Search

Search Results (313424 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-11522 2025-10-09 9.8 Critical
The Search & Go - Directory WordPress Theme theme for WordPress is vulnerable to Authentication Bypass via account takeover in all versions up to, and including, 2.7. This is due to insufficient user validation in the search_and_go_elated_check_facebook_user() function This makes it possible for unauthenticated attackers to gain access to other user's accounts, including administrators, when Facebook login is enabled.
CVE-2025-7634 2025-10-09 9.8 Critical
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 6.6.7 via the mode parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.
CVE-2025-7526 2025-10-09 9.8 Critical
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to arbitrary file deletion (via renaming) due to insufficient file path validation in the set_user_profile_image function in all versions up to, and including, 6.6.7. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
CVE-2022-50450 1 Linux 1 Linux Kernel 2025-10-09 5.5 Medium
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-6038 2025-10-09 8.8 High
The Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme plugin for WordPress is vulnerable to privilege escalation via password update in all versions up to, and including, 1.4.0. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change arbitrary user's passwords, including those of administrators.
CVE-2025-47355 2025-10-09 7.8 High
Memory corruption while invoking remote procedure IOCTL calls.
CVE-2025-47354 2025-10-09 7.8 High
Memory corruption while allocating buffers in DSP service.
CVE-2025-47351 2025-10-09 7.8 High
Memory corruption while processing user buffers.
CVE-2025-47349 2025-10-09 7.8 High
Memory corruption while processing an escape call.
CVE-2025-47347 2025-10-09 7.8 High
Memory corruption while processing control commands in the virtual memory management interface.
CVE-2025-47342 2025-10-09 7.1 High
Transient DOS may occur when multi-profile concurrency arises with QHS enabled.
CVE-2025-47341 2025-10-09 7.8 High
memory corruption while processing an image encoding completion event.
CVE-2025-47340 2025-10-09 7.8 High
Memory corruption while processing IOCTL call to get the mapping.
CVE-2025-47338 2025-10-09 7.8 High
Memory corruption while processing escape commands from userspace.
CVE-2025-27060 2025-10-09 8.8 High
Memory corruption while performing SCM call with malformed inputs.
CVE-2025-27059 2025-10-09 8.8 High
Memory corruption while performing SCM call.
CVE-2025-27054 2025-10-09 7.8 High
Memory corruption while processing a malformed license file during reboot.
CVE-2025-27053 2025-10-09 7.8 High
Memory corruption during PlayReady APP usecase while processing TA commands.
CVE-2025-27049 2025-10-09 5.5 Medium
Transient DOS while processing IOCTL call for image encoding.
CVE-2025-27048 2025-10-09 7.8 High
Memory corruption while processing camera platform driver IOCTL calls.