CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2025-48290

    Last Modified: 27 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in bslthemes Kinsley kinsley allows PHP Local File Inclusion.This issue affects Kinsley: from n/a through <= 3.4.4.

    Published: 6 Nov 2025
    8.1
    High

    CVE-2025-48090

    Last Modified: 27 Apr 2026

    Path Traversal: '.../...//' vulnerability in CocoBasic Blanka - One Page WordPress Theme blanka-wp allows PHP Local File Inclusion.This issue affects Blanka - One Page WordPress Theme: from n/a through < 1.5.

    Published: 6 Nov 2025
    9.3
    Critical

    CVE-2025-48089

    Last Modified: 27 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rainbow-Themes Education WordPress Theme | HiStudy histudy allows SQL Injection.This issue affects Education WordPress Theme | HiStudy: from n/a through < 3.1.0.

    Published: 6 Nov 2025
    5.5
    Medium

    CVE-2025-48086

    Last Modified: 27 Apr 2026

    Deserialization of Untrusted Data vulnerability in wpdreams Ajax Search Lite ajax-search-lite allows Object Injection.This issue affects Ajax Search Lite: from n/a through <= 4.13.3.

    Published: 6 Nov 2025
    7.1
    High

    CVE-2025-48085

    Last Modified: 27 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ZIPANG Simple Stripe simple-stripe allows Stored XSS.This issue affects Simple Stripe: from n/a through <= 0.9.17.

    Published: 6 Nov 2025
    7.1
    High

    CVE-2025-48083

    Last Modified: 27 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in andriassundskard wpNamedUsers wpnamedusers allows Stored XSS.This issue affects wpNamedUsers: from n/a through <= 0.5.

    Published: 6 Nov 2025
    7.1
    High

    CVE-2025-48078

    Last Modified: 27 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Norbert Slick Google Map slick-google-map allows Stored XSS.This issue affects Slick Google Map: from n/a through <= 0.3.

    Published: 6 Nov 2025
    7.1
    High

    CVE-2025-48077

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in nitinmaurya12 Block Country block-country allows Stored XSS.This issue affects Block Country: from n/a through <= 1.0.

    Published: 6 Nov 2025
    9.1
    Critical

    CVE-2025-47588

    Last Modified: 27 Apr 2026

    Improper Control of Generation of Code ('Code Injection') vulnerability in acowebs Dynamic Pricing With Discount Rules for WooCommerce aco-woo-dynamic-pricing allows Code Injection.This issue affects Dynamic Pricing With Discount Rules for WooCommerce: from n/a through <= 4.5.9.

    Published: 6 Nov 2025
    8.1
    High

    CVE-2025-39468

    Last Modified: 28 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in pantherius Modal Survey modal-survey.This issue affects Modal Survey: from n/a through <= 2.0.2.0.1.

    Published: 6 Nov 2025
    8.1
    High

    CVE-2025-39467

    Last Modified: 23 Apr 2026

    Path Traversal: '.../...//' vulnerability in Mikado-Themes Wanderland wanderland allows PHP Local File Inclusion.This issue affects Wanderland: from n/a through <= 1.7.1.

    Published: 6 Nov 2025
    8.1
    High

    CVE-2025-39466

    Last Modified: 27 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Dør dor allows PHP Local File Inclusion.This issue affects Dør: from n/a through <= 2.4.

    Published: 6 Nov 2025
    4.3
    Medium

    CVE-2025-39465

    Last Modified: 27 Apr 2026

    Missing Authorization vulnerability in flippercode Advanced Google Maps wp-google-map-gold allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Google Maps: from n/a through <= 5.8.4.

    Published: 6 Nov 2025
    7.5
    High

    CVE-2025-39463

    Last Modified: 27 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Dessau dessau allows PHP Local File Inclusion.This issue affects Dessau: from n/a through < 1.9.

    Published: 6 Nov 2025
    9.9
    Critical

    CVE-2025-32222

    Last Modified: 27 Apr 2026

    Improper Control of Generation of Code ('Code Injection') vulnerability in Widgetlogic.org Widget Logic widget-logic allows Code Injection.This issue affects Widget Logic: from n/a through <= 6.0.5.

