NA - CVE-2025-4231 - A command injection vulnerability in Palo Alto...
A command injection vulnerability in Palo Alto Networks PAN-OS® enables an authenticated administrative user to perform actions as the root user. The attacker must have network access to the...
NA - CVE-2025-4232 - An improper neutralization of wildcards...
An improper neutralization of wildcards vulnerability in the log collection feature of Palo Alto Networks GlobalProtect™ app on macOS allows a non administrative user to escalate their privileges...
High - CVE-2025-47959 - Improper neutralization of special elements...
Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code over a network.
Medium - CVE-2025-4584 - The IRM Newsroom plugin for WordPress is...
The IRM Newsroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'irmeventlist' shortcode in all versions up to, and including, 1.2.17 due to...
Medium - CVE-2025-4585 - The IRM Newsroom plugin for WordPress is...
The IRM Newsroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'irmflat' shortcode in all versions up to, and including, 1.2.17 due to...
Medium - CVE-2025-4586 - The IRM Newsroom plugin for WordPress is...
The IRM Newsroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'irmcalendarview' shortcode in all versions up to, and including, 1.2.17 due to...
Medium - CVE-2025-5123 - The Contact Us Page – Contact People plugin for...
The Contact Us Page – Contact People plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ parameter in all versions up to, and including, 3.7.4 due to insufficient...
Medium - CVE-2025-5233 - The Color Palette plugin for WordPress is...
The Color Palette plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hex’ parameter in all versions up to, and including, 4.3.2 due to insufficient input sanitization and...
Critical - CVE-2025-5288 - The REST API | Custom API Generator For Cross...
The REST API | Custom API Generator For Cross Platform And Import Export In WP plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the process_handler()...