5.9

CVSS4.0

CVE-2025-12058 - Vulnerability in Keras Model.load_model Leading to Arbitrary Local File Loading and SSRF

The Keras.Model.load_model method, including when executed with the intended security mitigation safe_mode=True, is vulnerable to arbitrary local file loading and Server-Side Request Forgery (SSRF). This vulnerability stems from the way the StringLookup layer is handled during model loading from โ€ฆ

๐Ÿ“… Published: Oct. 29, 2025, 8:48 a.m. ๐Ÿ”„ Last Modified: Oct. 29, 2025, 8:48 a.m.

5.9

CVSS3.1

CVE-2025-64291 - WordPress Premmerce User Roles plugin <= 1.0.13 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Premmerce Premmerce User Roles premmerce-user-roles allows Stored XSS.This issue affects Premmerce User Roles: from n/a through <= 1.0.13.

๐Ÿ“… Published: Oct. 29, 2025, 8:38 a.m. ๐Ÿ”„ Last Modified: Oct. 29, 2025, 2:18 p.m.

4.3

CVSS3.1

CVE-2025-64290 - WordPress Premmerce Product Search for WooCommerce plugin <= 2.2.4 - Cross Site Request Forgery (CSโ€ฆ

Cross-Site Request Forgery (CSRF) vulnerability in Premmerce Premmerce Product Search for WooCommerce premmerce-search allows Cross Site Request Forgery.This issue affects Premmerce Product Search for WooCommerce: from n/a through <= 2.2.4.

๐Ÿ“… Published: Oct. 29, 2025, 8:38 a.m. ๐Ÿ”„ Last Modified: Oct. 29, 2025, 2:20 p.m.

0.0

CVE-2025-64289 - WordPress Premmerce Product Search for WooCommerce plugin <= 2.2.4 - Cross Site Scripting (XSS) vulโ€ฆ

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Premmerce Premmerce Product Search for WooCommerce premmerce-search allows Stored XSS.This issue affects Premmerce Product Search for WooCommerce: from n/a through <= 2.2.4.

๐Ÿ“… Published: Oct. 29, 2025, 8:38 a.m. ๐Ÿ”„ Last Modified: Oct. 29, 2025, 8:38 a.m.

0.0

CVE-2025-64288 - WordPress Premmerce plugin <= 1.3.19 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Premmerce Premmerce premmerce allows Cross Site Request Forgery.This issue affects Premmerce: from n/a through <= 1.3.19.

๐Ÿ“… Published: Oct. 29, 2025, 8:38 a.m. ๐Ÿ”„ Last Modified: Oct. 29, 2025, 8:38 a.m.

0.0

CVE-2025-64286 - WordPress WP Rentals theme <= 3.13.1 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in WpEstate WP Rentals wprentals allows Cross Site Request Forgery.This issue affects WP Rentals: from n/a through <= 3.13.1.

๐Ÿ“… Published: Oct. 29, 2025, 8:38 a.m. ๐Ÿ”„ Last Modified: Oct. 29, 2025, 8:38 a.m.

0.0

CVE-2025-64285 - WordPress Premmerce Wholesale Pricing for WooCommerce plugin <= 1.1.10 - Broken Access Control vulnโ€ฆ

Missing Authorization vulnerability in Premmerce Premmerce Wholesale Pricing for WooCommerce premmerce-woocommerce-wholesale-pricing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Premmerce Wholesale Pricing for WooCommerce: from n/a through <= 1.1.10.

๐Ÿ“… Published: Oct. 29, 2025, 8:38 a.m. ๐Ÿ”„ Last Modified: Oct. 29, 2025, 8:38 a.m.

7.5

CVSS3.1

CVE-2025-64284 - WordPress Majestic Support plugin <= 1.1.1 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Majestic Support Majestic Support majestic-support allows PHP Local File Inclusion.This issue affects Majestic Support: from n/a through <= 1.1.1.

๐Ÿ“… Published: Oct. 29, 2025, 8:38 a.m. ๐Ÿ”„ Last Modified: Oct. 29, 2025, 2:13 p.m.

6.5

CVSS3.1

CVE-2025-64283 - WordPress RTMKit plugin <= 1.6.7 - Insecure Direct Object References (IDOR) vulnerability

Authorization Bypass Through User-Controlled Key vulnerability in Rometheme RTMKit rometheme-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RTMKit: from n/a through <= 1.6.7.

๐Ÿ“… Published: Oct. 29, 2025, 8:38 a.m. ๐Ÿ”„ Last Modified: Oct. 29, 2025, 2:14 p.m.

4.3

CVSS3.1

CVE-2025-64234 - WordPress Evergreen Content Poster plugin <= 1.4.5 - Broken Access Control vulnerability

Missing Authorization vulnerability in Evergreen Content Poster Evergreen Content Poster evergreen-content-poster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Evergreen Content Poster: from n/a through <= 1.4.5.

๐Ÿ“… Published: Oct. 29, 2025, 8:38 a.m. ๐Ÿ”„ Last Modified: Oct. 29, 2025, 2:33 p.m.
Total resulsts: 316165
Page 5 of 31,617
ยซ previous page ยป next page
Filters