    Published: 6 Nov 2025
    7.1
    High

    CVE-2025-31029

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bingu replyMail replymail allows Stored XSS.This issue affects replyMail: from n/a through <= 1.2.0.

    Published: 6 Nov 2025
    8.5
    High

    CVE-2025-28953

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in axiomthemes smart SEO smartSEO allows SQL Injection.This issue affects smart SEO: from n/a through <= 4.0.

    Published: 6 Nov 2025
    4.1
    Medium

    CVE-2025-22288

    Last Modified: 15 Apr 2026

    Path Traversal: '.../...//' vulnerability in WPMU DEV - Your All-in-One WordPress Platform Smush Image Compression and Optimization wp-smushit allows Path Traversal.This issue affects Smush Image Compression and Optimization: from n/a through <= 3.17.0.

    Published: 6 Nov 2025
    8.7
    High

    CVE-2025-12556

    Last Modified: 15 Apr 2026

    An argument injection vulnerability exists in the affected product that could allow an attacker to execute arbitrary code within the context of the host machine.

    Published: 6 Nov 2025
    8.9
    High

    CVE-2025-11956

    Last Modified: 4 Jun 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Proliz Software Ltd. Co. OBS (Student Affairs Information System) allows Stored XSS. This issue affects OBS (Student Affairs Information System): before 25.0401.

    Published: 6 Nov 2025
    6.1
    Medium

    CVE-2025-10955

    Last Modified: 5 Jun 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Netcad Software Inc. Netigma allows XSS Through HTTP Query Strings. This issue affects Netigma: from 6.3.5 before 6.3.5 V8.

    Published: 6 Nov 2025
    7
    High

    CVE-2025-37735

    Last Modified: 15 Apr 2026

    Improper preservation of permissions in Elastic Defend on Windows hosts can lead to arbitrary files on the system being deleted by the Defend service running as SYSTEM. In some cases, this could result in local privilege escalation.

    Published: 6 Nov 2025
    6.1
    Medium

    CVE-2025-36054

    Last Modified: 12 Dec 2025

    IBM Business Automation Workflow containers 24.0.0 through 24.0.0-IF006, 24.0.1 through 24.0.1-IF004, 25.0.0 through 25.0.0-IF001 and IBM Business Automation Workflow traditional with Process Federation Server 24.0.0 through 24.0.1 and 25.0.0 are vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

    Published: 6 Nov 2025
    4.3
    Medium

    CVE-2025-11268

    Last Modified: 21 Apr 2026

    The Strong Testimonials plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.2.16. This is due to the software allowing users to submit a testimonial in which a value is not properly validated or sanitized prior to being passed to a do_shortcode call. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes if an administrator previews or publishes a crafted testimonial.

    Published: 6 Nov 2025
    4.3
    Medium

    CVE-2025-12360

    Last Modified: 22 Apr 2026

    The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to unauthorized API usage due to a missing capability check on the rtafar_ajax() function in all versions up to, and including, 1.7.7. This makes it possible for authenticated attackers, with Subscriber-level access, to trigger OpenAI API key usage resulting in quota consumption potentially incurring cost.

    Published: 6 Nov 2025
    5.3
    Medium

    CVE-2025-10259

    Last Modified: 15 Apr 2026

    Improper Validation of Specified Quantity in Input vulnerability in TCP Communication Function on Mitsubishi Electric Corporation MELSEC iQ-F Series CPU module allows a remote attacker to disconnect the connection by sending specially crafted TCP packets to cause a denial-of-service (DoS) condition on the products. There is no impact on connections other than the attacked one.

    Published: 6 Nov 2025
    6.1
    Medium

    CVE-2025-12471

    Last Modified: 21 Apr 2026

    The Hubbub Lite – Fast, free social sharing and follow buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dpsp_list_attention_search' parameter in all versions up to, and including, 1.36.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 6 Nov 2025
    7.3
    High

    CVE-2025-9338

    Last Modified: 15 Apr 2026

    A improper restriction of operations within the bounds of a memory buffer exists in AsIO3.sys driver. This vulnerability can be triggered by manually executing a specially crafted process, potentially leading to local privilage escalation. For additional information, please refer to the 'Security Update for Armoury Crate App' section of the ASUS Security Advisory.

