NA - CVE-2025-24385 - Dell Unity, version(s) 5.4 and prior,...
Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker...
NA - CVE-2025-24386 - Dell Unity, version(s) 5.4 and prior,...
Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker...
NA - CVE-2025-2894 - The Go1 also known as "The World's First...
The Go1 also known as "The World's First Intelligence Bionic Quadruped Robot Companion of Consumer Level," contains an undocumented backdoor that can enable the manufacturer, and anyone in...
NA - CVE-2025-31335 - The OpenSAML C++ library before 3.3.1 allows...
The OpenSAML C++ library before 3.3.1 allows forging of signed SAML messages via parameter manipulation (when using SAML bindings that rely on non-XML signatures).
Medium - CVE-2025-2804 - The tagDiv Composer plugin for WordPress, used...
The tagDiv Composer plugin for WordPress, used by the Newspaper theme, is vulnerable to Reflected Cross-Site Scripting via the 'account_id' and 'account_username' parameters in...
Critical - CVE-2025-2294 - The Kubio AI Page Builder plugin for WordPress...
The Kubio AI Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.5.1 via thekubio_hybrid_theme_load_template function. This makes it...
NA - CVE-2025-2027 - A double free vulnerability has been identified...
A double free vulnerability has been identified in the ASUS System Analysis service. This vulnerability can be triggered by sending specially crafted local RPC requests, leading to the service...
NA - CVE-2025-1762 - The Event Tickets with Ticket Scanner WordPress...
The Event Tickets with Ticket Scanner WordPress plugin before 2.5.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them...
High - CVE-2025-2328 - The Drag and Drop Multiple File Upload for...
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the...
High - CVE-2025-2485 - The Drag and Drop Multiple File Upload for...
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.8.7 via deserialization of untrusted...