High - CVE-2025-3302 - The Xagio SEO – AI Powered SEO plugin for...
The Xagio SEO – AI Powered SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘HTTP_REFERER’ parameter in all versions up to, and including, 7.1.0.16 due to insufficient...
NA - CVE-2025-5687 - A vulnerability in Mozilla VPN on macOS allows...
A vulnerability in Mozilla VPN on macOS allows privilege escalation from a normal user to root. *This bug only affects Mozilla VPN on macOS. Other operating systems are unaffected.* This...
NA - CVE-2025-5986 - A crafted HTML email using mailbox:/// links...
A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompting, even if auto-saving is...
Medium - CVE-2025-5144 - The The Events Calendar plugin for WordPress is...
The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-date-*’ parameters in all versions up to, and including, 6.13.2 due to insufficient input...
NA - CVE-2025-40914 - Perl CryptX before version 0.087 contains a...
Perl CryptX before version 0.087 contains a dependency that may be susceptible to an integer overflow. CryptX embeds a version of the libtommath library that is susceptible to an integer overflow...