8.8

CVSS3.1

CVE-2025-3761 - My Tickets – Accessible Event Ticketing <= 2.0.16 - Authenticated (Subscriber+) Privilege Escalation

The My Tickets – Accessible Event Ticketing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.16. This is due to the mt_save_profile() function not appropriately restricting access to unauthorized users to update roles. This makes it possible for a…

📅 Published: April 24, 2025, 6:57 a.m. 🔄 Last Modified: April 22, 2026, 7:45 a.m.

3.1

CVSS3.1

CVE-2025-41423 - Unauthorized Playbooks Post Deletion in Mattermost Playbooks Plugin

Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate permissions for the API endpoint /plugins/playbooks/api/v0/signal/keywords/ignore-thread, allowing any user or attacker to delete posts containing actions created by the Playbooks bot, even without c…

📅 Published: April 24, 2025, 6:50 a.m. 🔄 Last Modified: Sept. 29, 2025, 9:06 p.m.

6.5

CVSS3.1

CVE-2025-35965 - DoS in Mattermost Playbooks via Excessive Task Actions

Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to validate the uniqueness and quantity of task actions within the UpdateRunTaskActions GraphQL operation, which allows an attacker to create task items containing an excessive number of actions triggered by specific pos…

📅 Published: April 24, 2025, 6:49 a.m. 🔄 Last Modified: Sept. 29, 2025, 9:10 p.m.

6.5

CVSS3.1

CVE-2025-41395 - Webapp DoS via malicious retrospective post in Playbooks

Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate the props used by the RetrospectivePost custom post type in the Playbooks plugin, which allows an attacker to create a specially crafted post with maliciously crafted props and cause a denial of serv…

📅 Published: April 24, 2025, 6:48 a.m. 🔄 Last Modified: Oct. 1, 2025, 7:35 p.m.

6.8

CVSS4.0

CVE-2025-32730 -

Use of hard-coded cryptographic key vulnerability in i-PRO Configuration Tool affects the network system for i-PRO Co., Ltd. surveillance cameras and recorders. This vulnerability allows a local authenticated attacker to use the authentication information from the last connected surveillance camera…

📅 Published: April 24, 2025, 6:38 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS3.1

CVE-2025-2558 - The Wound <= 0.0.1 - Unauthenticated LFI

The-wound WordPress theme through 0.0.1 does not validate some parameters before using them to generate paths passed to include function/s, allowing unauthenticated users to perform LFI attacks and download arbitrary file from the server

📅 Published: April 24, 2025, 6 a.m. 🔄 Last Modified: June 23, 2025, 3:17 p.m.

4.8

CVSS3.1

CVE-2025-1453 - Category Posts Widget < 4.9.20 - Admin+ Stored XSS

The Category Posts Widget WordPress plugin before 4.9.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

📅 Published: April 24, 2025, 6 a.m. 🔄 Last Modified: May 7, 2025, 7:11 p.m.

4.4

CVSS3.1

CVE-2025-3435 - MangBoard WP <= 1.8.6 - Authenticated (Administrator+) Stored Cross-Site Scripting via Board Header…

The Mang Board WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the board_header and board_footer parameters in all versions up to, and including, 1.8.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with admin…

📅 Published: April 24, 2025, 3:21 a.m. 🔄 Last Modified: April 21, 2026, 9:15 p.m.

8.6

CVSS4.0

CVE-2025-1976 - Code injection exposure in Fabric OS 9.1.0 through 9.1.1d6

Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary code with full root privileges on Fabric OS versions 9.1.0 through 9.1.1d6.

📅 Published: April 24, 2025, 2:55 a.m. 🔄 Last Modified: Feb. 26, 2026, 6:28 p.m.

6.5

CVSS3.1

CVE-2025-44135 -

A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0 in /Scheduling/pages/profile_update.php. Manipulating the parameter username will cause SQL injection attacks.

📅 Published: April 24, 2025, midnight 🔄 Last Modified: May 14, 2025, 1:04 p.m.
Total resulsts: 346532
Page 5418 of 34,654
« previous page » next page
Filters