Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-69428

An issue in Pro-Bit before v1.77.4 allows unauthenticated attackers to directly access sensitive directory and its subdirectories.

PUBLISHED
Vendor
n/a
Product
n/a
Provider severity
HIGH
Conflicts
1

CVE-2025-69426

The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) contain hardcoded credentials for an operating system user account within an initialization script. The SSH service is network-accessible without IP-based restrictions. Although the configuration disables SCP and pseudo-TTY allocation, an attacker can authenticate using the hardcoded credentials and establish SSH local port forwarding to access the Docker socket. By mounting the host filesystem via Docker, an attacker can es

PUBLISHED
Vendor
RUCKUS Networks
Product
vRIoT IOT Controller
Provider severity
CRITICAL
Conflicts
1

CVE-2025-69425

The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) expose a command execution service on TCP port 2004 running with root privileges. Authentication to this service relies on a hardcoded Time-based One-Time Password (TOTP) secret and an embedded static token. An attacker who extracts these credentials from the appliance or a compromised device can generate valid authentication tokens and execute arbitrary OS commands with root privileges, resulting in complete system compromi

PUBLISHED
Vendor
RUCKUS Networks
Product
vRIoT IoT Controller
Provider severity
CRITICAL
Conflicts
1

CVE-2025-69421

Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function. Impact summary: A NULL pointer dereference can trigger a crash which leads to Denial of Service for an application processing PKCS#12 files. The PKCS12_item_decrypt_d2i_ex() function does not check whether the oct parameter is NULL before dereferencing it. When called from PKCS12_unpack_p7encdata() with a malformed PKCS#12 file, this parameter can be NULL, cau

PUBLISHED
Vendor
OpenSSL, Siemens
Product
OpenSSL, SIMATIC S7-1500 TM MFP - GNU/Linux subsystem
Provider severity
HIGH
Conflicts
1

CVE-2025-69420

Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing a malformed TimeStamp Response file. Impact summary: An application calling TS_RESP_verify_response() with a malformed TimeStamp Response can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service. The functions oss

PUBLISHED
Vendor
Siemens, OpenSSL
Product
SIMATIC S7-1500 TM MFP - GNU/Linux subsystem, OpenSSL
Provider severity
HIGH
Conflicts
1

CVE-2025-6942

The distributed engine versions 8.4.39.0 and earlier of Secret Server versions 11.7.49 and earlier can be exploited during an initial authorization event that would allow an attacker to impersonate another distributed engine.

PUBLISHED
Vendor
Delinea
Product
Secret Server
Provider severity
LOW
Conflicts
0

CVE-2025-69419

Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte write before the allocated buffer. Impact summary: The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service. The OPENSSL_uni2utf8() function performs a two-pass conversion of a PKCS#12 BMPString (UTF-16BE) to UTF-8. In the second pass, wh

PUBLISHED
Vendor
OpenSSL, Siemens
Product
OpenSSL, SIMATIC S7-1500 TM MFP - GNU/Linux subsystem
Provider severity
HIGH
Conflicts
1

CVE-2025-69418

Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs whose length is not a multiple<br>of 16 bytes can leave the final partial block unencrypted and unauthenticated.<br><br>Impact summary: The trailing 1-15 bytes of a message may be exposed in<br>cleartext on encryption and are not covered by the authentication tag,<br>allowing an attacker to read or tamper with those bytes without detection.<br><br>The low-level OCB encrypt and

PUBLISHED
Vendor
Siemens, OpenSSL
Product
SIMATIC S7-1500 TM MFP - GNU/Linux subsystem, OpenSSL
Provider severity
MEDIUM
Conflicts
1

CVE-2025-69417

In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve share tokens (intended for unrelated access) via a shared_servers endpoint.

PUBLISHED
Vendor
Plex
Product
plex.tv backend
Provider severity
MEDIUM
Conflicts
0

CVE-2025-69416

In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve other tokens (intended for unrelated access) via clients.plex.tv/devices.xml.

