Recent Advisories

Severity ID Title Vendor Product Date Type
Unknown ADV-0495

CVE-2025-39470 WordPress Ivy School <= 1.6.0 - Local File Inclusion Vulnerability

Vulnerability Details Basic Information Title CVE-2025-39470 WordPress Ivy School

N/A N/A NEWS
Unknown ADV-0492

CVE-2025-39469 WordPress Modal Survey plugin <= 2.0.2.0.1 - Cross Site Scripting (XSS) vulnerability

Vulnerability Details Basic Information Title CVE-2025-39469 WordPress Modal Survey plugin

N/A N/A NEWS
Unknown ADV-0487

CVE-2025-3598 Coupon Affiliates – Affiliate Plugin for WooCommerce <= 6.3.0 - Reflected Cross-Site Scripting via 'commission_summary' Parameter

Vulnerability Details Basic Information Title CVE-2025-3598 Coupon Affiliates – Affiliate Plugin for WooCommerce

N/A N/A NEWS
Unknown ADV-0485

CVE-2025-3783 SourceCodester Web-based Pharmacy Product Management System add-product.php unrestricted upload

Vulnerability Details Basic Information Title CVE-2025-3783 SourceCodester Web-based Pharmacy Product Management System add-product.php unrestricte...

N/A N/A NEWS
Unknown ADV-0484

CVE-2025-1863 Insecure default settings for recorder products

Vulnerability Details Basic Information Title CVE-2025-1863 Insecure default settings for recorder products Type cvelist Published 2025-04-18T05:55...

N/A N/A NEWS
Unknown ADV-0482

CVE-2025-3785 D-Link DWR-M961 Authorization Interface formStaticDHCP stack-based overflow

Vulnerability Details Basic Information Title CVE-2025-3785 D-Link DWR-M961 Authorization Interface formStaticDHCP stack-based overflow Type cvelis...

N/A N/A NEWS
Unknown ADV-0481

CVE-2025-3786 Tenda AC15 WifiExtraSet fromSetWirelessRepeat buffer overflow

Vulnerability Details Basic Information Title CVE-2025-3786 Tenda AC15 WifiExtraSet fromSetWirelessRepeat buffer overflow Type cvelist Published 20...

N/A N/A NEWS
Unknown ADV-0480

CVE-2025-3106 LA-Studio Element Kit for Elementor <= 1.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Table of Contents Widget

Vulnerability Details Basic Information Title CVE-2025-3106 LA-Studio Element Kit for Elementor

N/A N/A NEWS
Unknown ADV-0440

CVE-2024-49808 IBM Sterling Connect:Direct Web Services improper authorization

Vulnerability Details Basic Information Title CVE-2024-49808 IBM Sterling Connect:Direct Web Services improper authorization Type cvelist Published...

N/A N/A NEWS
Unknown ADV-0437

CVE-2024-45651 IBM Sterling Connect:Direct Web Services session fixation

Vulnerability Details Basic Information Title CVE-2024-45651 IBM Sterling Connect:Direct Web Services session fixation Type cvelist Published 2025-...

N/A N/A NEWS