Critical vulnerabilities, curated daily for security professionals
π― SSCV Profile
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Risk scores will be adjusted based on your selected environment
π
Archived Security Brief
Thursday's vulnerability disclosure reflects elevated critical activity with 28 critical CVEs and 64 high-priority vulnerabilities, representing a 300% increase in critical vulnerabilities compared to Wednesday. Six CISA KEV vulnerabilities require remediation across multiple systems. The increase in critical CVEs (from 7 to 28) indicates heightened disclosure activity, while high-priority CVEs remained stable at 64.
Twenty-eight critical vulnerabilities disclosed (CVSS 9.0+), a 300% increase from Wednesday's count of 7 critical CVEs
Sixty-four high-priority vulnerabilities (CVSS 7.0-8.9), unchanged from Wednesday's count
Six CISA KEV vulnerabilities requiring remediation, up from 5 on Wednesday
Critical CVE frequency increased 138% compared to historical average, reflecting elevated disclosure activity
Immediate action: Security teams should review the 28 critical vulnerabilities and assess organizational exposure to the 64 high-priority CVEs. Organizations should continue addressing the 6 CISA KEV vulnerabilities. Detailed analyst comments are available for select CVEs to support remediation planning.
π‘ Tip: Swipe CVE cards left to β star, right to β remove
Section Navigation
β οΈ
CISA Known Exploited Vulnerabilities
π¨
Critical Vulnerabilities
CVE-2025-13390
10
The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions upMultiple Products
The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.4.4 due to incorrect implementation of the authentication algorithm in the "wdk_generate_auto_login_link" function. This is due to the feature using a cryptographically weak token generation mechanism. This makes it possible for unauthenticated attackers to gain administrative access and achieve full site takeover via the auto-login endpoint with a predictable token.
CVSS Base10
β
CRSSelect profile
CVE-2025-55182
10
AMultiple Products
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.
CVSS Base10
β
CRSSelect profile
CVE-2025-41742
9.8
Sprecher AutomationsMultiple Products
Sprecher Automations SPRECON-E-C, Β SPRECON-E-P, SPRECON-E-T3Β is vulnerable to attack by an unauthorized remote attacker via default cryptographic keys. The use of these keys allows the attacker to read, modify, and write projects and data, or to access any device via remote maintenance.
CVSS Base9.8
β
CRSSelect profile
CVE-2025-11778
9.8
UnknownMultiple Products
Stack-based buffer overflow in Circutor SGE-PLC1000/SGE-PLC50 v0.9.2. This vulnerability allows an attacker to remotely exploit memory corruption through the 'read_packet()' function of the TACACSPLUS implementation.
CVSS Base9.8
β
CRSSelect profile
CVE-2025-11779
9.8
UnknownMultiple Products
Stack-based buffer overflow vulnerability in CircutorSGE-PLC1000/SGE-PLC50 v9.0.2. The 'SetLan' function is invoked when a new configuration is applied. This new configuration function is activated by a management web request, which can be invoked by a user when making changes to the 'index.cgi' web application. The parameters are not being sanitised, which could lead to command injection.
CVSS Base9.8
β
CRSSelect profile
CVE-2025-11780
9.8
UnknownMultiple Products
Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'showMeterReport()' function, there is an unlimited user input that is copied to a fixed-size buffer via 'sprintf()'. The 'GetParameter(meter)' function retrieves the user input, which is directly incorporated into a buffer without size validation. An attacker can provide an excessively large input for the βmeterβ parameter.
CVSS Base9.8
β
CRSSelect profile
CVE-2025-11782
9.8
UnknownMultiple Products
Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'ShowDownload()' function uses βsprintf()β to format a string that includes the user-controlled input of 'GetParameter(meter)' in the fixed-size buffer 'acStack_4c' (64 bytes) without checking the length. An attacker can provide an excessively long value for the 'meter' parameter that exceeds the 64-byte buffer size.
