CVE Feed

    Dashboard / CVE

    5.9
    Medium

    CVE-2025-58810

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jimmywb Simple Link List Widget simple-link-list-widget allows Stored XSS.This issue affects Simple Link List Widget: from n/a through <= 0.3.2.

    Published: 5 Sept 2025
    7.1
    High

    CVE-2025-58809

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Nick Ciske To Lead For Salesforce salesforce-wordpress-to-lead allows Reflected XSS.This issue affects To Lead For Salesforce: from n/a through <= 2.7.3.9.

    Published: 5 Sept 2025
    6.5
    Medium

    CVE-2025-58808

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Babar prettyPhoto prettyphoto allows Stored XSS.This issue affects prettyPhoto: from n/a through <= 1.2.5.

    Published: 5 Sept 2025
    7.1
    High

    CVE-2025-58807

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Dsingh Purge Varnish Cache purge-varnish allows Stored XSS.This issue affects Purge Varnish Cache: from n/a through <= 2.6.

    Published: 5 Sept 2025
    7.1
    High

    CVE-2025-58806

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Tom Longridge WordPress Error Monitoring by Bugsnag bugsnag allows Stored XSS.This issue affects WordPress Error Monitoring by Bugsnag: from n/a through <= 1.6.3.

    Published: 5 Sept 2025
    5.9
    Medium

    CVE-2025-58805

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Widgetize Pages Light widgetize-pages-light allows Stored XSS.This issue affects Widgetize Pages Light: from n/a through <= 3.0.

    Published: 5 Sept 2025
    4.3
    Medium

    CVE-2025-58804

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in brijrajs WooCommerce Single Page Checkout woo-single-page-checkout allows Cross Site Request Forgery.This issue affects WooCommerce Single Page Checkout: from n/a through <= 1.2.7.

    Published: 5 Sept 2025
    4.3
    Medium

    CVE-2025-58802

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in michalzagdan TrustMate.io – WooCommerce integration trustmate-io-integration-for-woocommerce allows Cross Site Request Forgery.This issue affects TrustMate.io – WooCommerce integration: from n/a through <= 1.16.0.

    Published: 5 Sept 2025
    5.4
    Medium

    CVE-2025-58801

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in KCS Responder responder allows Cross Site Request Forgery.This issue affects Responder: from n/a through <= 4.3.8.

    Published: 5 Sept 2025
    4.3
    Medium

    CVE-2025-58800

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Steve Truman WP Email Template wp-email-template allows Cross Site Request Forgery.This issue affects WP Email Template: from n/a through <= 2.8.5.

    Published: 5 Sept 2025
    4.3
    Medium

    CVE-2025-58799

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in themelocation Custom WooCommerce Checkout Fields Editor add-fields-to-checkout-page-woocommerce allows Cross Site Request Forgery.This issue affects Custom WooCommerce Checkout Fields Editor: from n/a through <= 1.3.4.

    Published: 5 Sept 2025
    4.3
    Medium

    CVE-2025-58798

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Bjorn Manintveld BCM Duplicate Menu bcm-duplicate-menu allows Cross Site Request Forgery.This issue affects BCM Duplicate Menu: from n/a through <= 1.1.3.

    Published: 5 Sept 2025
    5.3
    Medium

    CVE-2025-58797

    Last Modified: 23 Apr 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Mahmudul Hasan Arif Ninja Charts ninja-charts allows Retrieve Embedded Sensitive Data.This issue affects Ninja Charts: from n/a through <= 3.3.5.

    Published: 5 Sept 2025
    6.5
    Medium

    CVE-2025-58796

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dudaster Elementor Element Condition ele-conditions allows Stored XSS.This issue affects Elementor Element Condition: from n/a through <= 1.0.5.

    Published: 5 Sept 2025
    4.3
    Medium

    CVE-2025-58795

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Payoneer Checkout Payoneer Checkout payoneer-checkout allows Content Spoofing.This issue affects Payoneer Checkout: from n/a through <= 3.4.0.

