CVE List - 2025 / May
Showing 901 - 1000 of 3984 CVEs for May 2025 (Page 10 of 40)
CVE ID | Date | Title |
---|---|---|
CVE-2025-4335 | 2025-05-07 | Woocommerce Multiple Addresses <= 1.0.7.1 - Authenticated (Subscriber+) Privilege Escalation |
CVE-2025-3852 | 2025-05-07 | WPshop 2 – E-Commerce 2.0.0 - 2.6.0 - Authenticated (Subscriber+) Privilege Escalation via Account Takeover |
CVE-2025-3921 | 2025-05-07 | PeproDev Ultimate Profile Solutions 1.9.1 - 7.5.2 - Missing Authorization to Limited Unauthenticated Arbitrary User Meta Update via handel_ajax_req Function |
CVE-2025-4055 | 2025-05-07 | Multiple Post Type Order <= 1.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via mpto Shortcode |
CVE-2025-3860 | 2025-05-07 | CarDealerPress <= 6.7.2504.00 - Authenticated (Contributor+) Stored Cross-Site Scripting via saleclass Parameter |
CVE-2025-4220 | 2025-05-07 | Xavin's List Subpages <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting |
CVE-2025-4054 | 2025-05-07 | Relevanssi <= 4.24.3 - Unauthenticated Stored Cross-Site Scripting via Search Highlights |
CVE-2025-3766 | 2025-05-07 | Login Lockdown & Protection <= 2.11 - Missing Authorization to Authenticated (Subscriber+) Arbitrary IP Whitelisting |
CVE-2025-1399 | 2025-05-07 | Out-of-bounds Read in libplctag library |
CVE-2025-1400 | 2025-05-07 | Out-of-bounds Read in libplctag library |
CVE-2025-32396 | 2025-05-07 | An Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or... |
CVE-2025-32397 | 2025-05-07 | An Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or... |
CVE-2025-32398 | 2025-05-07 | A NULL Pointer Dereference in RT-Labs P-Net version 1.0.1 or... |
CVE-2025-32399 | 2025-05-07 | An Unchecked Input for Loop Condition in RT-Labs P-Net version... |
CVE-2025-32400 | 2025-05-07 | An Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or... |
CVE-2025-32401 | 2025-05-07 | An Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or... |
CVE-2025-32402 | 2025-05-07 | An Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or earlier... |
CVE-2025-32403 | 2025-05-07 | An Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or earlier... |
CVE-2025-32404 | 2025-05-07 | An Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or earlier... |
CVE-2025-32405 | 2025-05-07 | An Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or earlier... |
CVE-2025-4171 | 2025-05-07 | WZ Followed Posts – Display what visitors are reading <= 3.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting |
CVE-2024-12120 | 2025-05-07 | Royal Elementor Addons and Templates <= 1.7.1017 - Authenticated (Contributor+) Stored Cross-Site Scripting |
CVE-2025-0666 | 2025-05-07 | BOINC Server Stored XSS Injection in host_venue_action.php |
CVE-2025-0667 | 2025-05-07 | BOINC Server Stored XSS Injection in pm.php |
CVE-2025-0668 | 2025-05-07 | BOINC Server Multiple SQL Injections |
CVE-2025-0669 | 2025-05-07 | BOINC Server Cross-Site Request Forgery |
CVE-2025-20937 | 2025-05-07 | Out-of-bounds write in Keymaster trustlet prior to SMR May-2025 Release... |
CVE-2025-20949 | 2025-05-07 | Path traversal vulnerability in Samsung Members prior to version 5.0.00.11... |
CVE-2025-20953 | 2025-05-07 | Improper access control in SmartManagerCN prior to SMR May-2025 Release... |
CVE-2025-20954 | 2025-05-07 | Use of implicit intent for sensitive communication in EnrichedCall prior... |
CVE-2025-20955 | 2025-05-07 | Improper Export of Android Application Components in NotificationHistoryImageProvider prior to... |
CVE-2025-20956 | 2025-05-07 | Improper export of android application components in Settings in Galaxy... |
CVE-2025-20957 | 2025-05-07 | Improper access control in SmartManagerCN prior to SMR May-2025 Release... |