CVSS Base9.8
β
CRSSelect profile
CVE-2025-11783
9.8
UnknownMultiple Products
Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The vulnerability is found in the 'AddEvent()' function when copying the user-controlled username input to a fixed-size buffer (48 bytes) without boundary checking. This can lead to memory corruption, resulting in possible remote code execution.
CVSS Base9.8
β
CRSSelect profile
CVE-2025-11784
9.8
UnknownMultiple Products
Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterDatabase()' function, there is an unlimited user input that is copied to a fixed-size buffer via 'sprintf()'. The 'GetParameter(meter)' function retrieves the user input, which is directly incorporated into a buffer without size validation. An attacker can provide an excessively large input for the 'meter' parameter.
CVSS Base9.8
β
CRSSelect profile
CVE-2025-11785
9.8
UnknownMultiple Products
Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterPasswords()' function, there is an unlimited user input that is copied to a fixed-size buffer via 'sprintf()'. The 'GetParameter(meter)' function retrieves the user input, which is directly incorporated into a buffer without size validation. An attacker can provide an excessively large input for the 'meter' parameter.
CVSS Base9.8
β
CRSSelect profile
CVE-2025-11786
9.8
UnknownMultiple Products
Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'SetUserPassword()' function, the 'newPassword' parameter is directly embedded in a shell command string using 'sprintf()' without any sanitisation or validation, and then executed using 'system()'. This allows an attacker to inject arbitrary shell commands that will be executed with the same privileges as the application.
CVSS Base9.8
β
CRSSelect profile
CVE-2025-11788
9.8
UnknownMultiple Products
Heap-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowSupervisorParameters()' function, there is an unlimited user input that is copied to a fixed-size buffer via 'sprintf()'. The 'GetParameter(meter)' function retrieves the user input, which is directly incorporated into a buffer without size validation. An attacker can provide an excessively large input for the 'meter' parameter.
CVSS Base9.8
β
CRSSelect profile
CVE-2025-41013
9.8
SQL injection vulnerability in TCMAN GIMMultiple Products
SQL injection vulnerability in TCMAN GIM v11 in version 20250304. This vulnerability allows an attacker to retrieve, create, update, and delete databases by sending a GET request using the 'idmant' parameter in '/PC/frmEPIS.aspx'.
CVSS Base9.8
β
CRSSelect profile
CVE-2025-59693
9.8
The Chassis Management Board in Entrust nShield ConnectMultiple Products
The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allows a physically proximate attacker to obtain debug access and escalate privileges by bypassing the tamper label and opening the chassis without leaving evidence, and accessing the JTAG connector. This is called F02.
CVSS Base9.8
β
CRSSelect profile
CVE-2025-65358
9.8
UnknownMultiple Products
Edoc-doctor-appointment-system v1.0.1 was discovered to contain SQl injection vulnerability via the 'docid' parameter at /admin/appointment.php.
CVSS Base9.8
β
CRSSelect profile
CVE-2025-65656
9.8
UnknownMultiple Products
dcat-admin v2.2.3-beta and before is vulnerable to file inclusion in admin/src/Extend/VersionManager.php.
CVSS Base9.8
β
CRSSelect profile
CVE-2025-58386
9.8
In TerminalfourMultiple Products
In Terminalfour 8 through 8.4.1.1, the userLevel parameter in the user management function is not subject to proper server-side authorization checks. A Power User can intercept and modify this parameter to assign the Administrator role to other existing lower-privileged accounts, or invite a new lower-privileged account and escalate its privileges. While manipulating this request, the Power User can also change the target account's password, effectively taking full control of it.
CVSS Base9.8
β
CRSSelect profile
CVE-2025-60854
9.8
A vulnerability has been found inMultiple Products
A vulnerability has been found in D-Link R15 (AX1500) 1.20.01 and below. By manipulating the model name parameter during a password change request in the web administrator page, it is possible to trigger a command injection in httpd.
