| CVE ID | Publié | Description | Score | Gravité | |
|---|---|---|---|---|---|
CVE-2025-12775 |
2025-11-18 08h15 +00:00 |
The WP Dropzone plugin for WordPress is vulnerable to authenticated arbitrary file upload in all ver... File Inclusion |
8.8 |
Haute |
|
CVE-2025-13069 |
2025-11-18 09h15 +00:00 |
The Enable SVG, WebP, and ICO Upload plugin for WordPress is vulnerable to arbitrary file upload in ... File Inclusion |
8.8 |
Haute |
|
CVE-2025-13088 |
2025-11-18 08h15 +00:00 |
The Category and Product Woocommerce Tabs plugin for WordPress is vulnerable to Local File Inclusion... |
8.8 |
Haute |
|
CVE-2025-40547 |
2025-11-18 08h15 +00:00 |
A logic error vulnerability exists in Serv-U which when abused could give a malicious actor with acc... |
9.1 |
Critique |
|
CVE-2025-40548 |
2025-11-18 08h15 +00:00 |
A missing validation process exists in Serv U when abused, could give a malicious actor with access ... Improper Privilege Management |
9.1 |
Critique |
|
CVE-2025-40549 |
2025-11-18 08h15 +00:00 |
A Path Restriction Bypass vulnerability exists in Serv-U that when abused, could give a malicious ac... Directory Traversal |
9.1 |
Critique |
|
CVE-2025-41733 |
2025-11-18 10h15 +00:00 |
The commissioning wizard on the affected devices does not validate if the device is already initiali... |
9.8 |
Critique |
|
CVE-2025-41734 |
2025-11-18 10h15 +00:00 |
An unauthenticated remote attacker can execute arbitrary php files and gain full access of the affec... |
9.8 |
Critique |
|
CVE-2025-41735 |
2025-11-18 10h15 +00:00 |
A low privileged remote attacker can upload any file to an arbitrary location due to missing file ch... File Inclusion |
8.8 |
Haute |
|
CVE-2025-41736 |
2025-11-18 10h15 +00:00 |
A low privileged remote attacker can upload a new or overwrite an existing python script by using a ... |
8.8 |
Haute |