7.5

CVSS3.1

CVE-2025-34509 - Sitecore XM and XP Hardcoded Credentials

Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.1.4 rev. 011974 PRE, all versions of 10.2, 10.3 to 10.3.3 rev. 011967 PRE, and 10.4 to 10.4.1 rev. 011941 PRE contain a hardcoded user account. Unauthenticated and remote attackers can use this account to access admin…

πŸ“… Published: June 17, 2025, 6:20 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

9.8

CVSS3.1

CVE-2025-49220 -

An insecure deserialization operation in Trend Micro Apex Central below version 8.0.7007 could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49219 but is in a different method.

πŸ“… Published: June 17, 2025, 5:43 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

9.8

CVSS3.1

CVE-2025-49219 -

An insecure deserialization operation in Trend Micro Apex Central below versions 8.0.7007 could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49220 but is in a different method.

πŸ“… Published: June 17, 2025, 5:43 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

7.5

CVSS3.1

CVE-2025-47867 -

A Local File Inclusion vulnerability in a Trend Micro Apex Central widget in versions below 8.0.6955 could allow an attacker to include arbitrary files to execute as PHP code and lead to remote code execution on affected installations.

πŸ“… Published: June 17, 2025, 5:42 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

4.3

CVSS3.1

CVE-2025-47866 -

An unrestricted file upload vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker to upload arbitrary files on affected installations.

πŸ“… Published: June 17, 2025, 5:42 p.m. πŸ”„ Last Modified: Sept. 8, 2025, 9:04 p.m.

7.5

CVSS3.1

CVE-2025-47865 -

A Local File Inclusion vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker to gain remote code execution on affected installations.

πŸ“… Published: June 17, 2025, 5:42 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

7.5

CVSS3.1

CVE-2025-33122 - IBM i privilege escalation

IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 could allow a user to gain elevated privileges due to an unqualified library call in IBM Advanced Job Scheduler for i. A malicious actor could cause user-controlled code to run with administrator privilege.

πŸ“… Published: June 17, 2025, 5:13 p.m. πŸ”„ Last Modified: Aug. 24, 2025, 11:51 a.m.

4.3

CVSS3.1

CVE-2025-48111 - WordPress YITH PayPal Express Checkout for WooCommerce plugin <= 1.49.0 - Cross Site Request Forger…

Cross-Site Request Forgery (CSRF) vulnerability in YITHEMES YITH PayPal Express Checkout for WooCommerce allows Cross Site Request Forgery. This issue affects YITH PayPal Express Checkout for WooCommerce: from n/a through 1.49.0.

πŸ“… Published: June 17, 2025, 3:01 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS3.1

CVE-2025-48333 - WordPress eForm - WordPress Form Builder < 4.19.1 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPQuark eForm - WordPress Form Builder wp-fsqm-pro allows Reflected XSS.This issue affects eForm - WordPress Form Builder: from n/a through < 4.19.1.

πŸ“… Published: June 17, 2025, 3:01 p.m. πŸ”„ Last Modified: April 23, 2026, 3:31 p.m.

10

CVSS3.1

CVE-2025-49071 - WordPress Flozen < 1.5.1 - Arbitrary File Upload Vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in NasaTheme Flozen flozen-theme allows Upload a Web Shell to a Web Server.This issue affects Flozen: from n/a through < 1.5.1.

πŸ“… Published: June 17, 2025, 3:01 p.m. πŸ”„ Last Modified: April 23, 2026, 3:31 p.m.
Total resulsts: 349182
Page 5003 of 34,919
Β« previous page Β» next page
Filters