    Published: 6 Nov 2025
    4.3
    Medium

    CVE-2025-12560

    Last Modified: 22 Apr 2026

    The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 8.6.0 via the getFullContent() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

    Published: 6 Nov 2025
    5.3
    Medium

    CVE-2025-11271

    Last Modified: 22 Apr 2026

    The Easy Digital Downloads plugin for WordPress is vulnerable to Order Manipulation in all versions up to, and including, 3.5.2 due to an order verification bypass. The verification is unconditionally skipped when the POST body includes verification_override=1. Because this value is attacker-supplied, an unauthenticated actor can submit a forged IPN and have it treated as verified, even on production sites and with verification otherwise enabled. A valid PayPal transaction id is needed, restricting order manipulation to orders placed by the attacker. This, in turn, requires them to have a customer account.

    Published: 6 Nov 2025
    4.3
    Medium

    CVE-2025-12563

    Last Modified: 22 Apr 2026

    The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to limited file upload due to an incorrect capability check on theuploadVideo() function in all versions up to, and including, 8.6.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload mp4 files to the 'wp-content/uploads/<YYYY>/<MM>/' directory.

    Published: 6 Nov 2025
    4.8
    Medium

    CVE-2025-61994

    Last Modified: 15 Apr 2026

    Cross-site scripting vulnerability exists in GROWI prior to v7.2.10. If a malicious user creates a page containing crafted contents, an arbitrary script may be executed on the web browser of a victim user who accesses the page.

    Published: 6 Nov 2025
    4.3
    Medium

    CVE-2025-10691

    Last Modified: 22 Apr 2026

    The Easy Email Subscription plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing or incorrect nonce validation on the show_editsub_page() function. This makes it possible for unauthenticated attackers to delete arbitrary subscribers via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 6 Nov 2025
    4.9
    Medium

    CVE-2025-10683

    Last Modified: 21 Apr 2026

    The Easy Email Subscription plugin for WordPress is vulnerable to SQL Injection via the 'uid' parameter in all versions up to, and including, 1.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 6 Nov 2025
    8.7
    High

    CVE-2025-64171

    Last Modified: 15 Apr 2026

    MARIN3R is a lightweight, CRD based envoy control plane for kubernetes. In versions 0.13.3 and below, there is a cross-namespace secret access vulnerability in the project's DiscoveryServiceCertificate which allows users to bypass RBAC and access secrets in unauthorized namespaces. This issue is fixed in version 0.13.4.

    Published: 6 Nov 2025
    8.9
    High

    CVE-2025-64164

    Last Modified: 7 Nov 2025

    Dataease is an open source data visualization analysis tool. In versions 2.10.14 and below, DataEase did not properly filter when establishing JDBC connections to Oracle, resulting in a risk of JNDI injection (Java Naming and Directory Interface injection). This issue is fixed in version 2.10.15.

    Published: 6 Nov 2025
    8.2
    High

    CVE-2025-27919

    Last Modified: 12 Nov 2025

    An issue was discovered in AnyDesk through 9.0.4. A remotely connected user with the "Control my device" permission can manipulate remote AnyDesk settings and create a password for the Full Access profile without needing confirmation from the counterparty. Consequently, the attacker can later connect without this counterparty confirmation.

    Published: 6 Nov 2025
    6.1
    Medium

    CVE-2025-12789

    Last Modified: 15 Apr 2026

    A flaw was found in Red Hat Single Sign-On. This issue is an Open Redirect vulnerability that occurs during the logout process. The redirect_uri parameter associated with the openid-connect logout protocol does not properly validate the provided URL.

    Published: 6 Nov 2025
    Unknown

    CVE-2025-59396

    Last Modified: 10 Nov 2025

    Not a security vulnerability

    Published: 6 Nov 2025
    7.1
    High

    CVE-2025-63588

    Last Modified: 10 Nov 2025

    An unauthenticated reflected cross-site scripting vulnerability in the query handling of CMSimpleXH allows remote attackers to inject and execute arbitrary JavaScript in a victim's browser via a crafted request (e.g., a maliciously crafted POST login). Successful exploitation may lead to theft of session cookies, credential disclosure, or other client-side impacts.