PUBLISHED
Vendor
Plex
Product
plex.tv backend
Provider severity
MEDIUM
Conflicts
0

CVE-2025-69415

In Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly aligned with whether the device is currently associated with an account.

PUBLISHED
Vendor
Plex
Product
Media Server
Provider severity
HIGH
Conflicts
0

CVE-2025-69414

Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call with a transient access token.

PUBLISHED
Vendor
Plex
Product
Media Server
Provider severity
HIGH
Conflicts
0

CVE-2025-69413

In Gitea before 1.25.2, /api/v1/user has different responses for failed authentication depending on whether a username exists.

PUBLISHED
Vendor
Gitea
Product
Gitea
Provider severity
MEDIUM
Conflicts
0

CVE-2025-69412

KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phishing API), which might allow spoofing of threat data. NOTE: this Lookup API is not contacted in the messagelib default configuration.

PUBLISHED
Vendor
KDE
Product
messagelib
Provider severity
LOW
Conflicts
0

CVE-2025-69411

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Robert Seyfriedsberger ionCube tester plus ioncube-tester-plus allows Path Traversal.This issue affects ionCube tester plus: from n/a through <= 1.3.

PUBLISHED
Vendor
Robert Seyfriedsberger
Product
ionCube tester plus
Provider severity
HIGH
Conflicts
0

CVE-2025-69410

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Belletrist belletrist allows PHP Local File Inclusion.This issue affects Belletrist: from n/a through <= 1.2.

PUBLISHED
Vendor
Edge-Themes
Product
Belletrist
Provider severity
HIGH
Conflicts
0

CVE-2025-6941

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the 'latepoint_resources' shortcode in all versions up to, and including, 5.1.94 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
latepoint
Product
LatePoint – Calendar Booking Plugin for Appointments and Events
Provider severity
MEDIUM
Conflicts
0

CVE-2025-69409

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes PJ | Life & Business Coaching pj allows PHP Local File Inclusion.This issue affects PJ | Life & Business Coaching: from n/a through <= 3.0.0.

PUBLISHED
Vendor
axiomthemes
Product
PJ | Life & Business Coaching
Provider severity
HIGH
Conflicts
0

CVE-2025-69408

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes HealthFirst healthfirst allows PHP Local File Inclusion.This issue affects HealthFirst: from n/a through <= 1.0.1.

PUBLISHED
Vendor
Mikado-Themes
Product
HealthFirst
Provider severity
HIGH
Conflicts
0

CVE-2025-69407

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Struktur struktur allows PHP Local File Inclusion.This issue affects Struktur: from n/a through <= 2.5.1.

PUBLISHED
Vendor
Select-Themes
Product
Struktur
Provider severity
HIGH
Conflicts
0

CVE-2025-69406

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX FreightCo freightco allows PHP Local File Inclusion.This issue affects FreightCo: from n/a through <= 1.1.7.

PUBLISHED
Vendor
ThemeREX
Product
FreightCo
Provider severity
HIGH
Conflicts
0

CVE-2025-69405

Deserialization of Untrusted Data vulnerability in ThemeREX Lorem Ipsum | Books & Media Store lorem-ipsum-books-media-store allows Object Injection.This issue affects Lorem Ipsum | Books & Media Store: from n/a through <= 1.2.11.

PUBLISHED
Vendor
ThemeREX
Product
Lorem Ipsum | Books & Media Store
Provider severity
CRITICAL
Conflicts
0

CVE-2025-69404

Deserialization of Untrusted Data vulnerability in ThemeREX Extreme Store extremestore allows Object Injection.This issue affects Extreme Store: from n/a through <= 1.5.10.

PUBLISHED
Vendor
ThemeREX
Product
Extreme Store
Provider severity
CRITICAL
Conflicts
0

CVE-2025-69403

Unrestricted Upload of File with Dangerous Type vulnerability in Bravis-Themes Bravis Addons bravis-addons allows Using Malicious Files.This issue affects Bravis Addons: from n/a through <= 1.3.0.

