Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2025-05-01 CVE-2025-3952 Missing Authorization vulnerability in Projectopia
The Projectopia – WordPress Project Management plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'pto_remove_logo' function in all versions up to, and including, 5.1.16.
network
low complexity
projectopia CWE-862
8.1
2025-05-01 CVE-2025-4099 Cross-site Scripting vulnerability in Sizeable List Children
The List Children plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'list_children' shortcode in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
sizeable CWE-79
5.4
2025-05-01 CVE-2025-4150 Classic Buffer Overflow vulnerability in Netgear Ex6200 Firmware 1.0.3.94
A vulnerability was found in Netgear EX6200 1.0.3.94.
network
low complexity
netgear CWE-120
critical
9.8
2025-05-01 CVE-2025-1304 Missing Authorization vulnerability in Spicethemes Newsblogger
The NewsBlogger theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the newsblogger_install_and_activate_plugin() function in all versions up to, and including, 0.2.5.1.
network
low complexity
spicethemes CWE-862
8.8
2025-05-01 CVE-2025-1305 Cross-Site Request Forgery (CSRF) vulnerability in Spicethemes Newsblogger
The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2.5.4.
network
low complexity
spicethemes CWE-352
8.8
2025-05-01 CVE-2025-2168 Cross-Site Request Forgery (CSRF) vulnerability in Bdthemes Ultimate Store KIT
The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.1.
network
low complexity
bdthemes CWE-352
4.3
2025-05-01 CVE-2025-4148 Classic Buffer Overflow vulnerability in Netgear Ex6200 Firmware 1.0.3.94
A vulnerability was found in Netgear EX6200 1.0.3.94 and classified as critical.
network
low complexity
netgear CWE-120
critical
9.8
2025-05-01 CVE-2025-4149 Classic Buffer Overflow vulnerability in Netgear Ex6200 Firmware 1.0.3.94
A vulnerability was found in Netgear EX6200 1.0.3.94.
network
low complexity
netgear CWE-120
critical
9.8
2025-05-01 CVE-2025-2816 Missing Authorization vulnerability in A3Rev Page View Count
The Page View Count plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the yellow_message_dontshow() function in versions 2.8.0 to 2.8.4.
network
low complexity
a3rev CWE-862
8.1
2025-05-01 CVE-2025-4146 Classic Buffer Overflow vulnerability in Netgear Ex6200 Firmware 1.0.3.94
A vulnerability, which was classified as critical, was found in Netgear EX6200 1.0.3.94.
network
low complexity
netgear CWE-120
critical
9.8