CVE Feed

    Dashboard / CVE

    8.7
    High

    CVE-2018-25143

    Last Modified: 26 Jan 2026

    Microhard Systems IPn4G 1.1.0 contains a service vulnerability that allows authenticated users to enable a restricted SSH shell with a default 'msshc' user. Attackers can exploit a custom 'ping' command in the NcFTP environment to escape the restricted shell and execute commands with root privileges.

    Published: 24 Dec 2025
    7.1
    High

    CVE-2018-25142

    Last Modified: 28 Jul 2026

    NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerability in XML preference import settings. Attackers can craft malicious XML files with DTD parameter entities to retrieve arbitrary system files through an out-of-band channel attack.

    Published: 24 Dec 2025
    8.7
    High

    CVE-2018-25141

    Last Modified: 15 Apr 2026

    FLIR thermal traffic cameras contain an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. Attackers can directly retrieve video streams by accessing specific endpoints like /live.mjpeg, /snapshot.jpg, and RTSP streaming URLs without authentication.

    Published: 24 Dec 2025
    9.3
    Critical

    CVE-2018-25140

    Last Modified: 15 Apr 2026

    FLIR thermal traffic cameras contain an unauthenticated device manipulation vulnerability in their WebSocket implementation that allows attackers to bypass authentication and authorization controls. Attackers can directly modify device configurations, access system information, and potentially initiate denial of service by sending crafted WebSocket messages without authentication.

    Published: 24 Dec 2025
    8.7
    High

    CVE-2018-25139

    Last Modified: 31 Dec 2025

    FLIR AX8 Thermal Camera 1.32.16 contains an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. Attackers can directly connect to the RTSP stream using tools like VLC or FFmpeg to view and record thermal camera footage.

    Published: 24 Dec 2025
    9.3
    Critical

    CVE-2018-25138

    Last Modified: 5 Jan 2026

    FLIR AX8 Thermal Camera 1.32.16 contains hard-coded SSH and web panel credentials that cannot be changed through normal camera operations. Attackers can exploit these persistent credentials to gain unauthorized shell access and login to multiple camera interfaces using predefined username and password combinations.

    Published: 24 Dec 2025
    8.7
    High

    CVE-2018-25137

    Last Modified: 15 Apr 2026

    FLIR Brickstream 3D+ 2.1.742.1842 contains an unauthenticated vulnerability in the ExportConfig REST API that allows attackers to download sensitive configuration files. Attackers can exploit the getConfigExportFile.cgi endpoint to retrieve system configurations, potentially enabling authentication bypass and privilege escalation.

    Published: 24 Dec 2025
    8.7
    High

    CVE-2018-25136

    Last Modified: 15 Apr 2026

    FLIR Brickstream 3D+ 2.1.742.1842 contains an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. Attackers can retrieve video stream images by directly accessing multiple image endpoints like middleImage.jpg, rightimage.jpg, and leftimage.jpg.

    Published: 24 Dec 2025
    9.3
    Critical

    CVE-2018-25135

    Last Modified: 15 Apr 2026

    Anviz AIM CrossChex Standard 4.3.6.0 contains a CSV injection vulnerability that allows attackers to execute commands by inserting malicious formulas in user import fields. Attackers can craft payloads in fields like 'Name', 'Gender', or 'Position' to trigger Excel macro execution when importing user data.

    Published: 24 Dec 2025
    9.3
    Critical

    CVE-2018-25134

    Last Modified: 15 Apr 2026

    Synaccess netBooter NP-02x/NP-08x 6.8 contains an authentication bypass vulnerability in the webNewAcct.cgi script that allows unauthenticated attackers to create admin user accounts. Attackers can exploit the missing control check by sending crafted POST requests to create administrative accounts and gain unauthorized control over power supply management.

    Published: 24 Dec 2025
    5.1
    Medium

    CVE-2018-25133

    Last Modified: 15 Apr 2026

    Synaccess netBooter NP-0801DU 7.4 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without proper request validation. Attackers can craft malicious web pages with hidden form submissions to add admin users by tricking authenticated administrators into loading a malicious page.

    Published: 24 Dec 2025
    5.1
    Medium

    CVE-2018-25131

    Last Modified: 15 Apr 2026

    Leica Geosystems GR10/GR25/GR30/GR50 GNSS 4.30.063 contains a stored cross-site scripting vulnerability in the configuration file upload functionality. Attackers can upload a malicious HTML file to that executes arbitrary JavaScript in a user's browser session when viewed.

    Published: 24 Dec 2025
    6.8
    Medium

    CVE-2018-25130

    Last Modified: 15 Apr 2026

    Beward Intercom 2.3.1 contains a credentials disclosure vulnerability that allows local attackers to access plain-text authentication credentials stored in an unencrypted database file. Attackers can read the BEWARD.INTERCOM.FDB file to extract usernames and passwords, enabling unauthorized access to IP cameras and door stations.