CVSS Base9.8
β
CRSSelect profile
CVE-2025-60736
9.8
UnknownMultiple Products
code-projects Online Medicine Guide 1.0 is vulnerable to SQL Injection in /login.php via the upass parameter.
CVSS Base9.8
β
CRSSelect profile
CVE-2025-65896
9.8
SQL injection vulnerability inMultiple Products
SQL injection vulnerability in long2ice assyncmy thru 0.2.10 allows attackers to execute arbitrary SQL commands via crafted dict keys.
CVSS Base9.8
β
CRSSelect profile
CVE-2025-13542
9.8
The DesignThemes LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions upMultiple Products
The DesignThemes LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.4. This is due to the 'dtlms_register_user_front_end' function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the 'administrator' role during registration and gain administrator access to the site.
CVSS Base9.8
β
CRSSelect profile
CVE-2025-13486
9.8
The Advanced CustomMultiple Products
The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_form() function. This is due to the function accepting user input and then passing that through call_user_func_array(). This makes it possible for unauthenticated attackers to execute arbitrary code on the server, which can be leveraged to inject backdoors or create new administrative user accounts.
CVSS Base9.8
β
CRSSelect profile
CVE-2025-13342
9.8
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in all versions upMultiple Products
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in all versions up to, and including, 3.28.20. This is due to insufficient capability checks and input validation in the ActionOptions::run() save handler. This makes it possible for unauthenticated attackers to modify critical WordPress options such as users_can_register, default_role, and admin_email via submitting crafted form data to public frontend forms.
CVSS Base9.8
β
CRSSelect profile
CVE-2024-32641
9.8
Masa CMS is an open source Enterprise Content ManagementMultiple Products
Masa CMS is an open source Enterprise Content Management platform. Masa CMS versions prior to 7.2.8, 7.3.13, and 7.4.6 are vulnerable to remote code execution. The vulnerability exists in the addParam function, which accepts user input via the criteria parameter. This input is subsequently evaluated by setDynamicContent, allowing an unauthenticated attacker to execute arbitrary code via the m tag. The vulnerability is patched in versions 7.2.8, 7.3.13, and 7.4.6.
CVSS Base9.8
β
CRSSelect profile
CVE-2025-66222
9.6
DeepChat is a smart assistant uses artificialMultiple Products
DeepChat is a smart assistant uses artificial intelligence. In 0.5.0 and earlier, there is a Stored Cross-Site Scripting (XSS) vulnerability in the Mermaid diagram renderer allows an attacker to execute arbitrary JavaScript within the application context. By leveraging the exposed Electron IPC bridge, this XSS can be escalated to Remote Code Execution (RCE) by registering and starting a malicious MCP (Model Context Protocol) server.
CVSS Base9.6
β
CRSSelect profile
CVE-2025-41744
9.1
Sprecher AutomationsMultiple Products
Sprecher Automations SPRECON-E seriesΒ uses default cryptographic keys that allow an unprivileged remote attacker to access all encrypted communications, thereby compromising confidentiality and integrity.
CVSS Base9.1
β
CRSSelect profile
CVE-2025-59703
9.1
Entrust nShield ConnectMultiple Products
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a Physically Proximate Attacker to access the internal components of the appliance, without leaving tamper evidence. To exploit this, the attacker needs to remove the tamper label and all fixing screws from the device without damaging it. This is called an F14 attack.
CVSS Base9.1
β
CRSSelect profile
CVE-2025-65267
9
In ERPNextMultiple Products
In ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images allows attackers to embed malicious JavaScript. The payload executes when an administrator clicks the image link to view the avatar, resulting in stored cross-site scripting (XSS). Successful exploitation may lead to account takeover, privilege escalation, or full compromise of the affected ERPNext instance.
