CVE Alert: CVE-2025-11691 – themeisle – PPOM – Product Addons & Custom Fields for WooCommerce
CVE-2025-11691 HIGHNo exploitation known The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to...
CVE-2025-11691 HIGHNo exploitation known The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to...
CVE-2025-9890 HIGHNo exploitation known The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up...
CVE-2025-11517 HIGHNo exploitation known The Event Tickets and Registration plugin for WordPress is vulnerable to payment bypass in all versions...
CVE-2025-5555 HIGHNo exploitation known A vulnerability has been found in Nixdorf Wincor PORT IO Driver up to 1.0.0.1. This affects...
CVE-2020-36853 HIGHNo exploitation known The 10WebMapBuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Plugin Settings Change in...
CVE-2025-11898 HIGHNo exploitation known Agentflow developed by Flowring has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers to exploit...
CVE-2025-11899 HIGHNo exploitation known Agentflow developed by Flowring has an Use of Hard-coded Cryptographic Key vulnerability, allowing unauthenticated remote attackers...
CVE-2025-11864 HIGHNo exploitation known A vulnerability was identified in NucleoidAI Nucleoid up to 0.7.10. The impacted element is the function...
CVE-2025-53951 MEDIUMNo exploitation known An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Fortinet FortiDLP...
CVE-2025-36128 HIGHNo exploitation known IBM MQ 9.1, 9.2, 9.3, 9.4 LTS and 9.3, 9.4 CD is vulnerable to a denial...
CVE-2025-10706 HIGHNo exploitation known The Classified Pro theme for WordPress is vulnerable to unauthorized plugin installation due to a missing...
CVE-2025-20350 HIGHNo exploitation known A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800...
CVE-2025-61990 HIGHNo exploitation known When using a multi-bladed platform with more than one blade, undisclosed traffic can cause the Traffic...
CVE-2025-61935 HIGHNo exploitation known When a BIG IP Advanced WAF or ASM security policy is configured on a virtual server,...
CVE-2025-57780 HIGHNo exploitation known A vulnerability exists in F5OS-A and F5OS-C system that may allow an authenticated attacker with local...
CVE-2025-10581 HIGHNo exploitation known A potential DLL hijacking vulnerability was discovered in the Lenovo PC Manager during an internal security...
CVE-2025-58071 HIGHNo exploitation known When IPsec is configured on the BIG-IP system, undisclosed traffic can cause the Traffic Management Microkernel...
CVE-2025-8486 HIGHNo exploitation known A potential vulnerability was reported in PC Manager that could allow a local authenticated user to...
CVE-2025-60016 HIGHNo exploitation known When Diffie-Hellman (DH) group Elliptic Curve Cryptography (ECC) Brainpool curves are configured in an SSL profile's...
CVE-2025-59481 HIGHNo exploitation known A vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may...
CVE-2025-59781 HIGHNo exploitation known When DNS cache is configured on a BIG-IP or BIG-IP Next CNF virtual server, undisclosed DNS...
CVE-2025-59778 HIGHNo exploitation known When the Allowed IP Addresses feature is configured on the F5OS-C partition control plane, undisclosed traffic...
CVE-2025-61938 HIGHNo exploitation known When a BIG-IP Advanced WAF or ASM security policy is configured with a URL greater than...
CVE-2025-55669 HIGHNo exploitation known When the BIG-IP Advanced WAF and ASM security policy and a server-side HTTP/2 profile are configured...