    Published: 24 Dec 2025
    7.1
    High

    CVE-2018-25129

    Last Modified: 15 Apr 2026

    SOCA Access Control System 180612 contains multiple insecure direct object reference vulnerabilities that allow attackers to access sensitive user credentials. Attackers can retrieve authenticated and unauthenticated user password hashes and pins through unprotected endpoints like Get_Permissions_From_DB.php and Ac10_ReadSortCard.

    Published: 24 Dec 2025
    9.3
    Critical

    CVE-2018-25128

    Last Modified: 15 Apr 2026

    SOCA Access Control System 180612 contains multiple SQL injection vulnerabilities that allow attackers to manipulate database queries through unvalidated POST parameters. Attackers can bypass authentication, retrieve password hashes, and gain administrative access with full system privileges by exploiting injection flaws in Login.php and Card_Edit_GetJson.php.

    Published: 24 Dec 2025
    5.1
    Medium

    CVE-2018-25127

    Last Modified: 15 Apr 2026

    SOCA Access Control System 180612 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without proper request validation. Attackers can craft malicious web pages that submit forged requests to create admin accounts by tricking logged-in users into visiting a malicious site.

    Published: 24 Dec 2025
    6.2
    Medium

    CVE-2025-36154

    Last Modified: 30 Dec 2025

    IBM Concert 1.0.0 through 2.1.0 stores sensitive information in cleartext during recursive docker builds which could be obtained by a local user.

    Published: 24 Dec 2025
    7.2
    High

    CVE-2025-2515

    Last Modified: 29 Jun 2026

    A vulnerability was found in BlueChi, a multi-node systemd service controller used in RHIVOS. This flaw allows a user with root privileges on a managed node (qm) to create or override systemd service unit files that affect the host node. This issue can lead to privilege escalation, unauthorized service execution, and potential system compromise.

    Published: 24 Dec 2025
    8.7
    High

    CVE-2025-43876

    Last Modified: 15 Apr 2026

    Under certain circumstances a successful exploitation could result in access to the device.

    Published: 24 Dec 2025
    8.7
    High

    CVE-2025-43875

    Last Modified: 15 Apr 2026

    Under certain circumstances a successful exploitation could result in access to the device.

    Published: 24 Dec 2025
    8.8
    High

    CVE-2025-2155

    Last Modified: 6 Jun 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Echo Call Center Services Trade and Industry Inc. Specto CM allows Remote Code Inclusion. This issue affects Specto CM: before 17032025.

    Published: 24 Dec 2025
    5.4
    Medium

    CVE-2025-2154

    Last Modified: 6 Jun 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Echo Call Center Services Trade and Industry Inc. Specto CM allows Stored XSS. This issue affects Specto CM: before 17032025.

    Published: 24 Dec 2025
    5.3
    Medium

    CVE-2025-68606

    Last Modified: 24 Apr 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPXPO PostX ultimate-post allows Retrieve Embedded Sensitive Data.This issue affects PostX: from n/a through <= 5.0.3.

    Published: 24 Dec 2025
    6.5
    Medium

    CVE-2025-68605

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Stored XSS.This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.3.23.

    Published: 24 Dec 2025
    5.4
    Medium

    CVE-2025-68603

    Last Modified: 27 Apr 2026

    Missing Authorization vulnerability in Marketing Fire Editorial Calendar editorial-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Editorial Calendar: from n/a through <= 3.8.8.

    Published: 24 Dec 2025
    4.7
    Medium

    CVE-2025-68602

    Last Modified: 24 Apr 2026

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Scott Paterson Accept Donations with PayPal & Stripe easy-paypal-donation allows Phishing.This issue affects Accept Donations with PayPal & Stripe: from n/a through <= 1.5.2.

    Published: 24 Dec 2025
    5.4
    Medium

    CVE-2025-68601

    Last Modified: 27 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Cross Site Request Forgery.This issue affects Five Star Restaurant Reservations: from n/a through <= 2.7.8.

    Published: 24 Dec 2025
    4.9
    Medium

    CVE-2025-68600

    Last Modified: 27 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in Yannick Lefebvre Link Library link-library allows Server Side Request Forgery.This issue affects Link Library: from n/a through <= 7.8.7.

    Published: 24 Dec 2025
    6.5
    Medium

    CVE-2025-68599

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Embeds For YouTube Plugin Support YouTube Embed youtube-embed allows Stored XSS.This issue affects YouTube Embed: from n/a through <= 5.4.

    Published: 24 Dec 2025
    6.5
    Medium

    CVE-2025-68598

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiveComposer Page Builder: Live Composer live-composer-page-builder allows Stored XSS.This issue affects Page Builder: Live Composer: from n/a through <= 2.1.13.

    Published: 24 Dec 2025
    6.5
    Medium

    CVE-2025-68597

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BlueGlass Interactive AG Jobs for WordPress job-postings allows Stored XSS.This issue affects Jobs for WordPress: from n/a through <= 2.8.1.

    Published: 24 Dec 2025
    5.3
    Medium

    CVE-2025-68596

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in Bit Apps Bit Assist bit-assist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bit Assist: from n/a through <= 1.5.11.