PUBLISHED
Vendor
Bravis-Themes
Product
Bravis Addons
Provider severity
CRITICAL
Conflicts
0

CVE-2025-69402

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX R&F rf allows PHP Local File Inclusion.This issue affects R&F: from n/a through <= 1.5.

PUBLISHED
Vendor
ThemeREX
Product
R&F
Provider severity
HIGH
Conflicts
0

CVE-2025-69401

Authentication Bypass by Spoofing vulnerability in mdalabar WooODT Lite byconsole-woo-order-delivery-time allows Identity Spoofing.This issue affects WooODT Lite: from n/a through <= 2.5.2.

PUBLISHED
Vendor
mdalabar
Product
WooODT Lite
Provider severity
HIGH
Conflicts
0

CVE-2025-69400

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Yokoo yokoo allows PHP Local File Inclusion.This issue affects Yokoo: from n/a through <= 1.1.11.

PUBLISHED
Vendor
ThemeREX
Product
Yokoo
Provider severity
HIGH
Conflicts
0

CVE-2025-6940

A vulnerability classified as critical was found in TOTOLINK A702R 4.0.0-B20230721.1521. Affected by this vulnerability is an unknown functionality of the file /boafrm/formParentControl of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
TOTOLINK
Product
A702R
Provider severity
HIGH
Conflicts
2

CVE-2025-69399

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Cobble cobble allows PHP Local File Inclusion.This issue affects Cobble: from n/a through <= 1.7.

PUBLISHED
Vendor
ThemeREX
Product
Cobble
Provider severity
HIGH
Conflicts
0

CVE-2025-69398

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Plank plank allows PHP Local File Inclusion.This issue affects Plank: from n/a through <= 1.7.

PUBLISHED
Vendor
ThemeREX
Product
Plank
Provider severity
HIGH
Conflicts
0

CVE-2025-69397

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Tint tint allows PHP Local File Inclusion.This issue affects Tint: from n/a through <= 1.7.

PUBLISHED
Vendor
ThemeREX
Product
Tint
Provider severity
HIGH
Conflicts
0

CVE-2025-69396

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Splendour splendour allows PHP Local File Inclusion.This issue affects Splendour: from n/a through <= 1.23.

PUBLISHED
Vendor
ThemeREX
Product
Splendour
Provider severity
HIGH
Conflicts
0

CVE-2025-69395

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Gable gable allows PHP Local File Inclusion.This issue affects Gable: from n/a through <= 1.5.

PUBLISHED
Vendor
ThemeREX
Product
Gable
Provider severity
HIGH
Conflicts
0

CVE-2025-69394

Authorization Bypass Through User-Controlled Key vulnerability in cnvrse Cnvrse cnvrse allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cnvrse: from n/a through < 026.02.10.20.

PUBLISHED
Vendor
cnvrse
Product
Cnvrse
Provider severity
HIGH
Conflicts
0

CVE-2025-69393

Missing Authorization vulnerability in Jthemes Exzo exzo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Exzo: from n/a through <= 1.2.4.

PUBLISHED
Vendor
Jthemes
Product
Exzo
Provider severity
HIGH
Conflicts
0

CVE-2025-69392

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in itex iMoney imoney allows Reflected XSS.This issue affects iMoney: from n/a through <= 0.36.

PUBLISHED
Vendor
itex
Product
iMoney
Provider severity
HIGH
Conflicts
0

CVE-2025-69391

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GT3themes Diamond diamond allows Reflected XSS.This issue affects Diamond: from n/a through <= 2.4.8.

PUBLISHED
Vendor
GT3themes
Product
Diamond
Provider severity
HIGH
Conflicts
0

CVE-2025-69390

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themebon Business Template Blocks for WPBakery (Visual Composer) Page Builder templates-and-addons-for-wpbakery-page-builder allows Reflected XSS.This issue affects Business Template Blocks for WPBakery (Visual Composer) Page Builder: from n/a through <= 1.3.2.

