6.4

CVSS3.1

CVE-2025-1458 - Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote A…

The Element Pack Addons for Elementor – Free Templates and Widgets for Your WordPress Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets like Dual Button, Creative Button, Image Stack and more in all versions up to, and including, 5.10.29 due to insuffici…

πŸ“… Published: April 26, 2025, 5:34 a.m. πŸ”„ Last Modified: April 22, 2026, 8:15 a.m.

8.1

CVSS3.1

CVE-2025-2105 - Jupiter X Core <= 4.8.11 - Unauthenticated PHP Object Injection via PHAR

The Jupiter X Core plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.8.11 via deserialization of untrusted input from the 'file' parameter of the 'raven_download_file' function. This makes it possible for attackers to inject a PHP Object through a PH…

πŸ“… Published: April 26, 2025, 5:34 a.m. πŸ”„ Last Modified: April 21, 2026, 9:15 p.m.

8.8

CVSS3.1

CVE-2024-13808 - Xpro Elementor Addons - Pro <= 1.4.9 - Authenticated (Contributor+) Remote Code Execution

The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.9 via the custom PHP widget. This is due to their only being client side controls when determining who can access the widget. This makes it possible for authenticate…

πŸ“… Published: April 26, 2025, 4:22 a.m. πŸ”„ Last Modified: April 8, 2026, 4:34 p.m.

7.3

CVSS3.1

CVE-2025-2801 - Create custom forms for WordPress with a smart form plugin for smart businesses <= 1.2.4 - Unauthen…

The The Create custom forms for WordPress with a smart form plugin for smart businesses plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.4. This is due to the software allowing users to execute an action that does not properly validate a …

πŸ“… Published: April 26, 2025, 3:24 a.m. πŸ”„ Last Modified: April 20, 2026, 11:15 p.m.

4.9

CVSS3.1

CVE-2025-46655 -

CodiMD through 2.5.4 has a CSP-based protection mechanism against XSS through uploaded SVG documents containing JavaScript, but it can be bypassed in certain cases of different-origin file storage, such as AWS S3. NOTE: it can be considered a user error if AWS is employed for hosting untrusted Java…

πŸ“… Published: April 26, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.1

CVSS3.1

CVE-2025-46653 - formidable: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Formidable

Formidable (aka node-formidable) 2.1.0 through 3.x before 3.5.3 relies on hexoid to prevent guessing of filenames for untrusted executable content; however, hexoid is documented as not "cryptographically secure." (Also, there is a scenario in which only the last two characters of a hexoid string ne…

πŸ“… Published: April 26, 2025, midnight πŸ”„ Last Modified: Oct. 16, 2025, 8:30 p.m.

4.5

CVSS3.1

CVE-2025-46646 - Ghostscript: Mishandling of Overlong UTF-8 Encoding in Artifex Ghostscript's decode_utf8 Function

In Artifex Ghostscript before 10.05.0, decode_utf8 in base/gp_utf8.c mishandles overlong UTF-8 encoding. NOTE: this issue exists because of an incomplete fix for CVE-2024-46954.

πŸ“… Published: April 26, 2025, midnight πŸ”„ Last Modified: June 23, 2025, 7:31 p.m.

6.4

CVSS3.1

CVE-2024-53636 -

An arbitrary file upload vulnerability via writefile.php of Serosoft Academia Student Information System (SIS) EagleR-1.0.118 allows attackers to execute arbitrary code via ../ in the filePath parameter.

πŸ“… Published: April 26, 2025, midnight πŸ”„ Last Modified: Jan. 29, 2026, 5:57 p.m.

4.9

CVSS3.1

CVE-2025-46654 -

CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be bypassed by uploading a .html file that references an uploaded .js file.

πŸ“… Published: April 26, 2025, midnight πŸ”„ Last Modified: Aug. 5, 2025, 3:14 p.m.

8.1

CVSS3.1

CVE-2025-5987 - Libssh: invalid return code for chacha20 poly1305 with openssl backend

A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an attacker manages to exhaust the heap space, this error is not detected and may lead to libssh using a partially initialized cipher context. This occurs because the OpenSSL error code returned aliases with the …

πŸ“… Published: April 26, 2025, midnight πŸ”„ Last Modified: March 20, 2026, 9:17 p.m.
Total resulsts: 346616
Page 5402 of 34,662
Β« previous page Β» next page
Filters