CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2023-23729

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through 2.3.0.

    Published: 9 Dec 2025
    7.8
    High

    CVE-2025-13662

    Last Modified: 26 Feb 2026

    Improper verification of cryptographic signatures in the patch management component of Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary code. User Interaction is required.

    Published: 9 Dec 2025
    7.1
    High

    CVE-2025-13661

    Last Modified: 26 Feb 2026

    Path traversal in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote authenticated attacker to write arbitrary files outside of the intended directory. User interaction is required.

    Published: 9 Dec 2025
    8.8
    High

    CVE-2025-13659

    Last Modified: 26 Feb 2026

    Improper control of dynamically managed code resources in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote, unauthenticated attacker to write arbitrary files on the server, potentially leading to remote code execution. User interaction is required.

    Published: 9 Dec 2025
    4.8
    Medium

    CVE-2025-9638

    Last Modified: 11 Dec 2025

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Portabilis i-Educar allows Stored Cross-Site Scripting (XSS) via the matricula_interna parameter in the educar_usuario_cad.php endpoint. This issue affects i-Educar: 2.10.0.

    Published: 9 Dec 2025
    7.3
    High

    CVE-2025-5469

    Last Modified: 15 Apr 2026

    Uncontrolled Search Path Element vulnerability in Yandex Messenger on MacOS allows Search Order Hijacking.This issue affects Telemost: before 2.245

    Published: 9 Dec 2025
    9.6
    Critical

    CVE-2025-10573

    Last Modified: 26 Feb 2026

    Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the context of an administrator session. User interaction is required.

    Published: 9 Dec 2025
    7.3
    High

    CVE-2025-5471

    Last Modified: 19 Feb 2026

    Uncontrolled Search Path Element vulnerability in Yandex Telemost on MacOS allows Search Order Hijacking.This issue affects Telemost: before 2.19.1.

    Published: 9 Dec 2025
    7.3
    High

    CVE-2025-5470

    Last Modified: 15 Apr 2026

    Uncontrolled Search Path Element vulnerability in Yandex Disk on MacOS allows Search Order Hijacking.This issue affects Disk: before 3.2.45.3275.

    Published: 9 Dec 2025
    5.4
    Medium

    CVE-2025-13642

    Last Modified: 21 Apr 2026

    The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.7 due to insufficient input sanitization on the `type` parameter in the form preview functionality. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes via the `pp_preview_form` endpoint.

    Published: 9 Dec 2025
    5.4
    Medium

    CVE-2025-67467

    Last Modified: 24 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in StellarWP GiveWP give allows Cross Site Request Forgery.This issue affects GiveWP: from n/a through <= 4.13.1.

    Published: 9 Dec 2025
    5.3
    Medium

    CVE-2025-66533

    Last Modified: 28 Apr 2026

    Improper Control of Generation of Code ('Code Injection') vulnerability in StellarWP GiveWP give allows Code Injection.This issue affects GiveWP: from n/a through <= 4.13.1.

    Published: 9 Dec 2025
    8.4
    High

    CVE-2025-2296

    Last Modified: 15 Apr 2026

    EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access. Successful exploitation of this vulnerability could alter control flow in unexpected ways, potentially allowing arbitrary command execution and impacting Confidentiality, Integrity, and Availability.

    Published: 9 Dec 2025
    2.3
    Low

    CVE-2025-14345

    Last Modified: 11 Dec 2025

    A post-authentication flaw in the network two-phase commit protocol used for cross-shard transactions in MongoDB Server may lead to logical data inconsistencies under specific conditions which are not predictable and exist for a very short period of time. This error can cause the transaction coordination logic to misinterpret the transaction as committed, resulting in inconsistent state on those shards. This may lead to low integrity and availability impact. This issue impacts MongoDB Server v8.0 versions prior to 8.0.16, MongoDB Server v7.0 versions prior to 7.0.26 and MongoDB server v8.2 versions prior to 8.2.2.