CVSS Base9
β
CRSSelect profile
β οΈ
High Priority Updates
CVE-2025-12529
8.8
The Cost Calculator Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in theMultiple Products
The Cost Calculator Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the deleteOrdersFiles() function in all versions up to, and including, 3
CVSS Base8.8
β
CRSSelect profile
CVE-2025-11787
8.8
Command injection vulnerability in the operating system in CircutorMultiple Products
Command injection vulnerability in the operating system in Circutor SGE-PLC1000/SGE-PLC50 v9
CVSS Base8.8
β
CRSSelect profile
CVE-2025-13630
8.8
Type Confusion inMultiple Products
Type Confusion in V8 in Google Chrome prior to 143
CVSS Base8.8
β
CRSSelect profile
CVE-2025-13631
8.8
Inappropriate implementation in Google Updater in Google Chrome on Mac prior toMultiple Products
Inappropriate implementation in Google Updater in Google Chrome on Mac prior to 143
CVSS Base8.8
β
CRSSelect profile
CVE-2025-13633
8.8
Use after free in Digital Credentials in Google Chrome prior toMultiple Products
Use after free in Digital Credentials in Google Chrome prior to 143
CVSS Base8.8
β
CRSSelect profile
CVE-2025-13638
8.8
Use after free in Media Stream in Google Chrome prior toMultiple Products
Use after free in Media Stream in Google Chrome prior to 143
CVSS Base8.8
β
CRSSelect profile
CVE-2025-13720
8.8
Bad cast in Loader in Google Chrome prior toMultiple Products
Bad cast in Loader in Google Chrome prior to 143
CVSS Base8.8
β
CRSSelect profile
CVE-2025-12744
8.8
A flaw was found in the ABRTMultiple Products
A flaw was found in the ABRT daemonβs handling of user-supplied mount information
CVSS Base8.8
β
CRSSelect profile
CVE-2025-57198
8.8
AVTECH SECURITY CorporationMultiple Products
AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the Machine
CVSS Base8.8
β
CRSSelect profile
CVE-2025-57199
8.8
AVTECH SECURITY CorporationMultiple Products
AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the NetFailDetectD binary
CVSS Base8.8
β
CRSSelect profile
CVE-2025-57201
8.8
AVTECH SECURITY CorporationMultiple Products
AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the SMB server function
CVSS Base8.8
β
CRSSelect profile
CVE-2024-32642
8.8
Masa CMS is an open source Enterprise Content ManagementMultiple Products
Masa CMS is an open source Enterprise Content Management platform
CVSS Base8.8
β
CRSSelect profile
CVE-2025-33208
8.8
NVIDIA TAO contains a vulnerability where an attacker may cause a resource to be loaded via an uncontrolled searchMultiple Products
NVIDIA TAO contains a vulnerability where an attacker may cause a resource to be loaded via an uncontrolled search path
CVSS Base8.8
β
CRSSelect profile
CVE-2024-45675
8.4
IBM Informix Dynamic ServerMultiple Products
IBM Informix Dynamic Server 14
CVSS Base8.4
β
CRSSelect profile
CVE-2025-64298
8.4
UnknownMultiple Products
NMIS/BioDose V22
CVSS Base8.4
β
CRSSelect profile
CVE-2025-50360
8.4
A heap buffer overflow inMultiple Products
A heap buffer overflow in compiler
CVSS Base8.4
β
CRSSelect profile
CVE-2025-61940
8.3
UnknownMultiple Products
NMIS/BioDose V22
CVSS Base8.3
β
CRSSelect profile
CVE-2025-62575
8.3
UnknownMultiple Products
NMIS/BioDose V22
CVSS Base8.3
β
CRSSelect profile
CVE-2025-13516
8.1
The SureMailMultiple Products
The SureMail β SMTP and Email Logs Plugin for WordPress is vulnerable to Unrestricted Upload of File with Dangerous Type in versions up to and including 1
CVSS Base8.1
β
CRSSelect profile
CVE-2025-64642
8
UnknownMultiple Products
NMIS/BioDose V22
CVSS Base8
β
CRSSelect profile
CVE-2025-20386
8
In Splunk Enterprise for Windows versions belowMultiple Products
In Splunk Enterprise for Windows versions below 10
