Common Vulnerabilities and Exposures (CVE)

CVE-2025-59456

Sep 17, 2025 12:59:54 UTC

In JetBrains TeamCity before 2025.07.2 path traversal was possible during project archive upload

CVE-2025-59455

Sep 17, 2025 12:59:24 UTC

In JetBrains TeamCity before 2025.07.2 project isolation bypass was possible due to race condition

CVE-2025-0419

Sep 17, 2025 12:58:57 UTC

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zirve Information Technologies Inc. Zirve Nova allows Cross-Site Scripting (XSS).This issue affects Zirve Nova: from 235 through 20...

CVE-2025-9972

Sep 17, 2025 12:56:29 UTC

The N-Reporter, N-Cloud, and N-Probe developed by N-Partner has an OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the server.

CVE-2025-9971

Sep 17, 2025 12:55:54 UTC

Certain models of Industrial Cellular Gateway developed by Planet Technology have a Missing Authentication vulnerability, allowing unauthenticated remote attackers to manipulate the device via a specific functionality.

CVE-2025-9565

Sep 17, 2025 12:54:12 UTC

The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocksy_newsletter_subscribe shortcode in all versions up to, and including, 2.1.10 due to insufficient input sanitization and output e...

CVE-2025-9216

Sep 17, 2025 12:53:28 UTC

The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the import() function in all versi...

CVE-2025-9203

Sep 17, 2025 12:52:40 UTC

The Media Player Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subtitle_ssize', 'track_title', and 'track_artist_name' parameters in version 1.0.5. This is due to insufficient input sanitiza...

CVE-2025-9215

Sep 17, 2025 12:51:48 UTC

The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.0 via the file_download() function. Thi...

CVE-2025-9450

Sep 17, 2025 12:51:00 UTC

A Use of Uninitialized Variable vulnerability affecting the JT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025 could allow an attacker to execute arbitrary code while opening a specially crafted JT file.

CVE-2025-9449

Sep 17, 2025 12:50:33 UTC

A Use After Free vulnerability affecting the PAR file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025 could allow an attacker to execute arbitrary code while opening a specially crafted PAR file.

CVE-2025-9447

Sep 17, 2025 12:50:06 UTC

An Out-Of-Bounds Read vulnerability affecting the PAR file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025 could allow an attacker to execute arbitrary code while opening a specially crafted PAR file.

CVE-2025-10057

Sep 17, 2025 12:49:25 UTC

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.28. This is due to the write_to_customfile() function writing unfiltered PHP code to...

CVE-2025-10058

Sep 17, 2025 12:48:43 UTC

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the upload_function() function in all versions up to, and including, 7.27. Thi...

CVE-2025-10042

Sep 17, 2025 12:48:06 UTC

The Quiz Maker plugin for WordPress is vulnerable to SQL Injection via spoofed IP headers in all versions up to, and including, 6.7.0.56 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the e...