    Published: 6 Nov 2025
    7.5
    High

    CVE-2025-63551

    Last Modified: 4 Feb 2026

    A Server-Side Request Forgery (SSRF) vulnerability, achievable through an XML External Entity (XXE) injection, exists in MetInfo Content Management System (CMS) thru 8.1. This flaw stems from a defect in the XML parsing logic, which allows an attacker to construct a malicious XML entity that forces the server to initiate an HTTP request to an arbitrary internal or external network address. Successful exploitation could lead to internal network reconnaissance, port scanning, or the retrieval of sensitive information. The vulnerability may be present in the backend API called by or associated with the path `/admin/#/webset/?head_tab_active=0`, where user-provided XML data is processed.

    Published: 6 Nov 2025
    7.5
    High

    CVE-2025-27917

    Last Modified: 8 Dec 2025

    An issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS before 9.0.1, AnyDesk for Linux before 7.0.0, AnyDesk for iOS before 7.1.2, and AnyDesk for Android before 8.0.0. Remote Denial of Service can occur because of incorrect deserialization that results in failed memory allocation and a NULL pointer dereference.

    Published: 6 Nov 2025
    7.4
    High

    CVE-2025-12790

    Last Modified: 15 Apr 2026

    A flaw was found in Rubygem MQTT. By default, the package used to not have hostname validation, resulting in possible Man-in-the-Middle (MITM) attack.

    Published: 6 Nov 2025
    7.1
    High

    CVE-2025-63589

    Last Modified: 10 Nov 2025

    A reflected XSS vulnerability exists in CMSimple_XH 1.8's index.php router when attacker-controlled path segments are not sanitized or encoded before being inserted into the generated HTML (navigation links, breadcrumbs, search form action, footer links). An attacker-controlled string placed in the URL path is reflected into multiple HTML elements, allowing execution of arbitrary JavaScript in victims' browsers visiting a crafted URL.

    Published: 6 Nov 2025
    7.5
    High

    CVE-2025-63560

    Last Modified: 4 Feb 2026

    An issue in KiloView Dual Channel 4k HDMI & 3G-SDI HEVC Video Encoder Firmware v.1.20.0006 allows a remote attacker to cause a denial of service via the systemctrl API System/reFactory component.

    Published: 6 Nov 2025
    8.1
    High

    CVE-2025-63307

    Last Modified: 8 Dec 2025

    alexusmai laravel-file-manager 3.3.1 is vulnerable to Cross Site Scripting (XSS). The application permits user-controlled upload, create, and rename of files to HTML and SVG types and serves those files inline without adequate content-type validation or output sanitization.

    Published: 6 Nov 2025
    7.3
    High

    CVE-2025-60541

    Last Modified: 31 Dec 2025

    A Server-Side Request Forgery (SSRF) in the /api/proxy/ component of linshenkx prompt-optimizer v1.3.0 to v1.4.2 allows attackers to scan internal resources via a crafted request.

    Published: 6 Nov 2025
    6.8
    Medium

    CVE-2025-59392

    Last Modified: 4 Feb 2026

    On Elspec G5 devices through 1.2.2.19, a person with physical access to the device can reset the Admin password by inserting a USB drive (containing a publicly documented reset string) into a USB port.

    Published: 6 Nov 2025
    9.8
    Critical

    CVE-2025-27918

    Last Modified: 8 Dec 2025

    An issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS before 9.0.1, AnyDesk for Linux before 7.0.0, AnyDesk for iOS before 7.1.2, and AnyDesk for Android before 8.0.0. It has an integer overflow and resultant heap-based buffer overflow via a UDP packet during processing of an Identity user image within the Discovery feature, or when establishing a connection between any two clients.

    Published: 6 Nov 2025
    7.5
    High

    CVE-2025-27916

    Last Modified: 8 Dec 2025

    An issue was discovered in AnyDesk for Windows before 9.0.6 and AnyDesk for Android before 8.0.0. When the connection between two clients is established via an IP address, it is possible to manipulate the data and spoof the AnyDesk ID.

    Published: 6 Nov 2025