Loading HuntDB...

Recently Updated CVEs

Latest Updates

Most recently updated vulnerabilities, including new information, EPSS scores, and exploit discoveries.

CVE-2025-10287 Updated 4 days, 5 hours ago

A vulnerability has been found in roncoo roncoo-pay up to 9428382af21cd5568319eae7429b7e1d0332ff40. The affected element is an unknown function of the file /auth/orderQuery. Such manipulation of the argument orderNo leads to direct request. The attack may be performed from remote. A high complexity level is associated with this attack. The exploitability is described as difficult. The exploit has been disclosed to the public and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The vendor was contacted early about this disclosure but did not respond in any way.

UNKNOWN (3.1)
CVE-2025-9881 Updated 4 days, 6 hours ago

The Ultimate Blogroll plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

MEDIUM (6.1)
CVE-2025-9880 Updated 4 days, 6 hours ago

The Side Slide Responsive Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

MEDIUM (6.1)
CVE-2025-9879 Updated 4 days, 6 hours ago

The Spotify Embed Creator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spotify' shortcode in all versions up to, and including, 1.0.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

MEDIUM (6.4)
CVE-2025-9877 Updated 4 days, 6 hours ago

The Embed Google Datastudio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'egds' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

MEDIUM (6.4)
CVE-2025-10278 Updated 4 days, 6 hours ago

A flaw has been found in YunaiV ruoyi-vue-pro up to 2025.09. Impacted is an unknown function of the file /crm/contact/transfer. This manipulation of the argument ids/newOwnerUserId causes improper authorization. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

UNKNOWN (6.3)
CVE-2025-43788 Updated 4 days, 7 hours ago

The organization selector in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q1.1 through 2024.Q1.12 and 7.4 update 81 through update 85 does not check user permission, which allows remote authenticated users to obtain a list of all organizations.

UNKNOWN (0.0)
CVE-2025-10276 Updated 4 days, 7 hours ago

A security vulnerability has been detected in YunaiV ruoyi-vue-pro up to 2025.09. This vulnerability affects unknown code of the file /crm/contract/transfer. The manipulation of the argument id/newOwnerUserId leads to improper authorization. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

UNKNOWN (6.3)
CVE-2025-10269 Updated 4 days, 7 hours ago

The Spirit Framework plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.2.13. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.

HIGH (7.5)
CVE-2025-55317 Updated 4 days, 8 hours ago

No description available

HIGH (7.8)
CVE-2025-55316 Updated 4 days, 8 hours ago

No description available

HIGH (7.8)
CVE-2025-55245 Updated 4 days, 8 hours ago

No description available

HIGH (7.8)
CVE-2025-55244 Updated 4 days, 8 hours ago

No description available

CRITICAL (9.0)
CVE-2025-55243 Updated 4 days, 8 hours ago

No description available

HIGH (7.5)
CVE-2025-55242 Updated 4 days, 8 hours ago

No description available

MEDIUM (6.5)
CVE-2025-55241 Updated 4 days, 8 hours ago

No description available

CRITICAL (9.0)
CVE-2025-55238 Updated 4 days, 8 hours ago

No description available

HIGH (7.5)
CVE-2025-55236 Updated 4 days, 8 hours ago

No description available

HIGH (7.3)
CVE-2025-55234 Updated 4 days, 8 hours ago

No description available

HIGH (8.8)
CVE-2025-55232 Updated 4 days, 8 hours ago

No description available

CRITICAL (9.8)