8.8
CVE-2025-3058 - Xelion Webchat <= 9.1.0 - Authenticated (Subscriber+) Arbitrary Options Update
The Xelion Webchat plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the xwc_save_settings() function in all versions up to, and including, 9.1.0. This makes it possible for authenticated attackers, witโฆ
9.1
CVE-2025-3065 - Database Toolset <= 1.8.4 - Unauthenticated Arbitrary File Deletion
The Database Toolset plugin is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, and including, 1.8.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote codeโฆ
4.3
CVE-2024-12244 - Missing Authorization in GitLab
An issue has been discovered in access controls could allow users to view certain restricted project information even when related features are disabled in GitLab EE, affecting all versions from 17.7 prior to 17.9.7, 17.10 prior to 17.10.5, and 17.11 prior to 17.11.1.
6.5
CVE-2025-0639 - Allocation of Resources Without Limits or Throttling in GitLab
An issue has been discovered affecting service availability via issue preview in GitLab CE/EE affecting all versions from 16.7 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.
7.7
CVE-2025-1908 - Business Logic Errors in GitLab
An issue has been discovered in GitLab EE/CE that could allow an attacker to track users' browsing activities, potentially leading to full account take-over, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.
8.8
CVE-2025-3761 - My Tickets โ Accessible Event Ticketing <= 2.0.16 - Authenticated (Subscriber+) Privilege Escalation
The My Tickets โ Accessible Event Ticketing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.16. This is due to the mt_save_profile() function not appropriately restricting access to unauthorized users to update roles. This makes it possible for aโฆ
3.1
CVE-2025-41423 - Unauthorized Playbooks Post Deletion in Mattermost Playbooks Plugin
Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10ย fail to properly validate permissions for the API endpoint /plugins/playbooks/api/v0/signal/keywords/ignore-thread, allowing any user or attacker to delete posts containing actions created by the Playbooks bot, even without cโฆ
6.5
CVE-2025-35965 - DoS in Mattermost Playbooks via Excessive Task Actions
Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to validate the uniqueness and quantity of task actions within the UpdateRunTaskActions GraphQL operation, which allows an attacker to create task items containing an excessive number of actions triggered by specific posโฆ
6.5
CVE-2025-41395 - Webapp DoS via malicious retrospective post in Playbooks
Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate the props used by the RetrospectivePost custom post type in the Playbooks plugin, whichย allows an attacker to create a specially crafted post with maliciously crafted propsย and cause a denial of servโฆ
6.8
CVE-2025-32730 -
Use of hard-coded cryptographic key vulnerability in i-PRO Configuration Tool affects the network system for i-PRO Co., Ltd. surveillance cameras and recorders. This vulnerability allows a local authenticated attacker to use the authentication information from the last connected surveillance cameraโฆ