8.3

CVSS3.1

CVE-2025-3260 - grafana: Unauthorized Dashboard Access in Grafana

A security vulnerability in the /apis/dashboard.grafana.app/* endpoints allows authenticated users to bypass dashboard and folder permissions. The vulnerability affects all API versions (v0alpha1, v1alpha1, v2alpha1). Impact: - Viewers can view all dashboards/folders regardless of permissions - …

📅 Published: April 25, 2025, 1:02 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.7

CVSS4.0

CVE-2024-6199 - Unauthenticated Remote Code Execution

An unauthenticated attacker on the WAN interface, with the ability to intercept Dynamic DNS (DDNS) traffic between DDNS services and the modem, could manipulate specific responses to include code that forces a buffer overflow on the modem. Customers that have not enabled Dynamic DNS on their modem…

📅 Published: April 25, 2025, 1:02 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.7

CVSS4.0

CVE-2024-6198 - SNORE Interface Unauthenticated Remote Code Execution

The device exposes a web interface on ports TCP/3030 and TCP/9882. This web service runs lighttpd, which implements the “SNORE” interface. This interface is affected by a stack buffer overflow vulnerability due to insecure path parsing. An attacker with access to the LAN network interface could use…

📅 Published: April 25, 2025, 1:02 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-2470 - Service Finder Bookings <= 5.1 - Unauthenticated Privilege Escalation via 'nsl_registration_store_e…

The Service Finder Bookings plugin for WordPress, used by the Service Finder - Directory and Job Board WordPress Theme, is vulnerable to privilege escalation in all versions up to, and including, 5.1. This is due to a lack of restriction on user role in the 'nsl_registration_store_extra_input' func…

📅 Published: April 25, 2025, 11:12 a.m. 🔄 Last Modified: April 20, 2026, 11:15 p.m.

8.1

CVSS3.1

CVE-2024-11917 - JobSearch WP Job Board <= 2.9.2 - Authentication Bypass via Social Logins

The JobSearch WP Job Board plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.9.2. This is due to improper configurations in the 'jobsearch_xing_response_data_callback', 'set_access_tokes', and 'google_callback' functions. This makes it possible for …

📅 Published: April 25, 2025, 11:12 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-3912 - WS Form LITE – Drag & Drop Contact Form Builder for WordPress <= 1.10.35 - Missing Authorization to…

The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_config' function in all versions up to, and including, 1.10.35. This makes it possible for unauthenticated attackers to r…

📅 Published: April 25, 2025, 11:12 a.m. 🔄 Last Modified: April 22, 2026, 1:45 a.m.

5.5

CVSS3.1

CVE-2025-2986 - IBM Maximo Asset Management cross-site scripting

IBM Maximo Asset Management 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

📅 Published: April 25, 2025, 11:07 a.m. 🔄 Last Modified: Aug. 28, 2025, 3:03 p.m.

7.5

CVSS3.1

CVE-2025-1565 - Mayosis Core <= 5.4.1 - Unauthenticated Arbitrary File Read

The Mayosis Core plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.4.1 via the library/wave-audio/peaks/remote_dl.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain s…

📅 Published: April 25, 2025, 9:21 a.m. 🔄 Last Modified: April 20, 2026, 11:15 p.m.

8.8

CVSS3.1

CVE-2025-1279 - BM Content Builder <= 3.16.2.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Opt…

The BM Content Builder plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the ux_cb_tools_import_item_ajax AJAX action in all versions up to, and including, 3.16.2.1. This makes it possible for authentic…

📅 Published: April 25, 2025, 8:22 a.m. 🔄 Last Modified: April 21, 2026, 9:15 p.m.

6.1

CVSS3.1

CVE-2025-3870 - 1 Decembrie 1918 <= 1.dec.2012 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The 1 Decembrie 1918 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.dec.2012. This is due to missing or incorrect nonce validation on the 1-decembrie-1918/1-decembrie-1918.php page. This makes it possible for unauthenticated attackers to upd…

📅 Published: April 25, 2025, 8:22 a.m. 🔄 Last Modified: April 21, 2026, 9:15 p.m.
Total resulsts: 346583
Page 5403 of 34,659
« previous page » next page
Filters