    Published: 5 Sept 2025
    4.3
    Medium

    CVE-2025-58794

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in rainafarai Notification for Telegram notification-for-telegram allows Cross Site Request Forgery.This issue affects Notification for Telegram: from n/a through <= 3.5.

    Published: 5 Sept 2025
    6.5
    Medium

    CVE-2025-58793

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPBean WPB Elementor Addons wpb-elementor-addons allows Stored XSS.This issue affects WPB Elementor Addons: from n/a through <= 1.7.

    Published: 5 Sept 2025
    4.3
    Medium

    CVE-2025-58792

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WPKube Authors List authors-list allows Cross Site Request Forgery.This issue affects Authors List: from n/a through <= 2.0.6.2.

    Published: 5 Sept 2025
    5.9
    Medium

    CVE-2025-58791

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arjan Olsder SEO Auto Linker wpa-seo-auto-linker allows Stored XSS.This issue affects SEO Auto Linker: from n/a through <= 1.5.3.

    Published: 5 Sept 2025
    6.5
    Medium

    CVE-2025-58790

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKube Kiwi kiwi-social-share allows Stored XSS.This issue affects Kiwi: from n/a through <= 2.1.8.

    Published: 5 Sept 2025
    7.6
    High

    CVE-2025-58789

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle WP Full Stripe Free wp-full-stripe-free allows SQL Injection.This issue affects WP Full Stripe Free: from n/a through <= 8.2.5.

    Published: 5 Sept 2025
    7.6
    High

    CVE-2025-58788

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce allows Blind SQL Injection.This issue affects License Manager for WooCommerce: from n/a through <= 3.0.12.

    Published: 5 Sept 2025
    6.5
    Medium

    CVE-2025-58787

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify Popup themify-popup allows Stored XSS.This issue affects Themify Popup: from n/a through <= 1.4.2.

    Published: 5 Sept 2025
    6.5
    Medium

    CVE-2025-58786

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VW THEMES Ibtana – Ecommerce Product Addons ibtana-ecommerce-product-addons allows DOM-Based XSS.This issue affects Ibtana – Ecommerce Product Addons: from n/a through <= 0.4.7.6.

    Published: 5 Sept 2025
    5.4
    Medium

    CVE-2025-58785

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Jiro Sasamoto Ray Enterprise Translation lingotek-translation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ray Enterprise Translation: from n/a through <= 1.7.2.

    Published: 5 Sept 2025
    6.5
    Medium

    CVE-2025-58784

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in arisoft ARI Fancy Lightbox ari-fancy-lightbox allows Stored XSS.This issue affects ARI Fancy Lightbox: from n/a through <= 1.4.0.

    Published: 5 Sept 2025
    4.3
    Medium

    CVE-2025-58783

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in gutentor Gutentor gutentor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gutentor: from n/a through <= 3.5.5.

    Published: 5 Sept 2025
    5.4
    Medium

    CVE-2025-8695

    Last Modified: 5 Jun 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Netcad NetGIS Server allows Reflected XSS. This issue affects NetGIS Server: from 5.2.4 through 22.08.2025.

    Published: 5 Sept 2025
    3.2
    Low

    CVE-2024-21977

    Last Modified: 15 Apr 2026

    Incomplete cleanup after loading a CPU microcode patch may allow a privileged attacker to degrade the entropy of the RDRAND instruction, potentially resulting in loss of integrity for SEV-SNP guests.

