CVE Feed

    Dashboard / CVE

    Unknown

    CVE-2025-69291

    Last Modified: 5 Jan 2026

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2025. Notes: none

    Published: 31 Dec 2025
    5.1
    Medium

    CVE-2021-47743

    Last Modified: 15 Apr 2026

    COMMAX Biometric Access Control System 1.0.0 contains an unauthenticated reflected cross-site scripting vulnerability in cookie parameters 'CMX_ADMIN_NM' and 'CMX_COMPLEX_NM'. Attackers can inject malicious HTML and JavaScript code into these cookie values to execute arbitrary scripts in a victim's browser session.

    Published: 31 Dec 2025
    6.9
    Medium

    CVE-2021-47740

    Last Modified: 15 Apr 2026

    KZTech JT3500V 4G LTE CPE 2.0.1 contains a session management vulnerability that allows attackers to reuse old session credentials without proper expiration. Attackers can exploit the weak session handling to maintain unauthorized access and potentially compromise device authentication mechanisms.

    Published: 31 Dec 2025
    4.8
    Medium

    CVE-2021-47725

    Last Modified: 28 Jul 2026

    STVS ProVision 5.9.10 contains a cross-site scripting vulnerability in the 'files' POST parameter that allows authenticated attackers to inject arbitrary HTML code. Attackers can exploit the unvalidated input to execute malicious scripts within a user's browser session in the context of the affected site.

    Published: 31 Dec 2025
    5.3
    Medium

    CVE-2025-34467

    Last Modified: 5 Mar 2026

    ZwiiCMS versions prior to 13.7.00 contain a denial-of-service vulnerability in multiple administrative endpoints due to improper authorization checks combined with flawed resource state management. When an authenticated low-privilege user requests an administrative page, the application returns "404 Not Found" as expected, but incorrectly acquires and associates a temporary lock on the targeted resource with the attacker session prior to authorization. This lock prevents other users, including administrators, from accessing the affected functionality until the attacker navigates away or the session is terminated.

    Published: 31 Dec 2025
    8.6
    High

    CVE-2021-47747

    Last Modified: 15 Apr 2026

    meterN 1.2.3 contains an authenticated remote code execution vulnerability in admin_meter2.php and admin_indicator2.php scripts. Attackers can exploit the 'COMMANDx' and 'LIVECOMMANDx' POST parameters to execute arbitrary system commands with administrative privileges.

    Published: 31 Dec 2025
    8.6
    High

    CVE-2021-47745

    Last Modified: 15 Apr 2026

    Cypress Solutions CTM-200 2.7.1 contains an authenticated command injection vulnerability in the firmware upgrade script that allows remote attackers to execute shell commands. Attackers can exploit the 'fw_url' parameter in the ctm-config-upgrade.sh script to inject and execute arbitrary commands with root privileges.

    Published: 31 Dec 2025
    9.3
    Critical

    CVE-2021-47744

    Last Modified: 15 Apr 2026

    Cypress Solutions CTM-200/CTM-ONE 1.3.6 contains hard-coded credentials vulnerability in Linux distribution that exposes root access. Attackers can exploit the static 'Chameleon' password to gain remote root access via Telnet or SSH on affected devices.

    Published: 31 Dec 2025
    8.5
    High

    CVE-2021-47742

    Last Modified: 15 Apr 2026

    Epic Games Psyonix Rocket League <=1.95 contains an insecure permissions vulnerability that allows authenticated users to modify executable files with full access permissions. Attackers can leverage the 'F' (Full) flag for the 'Authenticated Users' group to change executable files and potentially escalate system privileges.

    Published: 31 Dec 2025
    8.7
    High

    CVE-2021-47741

    Last Modified: 15 Apr 2026

    ZBL EPON ONU Broadband Router V100R001 contains a privilege escalation vulnerability that allows limited administrative users to elevate access by sending requests to configuration endpoints. Attackers can exploit the vulnerability by accessing the configuration backup or password page to disclose the super user password and gain additional privileged functionalities.

    Published: 31 Dec 2025
    8.7
    High

    CVE-2021-47726

    Last Modified: 15 Apr 2026

    NuCom 11N Wireless Router 5.07.90 contains a privilege escalation vulnerability that allows non-privileged users to access administrative credentials through the configuration backup endpoint. Attackers can send a crafted HTTP GET request to the backup configuration page with a specific cookie to retrieve and decode the admin password in Base64 format.

    Published: 31 Dec 2025
    9.3
    Critical

    CVE-2020-36904

    Last Modified: 15 Apr 2026

    Selea CarPlateServer 4.0.1.6 contains a remote program execution vulnerability that allows attackers to execute arbitrary Windows binaries by manipulating the NO_LIST_EXE_PATH configuration parameter. Attackers can bypass authentication through the /cps/ endpoint and modify server configuration, including changing admin passwords and executing system commands.

