High - CVE-2025-41662 - An unauthenticated remote attacker can execute...
An unauthenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of Cross-Site Request Forgery (CSRF) protection in the Main Web Interface...
High - CVE-2025-41663 - An unauthenticated remote attacker in a...
An unauthenticated remote attacker in a man-in-the-middle position can inject arbitrary commands in responses returned by WWH servers and gain arbitrary command execution with elevated privileges.
High - CVE-2025-4315 - The CubeWP – All-in-One Dynamic Content...
The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.23. This is due to the plugin allowing a user...
High - CVE-2025-3302 - The Xagio SEO – AI Powered SEO plugin for...
The Xagio SEO – AI Powered SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘HTTP_REFERER’ parameter in all versions up to, and including, 7.1.0.16 due to insufficient...
NA - CVE-2025-5687 - A vulnerability in Mozilla VPN on macOS allows...
A vulnerability in Mozilla VPN on macOS allows privilege escalation from a normal user to root. *This bug only affects Mozilla VPN on macOS. Other operating systems are unaffected.* This...
NA - CVE-2025-5986 - A crafted HTML email using mailbox:/// links...
A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompting, even if auto-saving is...