    Published: 5 Sept 2025
    Unknown

    CVE-2025-58910

    Last Modified: 6 Sept 2025

    Not used

    Published: 5 Sept 2025
    Unknown

    CVE-2025-58911

    Last Modified: 6 Sept 2025

    Not used

    Published: 5 Sept 2025
    Unknown

    CVE-2025-58912

    Last Modified: 6 Sept 2025

    Not used

    Published: 5 Sept 2025
    Unknown

    CVE-2025-58908

    Last Modified: 6 Sept 2025

    Not used

    Published: 5 Sept 2025
    Unknown

    CVE-2025-58909

    Last Modified: 6 Sept 2025

    Not used

    Published: 5 Sept 2025
    Unknown

    CVE-2025-58906

    Last Modified: 6 Sept 2025

    Not used

    Published: 5 Sept 2025
    Unknown

    CVE-2025-58907

    Last Modified: 6 Sept 2025

    Not used

    Published: 5 Sept 2025
    Unknown

    CVE-2025-58904

    Last Modified: 6 Sept 2025

    Not used

    Published: 5 Sept 2025
    Unknown

    CVE-2025-58905

    Last Modified: 6 Sept 2025

    Not used

    Published: 5 Sept 2025
    5.1
    Medium

    CVE-2025-58313

    Last Modified: 11 Sept 2025

    Race condition vulnerability in the device standby module. Impact: Successful exploitation of this vulnerability may cause feature exceptions of the device standby module.

    Published: 5 Sept 2025
    7.5
    High

    CVE-2025-58296

    Last Modified: 11 Sept 2025

    Race condition vulnerability in the audio module. Impact: Successful exploitation of this vulnerability may affect function stability.

    Published: 5 Sept 2025
    8.4
    High

    CVE-2025-58281

    Last Modified: 11 Sept 2025

    Out-of-bounds read vulnerability in the runtime interpreter module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 5 Sept 2025
    8.4
    High

    CVE-2025-58280

    Last Modified: 29 Sept 2025

    Vulnerability of exposing object heap addresses in the Ark eTS module. Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 5 Sept 2025
    6.8
    Medium

    CVE-2025-58276

    Last Modified: 11 Sept 2025

    Permission verification vulnerability in the home screen module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 5 Sept 2025
    4.7
    Medium

    CVE-2025-48395

    Last Modified: 15 Apr 2026

    An attacker with authenticated and privileged access could modify the contents of a non-sensitive file by traversing the path in the limited shell of the CLI. This security issue has been fixed in the latest version of NMC G2 which is available on the Eaton download center.

    Published: 5 Sept 2025
    4.3
    Medium

    CVE-2025-8944

    Last Modified: 20 Jan 2026

    The OceanWP WordPress theme before 4.1.2 is vulnerable to an option update due to a missing capability check on one of its AJAX request handler, allowing any authenticated users, such as subscriber to update the darkMod` setting.

    Published: 5 Sept 2025
    8.4
    High

    CVE-2025-58400

    Last Modified: 15 Apr 2026

    RATOC RAID Monitoring Manager for Windows provided by RATOC Systems, Inc. registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.

    Published: 5 Sept 2025
    5.3
    Medium

    CVE-2025-41408

    Last Modified: 15 Apr 2026

    Improper authorization in handler for custom URL scheme issue in "Yahoo! Shopping" App for Android versions prior to 14.15.0 allows a remote unauthenticated attacker may lead a user to access an arbitrary website on the vulnerable App. As a result, the user may become a victim of a phishing attack.

    Published: 5 Sept 2025
    8.5
    High

    CVE-2025-55671

    Last Modified: 15 Apr 2026

    Uncontrolled search path element issue exists in TkEasyGUI versions prior to v1.0.22. If this vulnerability is exploited, arbitrary code may be executed with the privilege of running the program.

    Published: 5 Sept 2025
    9.3
    Critical

    CVE-2025-55037

    Last Modified: 15 Apr 2026

    Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in TkEasyGUI versions prior to v1.0.22. If this vulnerability is exploited, an arbitrary OS command may be executed by a remote unauthenticated attacker if the settings are configured to construct messages from external sources.

    Published: 5 Sept 2025
    5.1
    Medium

    CVE-2025-58401

    Last Modified: 15 Apr 2026

    Obsidian GitHub Copilot Plugin versions prior to 1.1.7 store Github API token in cleartext form. As a result, an attacker may perform unauthorized operations on the linked Github account.

    Published: 5 Sept 2025