CVE-2025-20958 | 2025-05-07 | Improper verification of intent by broadcast receiver in UnifiedWFC prior... |
CVE-2025-20959 | 2025-05-07 | Use of implicit intent for sensitive communication in Wi-Fi P2P... |
CVE-2025-20960 | 2025-05-07 | Improper handling of insufficient permission in CocktailBarService prior to SMR... |
CVE-2025-20961 | 2025-05-07 | Improper handling of insufficient permission or privileges in sepunion service... |
CVE-2025-20962 | 2025-05-07 | Improper handling of insufficient permission in SpenGesture service prior to... |
CVE-2025-20963 | 2025-05-07 | Out-of-bounds write in memory initialization in libsavsvc.so prior to SMR... |
CVE-2025-20964 | 2025-05-07 | Out-of-bounds write in parsing media files in libsavsvc.so prior to... |
CVE-2025-20965 | 2025-05-07 | Improper handling of insufficient permission in Bixby wakeup prior to... |
CVE-2025-20966 | 2025-05-07 | Improper access control in Samsung Gallery prior to version 14.5.10.3... |
CVE-2025-20967 | 2025-05-07 | Improper access control in Samsung Gallery prior to version 14.5.10.3... |
CVE-2025-20968 | 2025-05-07 | Improper access control in Samsung Gallery prior to version 14.5.10.3... |
CVE-2025-20969 | 2025-05-07 | Improper input validation in Samsung Gallery prior to version 14.5.10.3... |
CVE-2025-20970 | 2025-05-07 | Improper access control in Bixby Vision prior to version 3.8.1... |
CVE-2025-20971 | 2025-05-07 | Improper input validation in Samsung Flow prior to version 4.9.17.6... |
CVE-2025-20972 | 2025-05-07 | Improper verification of intent by broadcast receiver in Samsung Flow... |
CVE-2025-20973 | 2025-05-07 | Improper authentication in Secure Folder prior to version 1.8.12.0 in... |
CVE-2025-20974 | 2025-05-07 | Improper handling of insufficient permission in PackageInstallerCN prior to version... |
CVE-2025-20975 | 2025-05-07 | Improper Export of Android Application Components in AODService prior to... |
CVE-2025-20976 | 2025-05-07 | Out-of-bounds read in applying binary of text content in Samsung... |
CVE-2025-20977 | 2025-05-07 | Use of implicit intent for sensitive communication in translation in... |
CVE-2025-20978 | 2025-05-07 | Improper access control in PENUP prior to version 3.9.19.32 allows... |
CVE-2025-20979 | 2025-05-07 | Out-of-bounds write in libsavscmn prior to Android 15 allows local... |
CVE-2025-20980 | 2025-05-07 | Out-of-bounds write in libsavscmn prior to Android 15 allows local... |
CVE-2025-27533 | 2025-05-07 | Apache ActiveMQ: Unchecked buffer length can cause excessive memory allocation |
CVE-2025-39361 | 2025-05-07 | WordPress Royal Elementor Addons plugin <= 1.7.1017 - Cross Site Scripting (XSS) vulnerability |
CVE-2025-4104 | 2025-05-07 | Frontend Dashboard 1.0 - 2.2.6 - Missing Authorization to Unauthenticated Privilege Escalation via fed_wp_ajax_fed_login_form_post Function |
CVE-2025-33093 | 2025-05-07 | IBM Sterling Partner Engagement Manager information disclosure |
CVE-2020-36791 | 2025-05-07 | net_sched: keep alloc_hash updated after hash allocation |
CVE-2025-47439 | 2025-05-07 | WordPress Download Monitor <= 5.0.22 - Local File Inclusion Vulnerability |
CVE-2025-47440 | 2025-05-07 | WordPress WPAdverts <= 2.2.2 - Local File Inclusion Vulnerability |
CVE-2025-47441 | 2025-05-07 | WordPress Progress Bar <= 2.2.3 - Cross Site Scripting (XSS) Vulnerability |
CVE-2025-47442 | 2025-05-07 | WordPress CC BMI Calculator <= 2.1.0 - Cross Site Scripting (XSS) Vulnerability |
CVE-2025-47443 | 2025-05-07 | WordPress Widget Countdown <= 2.7.4 - Cross Site Scripting (XSS) Vulnerability |
CVE-2025-47446 | 2025-05-07 | WordPress Listamester <= 2.3.6 - Cross Site Request Forgery (CSRF) Vulnerability |
CVE-2025-47447 | 2025-05-07 | WordPress Cool Author Box <= 3.0.0 - Cross Site Request Forgery (CSRF) Vulnerability |