    Published: 31 Dec 2025
    8.5
    High

    CVE-2020-36903

    Last Modified: 15 Apr 2026

    Selea CarPlateServer 4.0.1.6 contains an unquoted service path vulnerability in the Windows service configuration that allows local users to potentially execute code with elevated privileges. Attackers can exploit the service's unquoted binary path by inserting malicious code in the system root path that could execute with LocalSystem privileges during application startup or reboot.

    Published: 31 Dec 2025
    8.2
    High

    CVE-2025-34468

    Last Modified: 23 Mar 2026

    libcoap versions up to and including 4.3.5, prior to commit 30db3ea, contain a stack-based buffer overflow in address resolution when attacker-controlled hostname data is copied into a fixed 256-byte stack buffer without proper bounds checking. A remote attacker can trigger a crash and potentially achieve remote code execution depending on compiler options and runtime memory protections. Exploitation requires the proxy logic to be enabled (i.e., the proxy request handling code path in an application using libcoap).

    Published: 31 Dec 2025
    5.4
    Medium

    CVE-2025-66149

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in merkulove UnGrabber ungrabber allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UnGrabber: from n/a through <= 3.1.3.

    Published: 31 Dec 2025
    5.4
    Medium

    CVE-2025-66150

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in merkulove Appender appender allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Appender: from n/a through <= 1.1.1.

    Published: 31 Dec 2025
    5.4
    Medium

    CVE-2025-66151

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in merkulove Countdowner for Elementor countdowner-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Countdowner for Elementor: from n/a through <= 1.0.4.

    Published: 31 Dec 2025
    5.4
    Medium

    CVE-2025-66152

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in merkulove Criptopayer for Elementor criptopayer-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Criptopayer for Elementor: from n/a through <= 1.0.1.

    Published: 31 Dec 2025
    2.1
    Low

    CVE-2025-15393

    Last Modified: 5 Jan 2026

    A security vulnerability has been detected in Kohana KodiCMS up to 13.82.135. This impacts the function Save of the file cms/modules/kodicms/classes/kodicms/model/file.php of the component Layout API Endpoint. The manipulation of the argument content leads to code injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Dec 2025
    5.4
    Medium

    CVE-2025-66153

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in merkulove Headinger for Elementor headinger-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Headinger for Elementor: from n/a through <= 1.1.4.

    Published: 31 Dec 2025
    2.1
    Low

    CVE-2025-15392

    Last Modified: 14 Jan 2026

    A weakness has been identified in Kohana KodiCMS up to 13.82.135. This affects the function like of the file cms/modules/pages/classes/kodicms/model/page.php of the component Search API Endpoint. Executing manipulation of the argument keyword can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Dec 2025
    2.1
    Low

    CVE-2025-15391

    Last Modified: 14 Jan 2026

    A weakness has been identified in D-Link DIR-806A 100CNb11. Affected is the function ssdpcgi_main of the component SSDP Request Handler. This manipulation causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 31 Dec 2025
    5.9
    Medium

    CVE-2025-49355

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ikaes Accessibility Press ilogic-accessibility allows Stored XSS.This issue affects Accessibility Press: from n/a through <= 1.0.2.

    Published: 31 Dec 2025
    5.9
    Medium

    CVE-2025-49337

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in janhenckens Dashboard Beacon wp-dashboard-beacon allows Stored XSS.This issue affects Dashboard Beacon: from n/a through <= 1.2.0.

    Published: 31 Dec 2025
    5.9
    Medium

    CVE-2025-59135

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eleopard Behance Portfolio Manager portfolio-manager-powered-by-behance allows Stored XSS.This issue affects Behance Portfolio Manager: from n/a through <= 1.7.5.

    Published: 31 Dec 2025
    5.9
    Medium

    CVE-2025-62989

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gora Tech Cooked cooked allows Stored XSS.This issue affects Cooked: from n/a through <= 1.11.3.

    Published: 31 Dec 2025
    7.1
    High

    CVE-2025-23608

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Omar Mohamed Mohamoud LIVE TV live-tv allows Reflected XSS.This issue affects LIVE TV: from n/a through <= 1.2.

    Published: 31 Dec 2025
    5.4
    Medium

    CVE-2025-62088

    Last Modified: 23 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in extendons WordPress & WooCommerce Scraper Plugin, Import Data from Any Site wp_scraper allows Server Side Request Forgery.This issue affects WordPress & WooCommerce Scraper Plugin, Import Data from Any Site: from n/a through <= 1.0.7.

    Published: 31 Dec 2025
    4.9
    Medium

    CVE-2025-59138

    Last Modified: 23 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in Jthemes Genemy genemy allows Server Side Request Forgery.This issue affects Genemy: from n/a through <= 1.6.6.