CVSS Base8
β
CRSSelect profile
CVE-2025-20387
8
In Splunk Universal Forwarder for Windows versions belowMultiple Products
In Splunk Universal Forwarder for Windows versions below 10
CVSS Base8
β
CRSSelect profile
CVE-2025-54065
7.9
GZDoom is a feature centric port for all Doom engineMultiple Products
GZDoom is a feature centric port for all Doom engine games
CVSS Base7.9
β
CRSSelect profile
CVE-2025-20763
7.8
InMultiple Products
In mmdvfs, there is a possible out of bounds write due to a missing bounds check
CVSS Base7.8
β
CRSSelect profile
CVE-2025-20764
7.8
InMultiple Products
In smi, there is a possible out of bounds write due to a missing bounds check
CVSS Base7.8
β
CRSSelect profile
CVE-2025-20766
7.8
InMultiple Products
In display, there is a possible memory corruption due to improper input validation
CVSS Base7.8
β
CRSSelect profile
CVE-2025-20767
7.8
InMultiple Products
In display, there is a possible out of bounds write due to an integer overflow
CVSS Base7.8
β
CRSSelect profile
CVE-2025-20768
7.8
InMultiple Products
In display, there is a possible out of bounds read due to a missing bounds check
CVSS Base7.8
β
CRSSelect profile
CVE-2025-11781
7.8
Use of hardcoded cryptographic keys in CircutorMultiple Products
Use of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50 v9
Coder allows organizations to provision remote development environments viaMultiple Products
Coder allows organizations to provision remote development environments via Terraform
CVSS Base7.8
β
CRSSelect profile
CVE-2025-13000
7.7
TheMultiple Products
The db-access WordPress plugin through 0
CVSS Base7.7
β
CRSSelect profile
CVE-2025-7044
7.7
An Improper Input Validation vulnerability exists in the user websocket handler ofMultiple Products
An Improper Input Validation vulnerability exists in the user websocket handler of MAAS
CVSS Base7.7
β
CRSSelect profile
CVE-2025-65843
7.7
Aquarius DesktopMultiple Products
Aquarius Desktop 3
CVSS Base7.7
β
CRSSelect profile
CVE-2025-66468
7.6
The Aimeos GrapesJS CMS extension provides page editor for creating content pages based on extensibleMultiple Products
The Aimeos GrapesJS CMS extension provides page editor for creating content pages based on extensible components
CVSS Base7.6
β
CRSSelect profile
CVE-2025-65027
7.6
RomMMultiple Products
RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface
CVSS Base7.6
β
CRSSelect profile
CVE-2025-13724
7.5
The VikRentCar Car Rental Management System plugin for WordPress is vulnerable toMultiple Products
The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'month' parameter in all versions up to, and including, 1
CVSS Base7.5
β
CRSSelect profile
CVE-2025-11789
7.5
UnknownMultiple Products
Out-of-bounds read vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9
CVSS Base7.5
β
CRSSelect profile
CVE-2025-13295
7.5
Insertion of Sensitive Information Into Sent Data vulnerability in Argus TechnologyMultiple Products
Insertion of Sensitive Information Into Sent Data vulnerability in Argus Technology Inc
CVSS Base7.5
β
CRSSelect profile
CVE-2025-41014
7.5
User Enumeration Vulnerability in TCMAN GIMMultiple Products
User Enumeration Vulnerability in TCMAN GIM v11 version 20250304
CVSS Base7.5
β
CRSSelect profile
CVE-2025-41015
7.5
User Enumeration Vulnerability in TCMAN GIMMultiple Products
User Enumeration Vulnerability in TCMAN GIM v11 version 20250304
CVSS Base7.5
β
CRSSelect profile
CVE-2025-64460
7.5
An issue was discovered inMultiple Products
An issue was discovered in 5
CVSS Base7.5
β
CRSSelect profile
CVE-2025-65844
7.5
EverShopMultiple Products
EverShop 2
CVSS Base7.5
β
CRSSelect profile
CVE-2025-13721
7.5
Race inMultiple Products
