7.2

CVSS4.0

CVE-2025-64339 - ClipBucket v5: Stored XSS Vulnerability in Manage Playlists

ClipBucket v5 is an open source video sharing platform. In versions 5.5.2-#146 and below, the Manage Playlists feature is vulnerable to stored Cross-site Scripting (XSS),specifically in the Playlist Name field. An authenticated low-privileged user can create a playlist with a malicious name contain…

📅 Published: Nov. 7, 2025, 5:12 a.m. 🔄 Last Modified: Nov. 12, 2025, 4:20 p.m.

7.2

CVSS4.0

CVE-2025-64336 - ClipBucket v5's Manage Photo Feature is Vulnerable to Stored XSS Attack via Photo Title

ClipBucket v5 is an open source video sharing platform. In versions 5.5.2-#146 and below, the Manage Photos feature is vulnerable to stored Cross-site Scripting (XSS). An authenticated regular user can upload a photo with a malicious Photo Title containing HTML/JavaScript code. While the payload do…

📅 Published: Nov. 7, 2025, 4:32 a.m. 🔄 Last Modified: Nov. 12, 2025, 4:20 p.m.

6.5

CVSS3.1

CVE-2025-4522 - IDonate 2.0.0 - 2.1.9 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary U…

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Insecure Direct Object Reference via the admin_post_donor_delete() function in versions 2.0.0 to 2.1.9. By supplying an arbitrary user_id parameter value to the wp_delete_user() function, authent…

📅 Published: Nov. 7, 2025, 4:28 a.m. 🔄 Last Modified: Nov. 12, 2025, 4:20 p.m.

8.8

CVSS3.1

CVE-2025-4519 - IDonate 2.1.5 - 2.1.9 - Missing Authorization to Authenticated (Subscriber+) Account Takeover/Privi…

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the idonate_donor_password() function in versions 2.1.5 to 2.1.9. This makes it possible for authenticated attackers, with Subscriber-lev…

📅 Published: Nov. 7, 2025, 4:28 a.m. 🔄 Last Modified: Nov. 12, 2025, 4:20 p.m.

9.8

CVSS3.1

CVE-2025-12352 - Gravity Forms <= 2.9.20 - Unauthenticated Arbitrary File Upload via 'copy_post_image'

The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the copy_post_image() function in all versions up to, and including, 2.9.20. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's se…

📅 Published: Nov. 7, 2025, 4:28 a.m. 🔄 Last Modified: Nov. 12, 2025, 4:20 p.m.

6.9

CVSS4.0

CVE-2025-64329 - containerd CRI server: Host memory exhaustion through Attach goroutine leak

containerd is an open-source container runtime. Versions 1.7.28 and below, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4, and 2.2.0-beta.0 through 2.2.0-rc.1 contain a bug in the CRI Attach implementation where a user can exhaust memory on the host due to goroutine leaks. This issue is fix…

📅 Published: Nov. 7, 2025, 4:15 a.m. 🔄 Last Modified: Nov. 12, 2025, 4:20 p.m.

8.6

CVSS4.0

CVE-2025-64328 - FreePBX Administration GUI is Vulnerable to Authenticated Command Injection

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore module within the Administrative interface is vulnerable to a post-authentication command injection by an authenticated known user via the testconne…

📅 Published: Nov. 7, 2025, 3:32 a.m. 🔄 Last Modified: Nov. 12, 2025, 4:20 p.m.

8.1

CVSS3.1

CVE-2025-5483 - LC Wizard 1.2.10 - 1.3.0 - Missing Authorization to Unauthenticated Privilege Escalation

The LC Wizard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check in the ghl-wizard/inc/wp_user.php file in versions 1.2.10 to 1.3.0. This makes it possible for unauthenticated attackers to create new user accounts with the administrator role when the PRO fu…

📅 Published: Nov. 7, 2025, 3:27 a.m. 🔄 Last Modified: Nov. 12, 2025, 4:20 p.m.

5.3

CVSS3.1

CVE-2025-64323 - kgateway is missing xDS authorization

kgateway is a Cloud-Native API and AI Gateway. Versions 2.0.4 and below and 2.1.0-agw-cel-rbac through 2.1.0-rc.2 lack authentication, allowing any client with unrestricted network access to the xDS port to retrieve potentially sensitive configuration data including certificate data, backend servic…

📅 Published: Nov. 7, 2025, 3:18 a.m. 🔄 Last Modified: Nov. 12, 2025, 4:20 p.m.

4.6

CVSS4.0

CVE-2025-64187 - OctoPrint is vulnerable to XSS through Action Command Notifications and Prompts

OctoPrint provides a web interface for controlling consumer 3D printers. Versions 1.11.3 and below are affected by a vulnerability that allows injection of arbitrary HTML and JavaScript into Action Command notifications and prompts popups generated by the printer. An attacker who successfully convi…

📅 Published: Nov. 7, 2025, 3:11 a.m. 🔄 Last Modified: Nov. 12, 2025, 4:20 p.m.
Total resulsts: 318147
Page 84 of 31,815
« previous page » next page
Filters