file path validation. This makes it possible for unauthenticated attackers to delete arbitrary files on the server.

πŸ“… Published: Jan. 13, 2026, 6 a.m. πŸ”„ Last Modified: April 27, 2026, 9:45 p.m.

9.8

CVSS3.1

CVE-2025-10915 - Dreamer Blog <= 1.2 - Subscriber+ Arbitrary Plugin Installation

The Dreamer Blog WordPress theme through 1.2 is vulnerable to arbitrary installations due to a missing capability check.

πŸ“… Published: Jan. 13, 2026, 6 a.m. πŸ”„ Last Modified: April 27, 2026, 9:45 p.m.

8.8

CVSS3.1

CVE-2025-66177 -

There is a Stack overflow Vulnerability in the device Search and Discovery feature of Hikvision NVR/DVR/CVR/IPC models. If exploited, an attacker on the same local area network (LAN) could cause the device to malfunction by sending specially crafted packets to an unpatched device.

πŸ“… Published: Jan. 13, 2026, 1:47 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-66176 -

There is a Stack overflow Vulnerability in the device Search and Discovery feature of Hikvision Access Control Products. If exploited, an attacker on the same local area network (LAN) could cause the device to malfunction by sending specially crafted packets to an unpatched device.

πŸ“… Published: Jan. 13, 2026, 1:47 a.m. πŸ”„ Last Modified: March 18, 2026, 4:16 p.m.
Total resulsts: 349182
Page 2174 of 34,919
Β« previous page Β» next page
Filters