CVE-2025-47448 | 2025-05-07 | WordPress WP Hotel Booking <= 2.1.9 - Cross Site Request Forgery (CSRF) Vulnerability |
CVE-2025-47449 | 2025-05-07 | WordPress Meow Gallery <= 5.2.7 - Cross Site Scripting (XSS) Vulnerability |
CVE-2025-47450 | 2025-05-07 | WordPress Simple File List <= 6.1.13 - Settings Change Vulnerability |
CVE-2025-47451 | 2025-05-07 | WordPress Product Quantity Dropdown For Woocommerce plugin <= 1.2 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability |
CVE-2025-47454 | 2025-05-07 | WordPress WP Gravity Forms Dynamics CRM <= 1.1.4 - Open Redirection Vulnerability |
CVE-2025-47455 | 2025-05-07 | WordPress Integration for WooCommerce and Salesforce <= 1.7.5 - Open Redirection Vulnerability |
CVE-2025-47456 | 2025-05-07 | WordPress WP Gravity Forms Zendesk <= 1.1.2 - Open Redirection Vulnerability |
CVE-2025-47457 | 2025-05-07 | WordPress LocateAndFilter <= 1.6.16 - Broken Access Control Vulnerability |
CVE-2025-47459 | 2025-05-07 | WordPress WP Fundraising Donation and Crowdfunding Platform <= 1.7.3 - Cross Site Request Forgery (CSRF) Vulnerability |
CVE-2025-47460 | 2025-05-07 | WordPress TrackShip for WooCommerce <= 1.9.1 - SQL Injection Vulnerability |
CVE-2025-47462 | 2025-05-07 | WordPress Challan plugin <= 3.7.58 - CSRF to Privilege Escalation vulnerability |
CVE-2025-47464 | 2025-05-07 | WordPress Solace Extra <= 1.3.1 - Server Side Request Forgery (SSRF) Vulnerability |
CVE-2025-47465 | 2025-05-07 | WordPress Blocksy <= 2.0.97 - Broken Access Control Vulnerability |
CVE-2025-47466 | 2025-05-07 | WordPress Ultimate WP Mail <= 1.3.4 - Cross Site Request Forgery (CSRF) Vulnerability |
CVE-2025-47467 | 2025-05-07 | WordPress GS Testimonial Slider <= 3.3.0 - Broken Access Control Vulnerability |
CVE-2025-47468 | 2025-05-07 | WordPress Hash Form <= 1.2.8 - Cross Site Request Forgery (CSRF) Vulnerability |
CVE-2025-47469 | 2025-05-07 | WordPress Media Hygiene <= 4.0.0 - Broken Access Control Vulnerability |
CVE-2025-47470 | 2025-05-07 | WordPress GPT3 AI Content Writer plugin <= 1.9.14 - Cross Site Request Forgery (CSRF) to Prompt Generation vulnerability |
CVE-2025-47471 | 2025-05-07 | WordPress Envo Extra <= 1.9.9 - Broken Access Control Vulnerability |
CVE-2025-47472 | 2025-05-07 | WordPress Music Player for WooCommerce <= 1.5.1 - Broken Access Control Vulnerability |
CVE-2025-47473 | 2025-05-07 | WordPress PW WooCommerce Bulk Edit <= 2.134 - Cross Site Request Forgery (CSRF) Vulnerability |
CVE-2025-47475 | 2025-05-07 | WordPress JupiterX Core <= 4.8.11 - Cross Site Scripting (XSS) Vulnerability |
CVE-2025-47476 | 2025-05-07 | WordPress Cost Calculator for Elementor <= 1.3.3 - Cross Site Scripting (XSS) Vulnerability |
CVE-2025-47480 | 2025-05-07 | WordPress Graphina <= 3.0.4 - Broken Access Control Vulnerability |
CVE-2025-47481 | 2025-05-07 | WordPress GS Testimonial Slider plugin <= 3.2.9 - Content Injection vulnerability |
CVE-2025-47482 | 2025-05-07 | WordPress SKT Skill Bar <= 2.4 - Cross Site Scripting (XSS) Vulnerability |
CVE-2025-47483 | 2025-05-07 | WordPress Easy Replace Image <= 3.5.0 - Server Side Request Forgery (SSRF) Vulnerability |
CVE-2025-47484 | 2025-05-07 | WordPress Display Remote Posts Block <= 1.1.0 - Server Side Request Forgery (SSRF) Vulnerability |
CVE-2025-47485 | 2025-05-07 | WordPress Cozy Blocks <= 2.1.22 - Broken Access Control Vulnerability |
CVE-2025-47486 | 2025-05-07 | WordPress Gutenberg & Elementor Templates Importer For Responsive <= 3.1.9 - Broken Access Control Vulnerability |
CVE-2025-47488 | 2025-05-07 | WordPress Bold Page Builder <= 5.3.2 - Cross Site Scripting (XSS) Vulnerability |
CVE-2025-47489 | 2025-05-07 | WordPress Beds24 Online Booking <= 2.0.29 - Cross Site Scripting (XSS) Vulnerability |