    Published: 31 Dec 2025
    5.1
    Medium

    CVE-2019-25262

    Last Modified: 15 Apr 2026

    A security vulnerability has been detected in elinicksic Razgover up to db37dfc5c82f023a40f2f7834ded6633fb2b5262. This affects an unknown part of the file Chattify/send.php of the component Chat Message Handler. Such manipulation of the argument msg leads to cross site scripting. The attack may be performed from remote. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The name of the patch is 995dd89d0e3ec5522966724be23a5d58ca1bdac3. Applying a patch is advised to resolve this issue. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 31 Dec 2025
    5.4
    Medium

    CVE-2025-66154

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in merkulove Couponer for Elementor couponer-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Couponer for Elementor: from n/a through <= 1.1.7.

    Published: 31 Dec 2025
    5.4
    Medium

    CVE-2025-66155

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in merkulove Questionar for Elementor questionar-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Questionar for Elementor: from n/a through <= 1.1.7.

    Published: 31 Dec 2025
    5.4
    Medium

    CVE-2025-66156

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in merkulove Watcher for Elementor watcher-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Watcher for Elementor: from n/a through <= 1.0.9.

    Published: 31 Dec 2025
    5.4
    Medium

    CVE-2025-66157

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in merkulove Sliper for Elementor sliper-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sliper for Elementor: from n/a through <= 1.0.10.

    Published: 31 Dec 2025
    5.4
    Medium

    CVE-2025-66158

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in merkulove Gmaper for Elementor gmaper-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gmaper for Elementor: from n/a through <= 1.0.9.

    Published: 31 Dec 2025
    5.4
    Medium

    CVE-2025-66159

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in merkulove Walker for Elementor walker-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Walker for Elementor: from n/a through <= 1.1.6.

    Published: 31 Dec 2025
    5.4
    Medium

    CVE-2025-66160

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in merkulove Select Graphist for Elementor Graphist for Elementor graphist-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Select Graphist for Elementor Graphist for Elementor: from n/a through <= 1.2.10.

    Published: 31 Dec 2025
    6.5
    Medium

    CVE-2025-63021

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codetipi Valenti Engine valenti-engine allows DOM-Based XSS.This issue affects Valenti Engine: from n/a through <= 1.0.3.

    Published: 31 Dec 2025
    4.3
    Medium

    CVE-2025-62874

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Alexander AnyComment anycomment allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AnyComment: from n/a through <= 0.3.6.

    Published: 31 Dec 2025
    Unknown

    CVE-2025-69290

    Last Modified: 5 Jan 2026

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2025. Notes: none

    Published: 31 Dec 2025
    4.3
    Medium

    CVE-2025-62099

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in approveme Signature Add-On for Gravity Forms gravity-signature-forms-add-on allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Signature Add-On for Gravity Forms: from n/a through <= 1.8.6.

    Published: 31 Dec 2025
    4.3
    Medium

    CVE-2025-62101

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Omid Shamloo Pardakht Delkhah pardakht-delkhah allows Cross Site Request Forgery.This issue affects Pardakht Delkhah: from n/a through <= 3.0.0.

    Published: 31 Dec 2025
    4.3
    Medium

    CVE-2025-63038

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Northern Beaches Websites WP Custom Admin Interface wp-custom-admin-interface allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Custom Admin Interface: from n/a through <= 7.40.

    Published: 31 Dec 2025
    4.3
    Medium

    CVE-2025-62078

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Fahad Mahmood Easy Upload Files During Checkout easy-upload-files-during-checkout allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Upload Files During Checkout: from n/a through <= 3.0.0.

    Published: 31 Dec 2025
    4.3
    Medium

    CVE-2025-49339

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Digages Direct Payments WP direct-payments-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Direct Payments WP: from n/a through <= 1.3.2.

    Published: 31 Dec 2025
    4.3
    Medium

    CVE-2025-49340

    Last Modified: 28 Apr 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Digages Direct Payments WP direct-payments-wp allows Retrieve Embedded Sensitive Data.This issue affects Direct Payments WP: from n/a through <= 1.3.2.

    Published: 31 Dec 2025
    4.3
    Medium

    CVE-2025-62083

    Last Modified: 23 Apr 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WP Messiah BoomDevs WordPress Coming Soon coming-soon-by-boomdevs allows Retrieve Embedded Sensitive Data.This issue affects BoomDevs WordPress Coming Soon: from n/a through <= 1.0.4.

    Published: 31 Dec 2025
    4.3
    Medium

    CVE-2025-62113

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in emendo_seb Co-marquage service-public.fr co-marquage-service-public allows Cross Site Request Forgery.This issue affects Co-marquage service-public.fr: from n/a through <= 0.5.77.

    Published: 31 Dec 2025
    4.3
    Medium

    CVE-2025-62115

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in ThemeBoy Hide Plugins hide-plugins allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hide Plugins: from n/a through <= 1.0.4.

    Published: 31 Dec 2025
    4.3
    Medium

    CVE-2025-62123

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in inkthemes WP Gmail SMTP wp-gmail-smtp allows Cross Site Request Forgery.This issue affects WP Gmail SMTP: from n/a through <= 1.0.7.

    Published: 31 Dec 2025