PUBLISHED
Vendor
themebon
Product
Business Template Blocks for WPBakery (Visual Composer) Page Builder
Provider severity
HIGH
Conflicts
0

CVE-2025-6939

A vulnerability classified as critical has been found in TOTOLINK A3002RU 3.0.0-B20230809.1615. Affected is an unknown function of the file /boafrm/formWlSiteSurvey of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
TOTOLINK
Product
A3002RU
Provider severity
HIGH
Conflicts
2

CVE-2025-69389

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hugh Mungus Visitor Maps Extended Referer Field visitor-maps-extended-referer-field allows Reflected XSS.This issue affects Visitor Maps Extended Referer Field: from n/a through <= 1.2.6.

PUBLISHED
Vendor
Hugh Mungus
Product
Visitor Maps Extended Referer Field
Provider severity
HIGH
Conflicts
0

CVE-2025-69388

Missing Authorization vulnerability in cliengo Cliengo – Chatbot cliengo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cliengo – Chatbot: from n/a through <= 3.0.4.

PUBLISHED
Vendor
cliengo
Product
Cliengo – Chatbot
Provider severity
MEDIUM
Conflicts
0

CVE-2025-69387

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in whatwouldjessedo Simple Retail Menus simple-retail-menus allows PHP Local File Inclusion.This issue affects Simple Retail Menus: from n/a through <= 4.2.1.

PUBLISHED
Vendor
whatwouldjessedo
Product
Simple Retail Menus
Provider severity
HIGH
Conflicts
0

CVE-2025-69386

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realvirtualmx RVCFDI para Woocommerce rvcfdi-para-woocommerce allows Reflected XSS.This issue affects RVCFDI para Woocommerce: from n/a through <= 8.1.8.

PUBLISHED
Vendor
realvirtualmx
Product
RVCFDI para Woocommerce
Provider severity
HIGH
Conflicts
0

CVE-2025-69385

Missing Authorization vulnerability in AgniHD Cartify - WooCommerce Gutenberg WordPress Theme cartify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cartify - WooCommerce Gutenberg WordPress Theme: from n/a through <= 1.3.

PUBLISHED
Vendor
AgniHD
Product
Cartify - WooCommerce Gutenberg WordPress Theme
Provider severity
MEDIUM
Conflicts
0

CVE-2025-69384

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdiscover Timeline Event History timeline-event-history allows Reflected XSS.This issue affects Timeline Event History: from n/a through <= 3.2.

PUBLISHED
Vendor
wpdiscover
Product
Timeline Event History
Provider severity
HIGH
Conflicts
0

CVE-2025-69383

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Agence web Eoxia - Montpellier WP shop wpshop allows PHP Local File Inclusion.This issue affects WP shop: from n/a through <= 2.6.1.

PUBLISHED
Vendor
Agence web Eoxia - Montpellier
Product
WP shop
Provider severity
HIGH
Conflicts
0

CVE-2025-69382

Deserialization of Untrusted Data vulnerability in themesflat Themesflat Elementor themesflat-elementor allows Object Injection.This issue affects Themesflat Elementor: from n/a through <= 1.0.1.

PUBLISHED
Vendor
themesflat
Product
Themesflat Elementor
Provider severity
CRITICAL
Conflicts
0

CVE-2025-69381

Missing Authorization vulnerability in vanquish WooCommerce Bulk Product Editor woocommerce-quick-product-editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Bulk Product Editor: from n/a through <= 3.0.

PUBLISHED
Vendor
vanquish
Product
WooCommerce Bulk Product Editor
Provider severity
HIGH
Conflicts
0

CVE-2025-69380

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish Upload Files Anywhere wp-upload-files-anywhere allows Path Traversal.This issue affects Upload Files Anywhere: from n/a through <= 2.8.

PUBLISHED
Vendor
vanquish
Product
Upload Files Anywhere
Provider severity
HIGH
Conflicts
0

CVE-2025-6938

A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /editcus.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Simple Pizza Ordering System
Provider severity
HIGH, MEDIUM
Conflicts
2