Race in v8 in Google Chrome prior to 143
CVSS Base7.5
β
CRSSelect profile
CVE-2025-61729
7.5
WithinMultiple Products
Within HostnameError
CVSS Base7.5
β
CRSSelect profile
CVE-2025-13646
7.5
The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in theMultiple Products
The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ajax_unzip_file' function in versions 2
CVSS Base7.5
β
CRSSelect profile
CVE-2025-65320
7.5
Abacre Restaurant Point of SaleMultiple Products
Abacre Restaurant Point of Sale (POS) up to 15
CVSS Base7.5
β
CRSSelect profile
CVE-2024-32643
7.5
Masa CMS is an open source Enterprise Content ManagementMultiple Products
Masa CMS is an open source Enterprise Content Management platform
CVSS Base7.5
β
CRSSelect profile
CVE-2025-54326
7.5
An issue was discovered in Camera in Samsung Mobile Processor ExynosMultiple Products
An issue was discovered in Camera in Samsung Mobile Processor Exynos 1280 and 2200
CVSS Base7.5
β
CRSSelect profile
CVE-2024-3884
7.5
A flaw was found in Undertow that can cause remote denial of serviceMultiple Products
A flaw was found in Undertow that can cause remote denial of service attacks
CVSS Base7.5
β
CRSSelect profile
CVE-2025-12819
7.5
Untrusted search path inMultiple Products
Untrusted search path in auth_query connection handler in PgBouncer before 1
CVSS Base7.5
β
CRSSelect profile
CVE-2025-33201
7.5
NVIDIA Triton Inference Server contains a vulnerability where an attacker may cause an improper check for unusual or exceptional conditions issue by sending extra largeMultiple Products
NVIDIA Triton Inference Server contains a vulnerability where an attacker may cause an improper check for unusual or exceptional conditions issue by sending extra large payloads
CVSS Base7.5
β
CRSSelect profile
CVE-2025-33211
7.5
NVIDIA Triton Server for Linux contains a vulnerability where an attacker may cause an improper validation of specified quantity inMultiple Products
NVIDIA Triton Server for Linux contains a vulnerability where an attacker may cause an improper validation of specified quantity in input
CVSS Base7.5
β
CRSSelect profile
CVE-2025-13947
7.4
A flaw was found inMultiple Products
A flaw was found in WebKitGTK
CVSS Base7.4
β
CRSSelect profile
CVE-2025-58481
7.3
Improper access control in MPRemoteService of MotionPhoto prior to versionMultiple Products
Improper access control in MPRemoteService of MotionPhoto prior to version 4
CVSS Base7.3
β
CRSSelect profile
CVE-2025-58482
7.3
Improper access control in MPLocalService of MotionPhoto prior to versionMultiple Products
Improper access control in MPLocalService of MotionPhoto prior to version 4
CVSS Base7.3
β
CRSSelect profile
CVE-2025-64778
7.3
UnknownMultiple Products
NMIS/BioDose software V22
CVSS Base7.3
β
CRSSelect profile
CVE-2025-13387
7.2
The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to StoredMultiple Products
The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer name in all versions up to, and including, 1
CVSS Base7.2
β
CRSSelect profile
CVE-2025-59697
7.2
Entrust nShield ConnectMultiple Products
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13
CVSS Base7.2
β
CRSSelect profile
CVE-2025-59702
7.2
Entrust nShield ConnectMultiple Products
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13
CVSS Base7.2
β
CRSSelect profile
CVE-2025-13645
7.2
The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in theMultiple Products
The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'ajax_unzip_file' function in versions 2
CVSS Base7.2
β
CRSSelect profile
CVE-2025-66293
7.1
LIBPNG is a reference library for use in applications thatMultiple Products
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files