    Published: 9 Dec 2025
    5.8
    Medium

    CVE-2024-38798

    Last Modified: 15 Apr 2026

    EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of Sensitive Information to an Unauthorized Actor” by local access. Successful exploitation of this vulnerability will lead to possible information disclosure or escalation of privilege and impact Confidentiality.

    Published: 9 Dec 2025
    Unknown

    CVE-2025-67610

    Last Modified: 10 Dec 2025

    Not used

    Published: 9 Dec 2025
    Unknown

    CVE-2025-67611

    Last Modified: 10 Dec 2025

    Not used

    Published: 9 Dec 2025
    Unknown

    CVE-2025-67612

    Last Modified: 10 Dec 2025

    Not used

    Published: 9 Dec 2025
    Unknown

    CVE-2025-67613

    Last Modified: 10 Dec 2025

    Not used

    Published: 9 Dec 2025
    Unknown

    CVE-2025-67608

    Last Modified: 10 Dec 2025

    Not used

    Published: 9 Dec 2025
    Unknown

    CVE-2025-67609

    Last Modified: 10 Dec 2025

    Not used

    Published: 9 Dec 2025
    Unknown

    CVE-2025-67605

    Last Modified: 10 Dec 2025

    Not used

    Published: 9 Dec 2025
    Unknown

    CVE-2025-67606

    Last Modified: 10 Dec 2025

    Not used

    Published: 9 Dec 2025
    Unknown

    CVE-2025-67607

    Last Modified: 10 Dec 2025

    Not used

    Published: 9 Dec 2025
    4.3
    Medium

    CVE-2025-63077

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Happy Addons for Elementor: from n/a through <= 3.20.3.

    Published: 9 Dec 2025
    7.5
    High

    CVE-2025-63076

    Last Modified: 15 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Dream-Theme The7 Elements dt-the7-core allows PHP Local File Inclusion.This issue affects The7 Elements: from n/a through <= 2.7.11.

    Published: 9 Dec 2025
    6.5
    Medium

    CVE-2025-63075

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in muffingroup Betheme betheme allows DOM-Based XSS.This issue affects Betheme: from n/a through <= 28.2.

    Published: 9 Dec 2025
    7.5
    High

    CVE-2025-63074

    Last Modified: 24 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Dream-Theme The7 dt-the7 allows PHP Local File Inclusion.This issue affects The7: from n/a through < 12.8.1.1.

    Published: 9 Dec 2025
    6.5
    Medium

    CVE-2025-63073

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dream-Theme The7 dt-the7 allows DOM-Based XSS.This issue affects The7: from n/a through < 12.9.0.

    Published: 9 Dec 2025
    6.5
    Medium

    CVE-2025-63072

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in THEMECO Cornerstone cornerstone allows Stored XSS.This issue affects Cornerstone: from n/a through <= 7.7.3.

    Published: 9 Dec 2025
    5.3
    Medium

    CVE-2025-63071

    Last Modified: 24 Apr 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in averta Shortcodes and extra features for Phlox theme auxin-elements allows Retrieve Embedded Sensitive Data.This issue affects Shortcodes and extra features for Phlox theme: from n/a through <= 2.17.15.

    Published: 9 Dec 2025
    4.3
    Medium

    CVE-2025-63070

    Last Modified: 15 Apr 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Shahjada Download Manager download-manager allows Retrieve Embedded Sensitive Data.This issue affects Download Manager: from n/a through <= 3.3.32.

    Published: 9 Dec 2025
    5.3
    Medium

    CVE-2025-63069

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Vinod Dalvi Ivory Search add-search-to-menu allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ivory Search: from n/a through <= 5.5.12.

    Published: 9 Dec 2025
    5.3
    Medium

    CVE-2025-63068

    Last Modified: 15 Apr 2026

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in sevenspark Contact Form 7 – Dynamic Text Extension contact-form-7-dynamic-text-extension allows Code Injection.This issue affects Contact Form 7 – Dynamic Text Extension: from n/a through <= 5.0.5.

