
Look up vulnerabilities by software, product or CVE number.
| CVE | Published | CVSS | ShadowTrackr CVSS | Summary |
|---|---|---|---|---|
CVE: CVE-2025-3650 | Published 2025-09-12 | CVSS: 3.5 | ShadowTrackr CVSS: 0.2 | Summary: The jQuery Colorbox WordPress plugin through 4.6.3 uses the colorbox library, which does not sanitize title attributes on links before using them, allowing users with at least the contributor role to conduct XSS attacks against administrators. |
CVE: CVE-2025-36506 | Published 2025-06-13 | CVSS: 6.9 | ShadowTrackr CVSS: 2.7 | Summary: External control of file name or path issue exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If an attacker sends a specially crafted request, arbitrary files in the file system can be overwritten with log data. |
CVE: CVE-2025-36504 | Published 2025-05-07 | CVSS: 8.7 | ShadowTrackr CVSS: 6.6 | Summary: When a BIG-IP HTTP/2 httprouter profile is configured on a virtual server, undisclosed responses can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. |