5.6

CVSS3.1

CVE-2025-2939 - Ninja Tables – Easy Data Table Builder <= 5.0.18 - Unauthenticated PHP Object Injection to Limited …

The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.0.18 via deserialization of untrusted input from the args[callback] parameter . This makes it possible for unauthenticated attackers to inject a PHP Object. …

πŸ“… Published: June 3, 2025, 2:27 a.m. πŸ”„ Last Modified: April 22, 2026, 1:30 a.m.

4.3

CVSS3.1

CVE-2025-4047 - Broken Link Checker <= 2.4.4 - Missing Autorization to Authenticated (Subscriber+) Plugin Status Da…

The Broken Link Checker plugin for WordPress is vulnerable to unauthorized data access due to a missing capability check on the ajax_full_status and ajax_dashboard_status functions in all versions up to, and including, 2.4.4. This makes it possible for authenticated attackers, with Subscriber-level…

πŸ“… Published: June 3, 2025, 2:27 a.m. πŸ”„ Last Modified: April 21, 2026, 8:45 p.m.

7.8

CVSS3.1

CVE-2025-23098 -

An issue was discovered in Samsung Mobile Processor Exynos 980, 990, 1080, 2100, 1280, 2200, 1380. A Use-After-Free in the mobile processor leads to privilege escalation.

πŸ“… Published: June 3, 2025, midnight πŸ”„ Last Modified: June 6, 2025, 6:44 p.m.

9.8

CVSS3.1

CVE-2025-32106 -

In Audiocodes Mediapack MP-11x through 6.60A.369.002, a crafted POST request request may result in an unauthenticated remote user's ability to execute unauthorized code.

πŸ“… Published: June 3, 2025, midnight πŸ”„ Last Modified: June 18, 2025, 2:15 p.m.

8.8

CVSS3.1

CVE-2025-23102 -

An issue was discovered in Samsung Mobile Processor Exynos 980, 990, 1080, 2100, 1280, 2200, 1380, 1480 and 2400. A Double Free in the mobile processor leads to privilege escalation.

πŸ“… Published: June 3, 2025, midnight πŸ”„ Last Modified: June 10, 2025, 8:07 p.m.

10

CVSS3.1

CVE-2025-45854 -

/server/executeExec of JEHC-BPM 2.0.1 allows attackers to execute arbitrary code via execParams.

πŸ“… Published: June 3, 2025, midnight πŸ”„ Last Modified: Aug. 26, 2025, 7:15 p.m.

8.4

CVSS3.1

CVE-2025-46154 -

Foxcms v1.25 has a SQL time injection in the $_POST['dbname'] parameter of installdb.php.

πŸ“… Published: June 3, 2025, midnight πŸ”„ Last Modified: June 9, 2025, 6:06 p.m.

6.1

CVSS3.1

CVE-2025-43924 -

Cross Site Scripting vulnerability was discovered in Unicom Focal Point 7.6.1. The val parameter in SettingController (for /fp/admin/settings/loginpage) and the rootserviceurl parameter in FriendsController (for /fp/admin/settings/friends), entered by an admin, allow stored XSS.

πŸ“… Published: June 3, 2025, midnight πŸ”„ Last Modified: June 9, 2025, 6:04 p.m.

8.6

CVSS3.1

CVE-2025-23103 -

An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bounds writes.

πŸ“… Published: June 3, 2025, midnight πŸ”„ Last Modified: June 6, 2025, 6:49 p.m.

4.6

CVSS3.1

CVE-2025-43925 -

An issue was discovered in Unicom Focal Point 7.6.1. The database is encrypted with a hardcoded key, making it easier to recover the cleartext data.

πŸ“… Published: June 3, 2025, midnight πŸ”„ Last Modified: June 11, 2025, 7:08 p.m.
Total resulsts: 346442
Page 4921 of 34,645
Β« previous page Β» next page
Filters