Critical - CVE-2025-4973 - The Workreap plugin for WordPress, used by the...
The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to authentication bypass in all versions up to, and including, 3.3.1. This is due to...
NA - CVE-2025-35978 - Improper restriction of communication channel...
Improper restriction of communication channel to intended endpoints issue exists in UpdateNavi V1.4 L10 to L33 and UpdateNaviInstallService Service 1.2.0091 to 1.2.0125. If a local authenticated...
Medium - CVE-2025-40592 - A vulnerability has been identified in Mendix...
A vulnerability has been identified in Mendix Studio Pro 10 (All versions < V10.23.0), Mendix Studio Pro 10.12 (All versions < V10.12.17), Mendix Studio Pro 10.18 (All versions < V10.18.7), Mendix...
NA - CVE-2025-5301 - ONLYOFFICE Docs (DocumentServer) in versions...
ONLYOFFICE Docs (DocumentServer) in versions equal and below 8.3.1 are affected by a reflected cross-site scripting (XSS) issue when opening files via the WOPI protocol. Attackers could inject...
NA - CVE-2025-4613 - Path traversal in Google Web Designer's...
Path traversal in Google Web Designer's template handling versions prior to 16.3.0.0407 on Windows allows attacker to achieve remote code execution by tricking users into downloading a...
Medium - CVE-2025-6003 - The WordPress Single Sign-On (SSO) plugin for...
The WordPress Single Sign-On (SSO) plugin for WordPress is vulnerable to unauthorized access due to a misconfigured capability check on a function in all versions up to, and including, the *.5.3...
NA - CVE-2025-1478 - An issue has been discovered in GitLab CE/EE...
An issue has been discovered in GitLab CE/EE affecting all versions from 8.13 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of input validation in Board Names could be used...
NA - CVE-2025-1516 - An issue has been discovered in GitLab CE/EE...
An issue has been discovered in GitLab CE/EE affecting all versions from 8.7 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper input validation in Tokens Names could be used to...
NA - CVE-2025-2254 - An issue has been discovered in GitLab CE/EE...
An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper output encoding in the snipper viewer...
NA - CVE-2025-4278 - An issue has been discovered in GitLab CE/EE...
An issue has been discovered in GitLab CE/EE affecting all versions starting with 18.0 before 18.0.2. Under certain conditions html injection in new search page could lead to account takeover.