    Published: 9 Dec 2025
    4.3
    Medium

    CVE-2025-63067

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in p-themes Porto Theme - Functionality porto-functionality allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Porto Theme - Functionality: from n/a through < 3.7.3.

    Published: 9 Dec 2025
    6.5
    Medium

    CVE-2025-63066

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in p-themes Porto Theme - Functionality porto-functionality allows Stored XSS.This issue affects Porto Theme - Functionality: from n/a through < 3.7.3.

    Published: 9 Dec 2025
    5.3
    Medium

    CVE-2025-63065

    Last Modified: 24 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Media LIbrary Assistant: from n/a through <= 3.29.

    Published: 9 Dec 2025
    6.5
    Medium

    CVE-2025-63064

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ashanjay EventON eventon allows Stored XSS.This issue affects EventON: from n/a through <= 4.9.12.

    Published: 9 Dec 2025
    5.3
    Medium

    CVE-2025-63063

    Last Modified: 27 Apr 2026

    Missing Authorization vulnerability in Yandex Metrika Yandex.Metrica wp-yandex-metrika allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Yandex.Metrica: from n/a through <= 1.2.2.

    Published: 9 Dec 2025
    7.5
    High

    CVE-2025-63062

    Last Modified: 27 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AndonDesign UDesign Core u-design-core allows PHP Local File Inclusion.This issue affects UDesign Core: from n/a through <= 4.14.0.

    Published: 9 Dec 2025
    6.5
    Medium

    CVE-2025-63061

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hogash KALLYAS kallyas allows DOM-Based XSS.This issue affects KALLYAS: from n/a through < 4.25.0.

    Published: 9 Dec 2025
    4.3
    Medium

    CVE-2025-63060

    Last Modified: 27 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in hogash KALLYAS kallyas allows Cross Site Request Forgery.This issue affects KALLYAS: from n/a through < 4.25.0.

    Published: 9 Dec 2025
    6.5
    Medium

    CVE-2025-63059

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in arscode Ninja Popups arscode-ninja-popups allows Stored XSS.This issue affects Ninja Popups: from n/a through <= 4.7.8.

    Published: 9 Dec 2025
    4.3
    Medium

    CVE-2025-63058

    Last Modified: 24 Apr 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Hiroaki Miyashita Custom Field Template custom-field-template allows Retrieve Embedded Sensitive Data.This issue affects Custom Field Template: from n/a through <= 2.7.6.

    Published: 9 Dec 2025
    6.5
    Medium

    CVE-2025-63057

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Roxnor Wp Ultimate Review wp-ultimate-review allows DOM-Based XSS.This issue affects Wp Ultimate Review: from n/a through <= 2.3.7.

    Published: 9 Dec 2025
    4.3
    Medium

    CVE-2025-63056

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in bestwebsoft Contact Form by BestWebSoft contact-form-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form by BestWebSoft: from n/a through <= 4.3.6.

    Published: 9 Dec 2025
    6.5
    Medium

    CVE-2025-63055

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liton Arefin Master Addons for Elementor master-addons allows Stored XSS.This issue affects Master Addons for Elementor: from n/a through <= 2.0.9.9.4.

    Published: 9 Dec 2025
    5.3
    Medium

    CVE-2025-63054

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quiz And Survey Master: from n/a through <= 10.3.2.

    Published: 9 Dec 2025
    6.5
    Medium

    CVE-2025-63052

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GalleryCreator SimpLy Gallery simply-gallery-block allows Stored XSS.This issue affects SimpLy Gallery: from n/a through <= 3.3.2.1.

    Published: 9 Dec 2025
    6.5
    Medium

    CVE-2025-63050

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sizam REHub Framework rehub-framework allows Stored XSS.This issue affects REHub Framework: from n/a through < 19.9.9.7.

    Published: 9 Dec 2025