Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.1 CVE-2025-69140

WordPress SweetDate Core plugin < 1.1.5 - Reflected Cross Site Scripting (XSS) vulnerability_CVE-2025-69140

Unauthenticated Cross Site Scripting (XSS) in SweetDate Core < 1.1.5 versions.

SeventhQueen SweetDate Core n/a CVE
HIGH 8.8 CVE-2025-69130

WordPress Entrepreneur – Booking for Small Businesses WordPress Theme theme <= 3.1.3 - PHP Object Injection vulnerability_CVE-2025-69130

Subscriber PHP Object Injection in Entrepreneur - Booking for Small Businesses WordPress Theme

Themovation Entrepreneur - Booking for Small Businesses WordPress Theme n/a CVE
HIGH 7.8 CVE-2025-48617

CVE-2025-48617_CVE-2025-48617

In overrideConfig of CarrierConfigLoader.java, there is a possible way to bypass UID check due to a permissions bypass. This could lead to local es...

Google Android 17 CVE
HIGH 8 CVE-2025-48640

CVE-2025-48640_CVE-2025-48640

In multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check. This could lead to remote (p...

Google Android 17 CVE
HIGH 7.8 CVE-2025-48643

CVE-2025-48643_CVE-2025-48643

In multiple locations there is a possible provisioning bypass due to improper input validation. This could lead to local escalation of privilege wi...

Google Android 17 CVE
HIGH 7.8 CVE-2026-0019

CVE-2026-0019_CVE-2026-0019

In SettingsLib, there is a possible way to disable system components due to a logic error in the code. This could lead to local escalation of privi...

Google Android 17 CVE
HIGH 8.6 CVE-2025-69128

WordPress JobCareer theme <= 7.3 - Arbitrary File Deletion vulnerability_CVE-2025-69128

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in EMV JobCareer allows Path Traversal. This issue af...

EMV JobCareer n/a CVE
CRITICAL 9.8 CVE-2025-69127

WordPress Plumbing theme <= 1.6 - PHP Object Injection vulnerability_CVE-2025-69127

Unauthenticated PHP Object Injection in Plumbing

ThemeREX Plumbing n/a CVE
LOW 3.3 CVE-2026-0057

CVE-2026-0057_CVE-2026-0057

In Contacts Provider, there is a possible way to access an incoming call's phone number and associated metadata due to a missing permission check. ...

Google Android 17 CVE
HIGH 8.1 CVE-2025-69126

WordPress Fortius theme <= 2.3.0 - Local File Inclusion vulnerability_CVE-2025-69126

Unauthenticated Local File Inclusion in Fortius

ThemeREX Fortius n/a CVE