    Published: 24 Dec 2025
    5.3
    Medium

    CVE-2025-68595

    Last Modified: 27 Apr 2026

    Missing Authorization vulnerability in Trustindex Widgets for Social Photo Feed social-photo-feed-widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Widgets for Social Photo Feed: from n/a through <= 1.8.

    Published: 24 Dec 2025
    5.3
    Medium

    CVE-2025-68594

    Last Modified: 27 Apr 2026

    Missing Authorization vulnerability in Opinion Stage Poll, Survey & Quiz Maker Plugin by Opinion Stage social-polls-by-opinionstage allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Poll, Survey & Quiz Maker Plugin by Opinion Stage: from n/a through <= 19.12.0.

    Published: 24 Dec 2025
    5.4
    Medium

    CVE-2025-68593

    Last Modified: 27 Apr 2026

    Missing Authorization vulnerability in Liton Arefin WP Adminify adminify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Adminify: from n/a through <= 4.0.6.1.

    Published: 24 Dec 2025
    4.3
    Medium

    CVE-2025-68592

    Last Modified: 27 Apr 2026

    Missing Authorization vulnerability in Liton Arefin WP Adminify adminify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Adminify: from n/a through <= 4.0.6.1.

    Published: 24 Dec 2025
    5.4
    Medium

    CVE-2025-68591

    Last Modified: 27 Apr 2026

    Missing Authorization vulnerability in Mitchell Bennis Simple File List simple-file-list allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple File List: from n/a through <= 6.1.18.

    Published: 24 Dec 2025
    7.6
    High

    CVE-2025-68590

    Last Modified: 27 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks Integration for Contact Form 7 HubSpot cf7-hubspot allows Blind SQL Injection.This issue affects Integration for Contact Form 7 HubSpot: from n/a through <= 1.4.2.

    Published: 24 Dec 2025
    5.3
    Medium

    CVE-2025-68589

    Last Modified: 27 Apr 2026

    Missing Authorization vulnerability in WP Socio WP Telegram Widget and Join Link wptelegram-widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Telegram Widget and Join Link: from n/a through <= 2.2.12.

    Published: 24 Dec 2025
    4.3
    Medium

    CVE-2025-68588

    Last Modified: 27 Apr 2026

    Missing Authorization vulnerability in totalsoft TS Poll poll-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TS Poll: from n/a through <= 2.5.5.

    Published: 24 Dec 2025
    4.3
    Medium

    CVE-2025-68587

    Last Modified: 27 Apr 2026

    Missing Authorization vulnerability in Bob Watu Quiz watu allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Watu Quiz: from n/a through <= 3.4.5.

    Published: 24 Dec 2025
    5.3
    Medium

    CVE-2025-68586

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in Gora Tech Cooked cooked allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cooked: from n/a through <= 1.11.3.

    Published: 24 Dec 2025
    2.7
    Low

    CVE-2025-68585

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Ben Balter WP Document Revisions wp-document-revisions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Document Revisions: from n/a through <= 3.7.2.

    Published: 24 Dec 2025
    4.3
    Medium

    CVE-2025-68584

    Last Modified: 24 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Constantin Boiangiu Vimeotheque codeflavors-vimeo-video-post-lite allows Cross Site Request Forgery.This issue affects Vimeotheque: from n/a through <= 2.3.5.2.

    Published: 24 Dec 2025
    4.3
    Medium

    CVE-2025-68583

    Last Modified: 27 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Tikweb Management Fast User Switching fast-user-switching allows Cross Site Request Forgery.This issue affects Fast User Switching: from n/a through <= 1.4.10.

    Published: 24 Dec 2025
    5.3
    Medium

    CVE-2025-68582

    Last Modified: 27 Apr 2026

    Missing Authorization vulnerability in Funnelforms Funnelforms Free funnelforms-free allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Funnelforms Free: from n/a through <= 3.8.

    Published: 24 Dec 2025
    5.4
    Medium

    CVE-2025-68581

    Last Modified: 27 Apr 2026

    Missing Authorization vulnerability in YITHEMES YITH Slider for page builders yith-slider-for-page-builders allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YITH Slider for page builders: from n/a through <= 1.0.11.

    Published: 24 Dec 2025
    4.3
    Medium

    CVE-2025-68580

    Last Modified: 27 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in pluginsware Advanced Classifieds & Directory Pro advanced-classifieds-and-directory-pro allows Cross Site Request Forgery.This issue affects Advanced Classifieds & Directory Pro: from n/a through <= 3.2.9.

    Published: 24 Dec 2025
    5.3
    Medium

    CVE-2025-68579

    Last Modified: 27 Apr 2026

    Missing Authorization vulnerability in FolioVision FV Simpler SEO fv-all-in-one-seo-pack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FV Simpler SEO: from n/a through <= 1.9.6.

    Published: 24 Dec 2025
    5.3
    Medium

    CVE-2025-68578

    Last Modified: 27 Apr 2026

    Missing Authorization vulnerability in Addonify Addonify addonify-quick-view allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Addonify: from n/a through <= 2.0.4.

    Published: 24 Dec 2025