CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2025-10223

    Last Modified: 8 Oct 2025

    Insufficient Session Expiration (CWE-613) in the Web Admin Panel in AxxonSoft Axxon One (C-Werk) prior to 2.0.3 on Windows allows a local or remote authenticated attacker to retain access with removed privileges via continued use of an unexpired session token until natural expiration.

    Published: 10 Sept 2025
    4.8
    Medium

    CVE-2025-10222

    Last Modified: 8 Oct 2025

    Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the diagnostic dump component in AxxonSoft Axxon One VMS (C-Werk) 2.0.0 through 2.0.1 on Windows allows a local attacker to obtain licensing-related information such as timestamps, license states, and registry values via reading diagnostic export files created by the built-in troubleshooting tool.

    Published: 10 Sept 2025
    6.7
    Medium

    CVE-2025-10221

    Last Modified: 19 Dec 2025

    Insertion of Sensitive Information into Log File (CWE-532) in the ARP Agent component in AxxonSoft Axxon One / AxxonNet / C-WerkNet 2.0.4 and earlier on Windows platforms allows a local attacker to obtain plaintext credentials via reading TRACE log files containing serialized JSON with passwords.

    Published: 10 Sept 2025
    9.3
    Critical

    CVE-2025-10220

    Last Modified: 19 Dec 2025

    Use of Unmaintained Third Party Components (CWE-1104) in the NuGet dependency components in AxxonSoft Axxon One VMS 2.0.0 through 2.0.4 on Windows allows a remote attacker to execute arbitrary code or bypass security features via exploitation of vulnerable third-party packages such as Google.Protobuf, DynamicData, System.Runtime.CompilerServices.Unsafe, and others.

    Published: 10 Sept 2025
    Unknown

    CVE-2025-10219

    Last Modified: 10 Sept 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 10 Sept 2025
    8.8
    High

    CVE-2025-7718

    Last Modified: 20 Apr 2026

    The Resideo Plugin for Resideo - Real Estate WordPress Theme plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.5.4. This is due to the plugin not properly validating a user's identity prior to updating their details like email. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account.

    Published: 10 Sept 2025
    5.1
    Medium

    CVE-2025-40725

    Last Modified: 15 Apr 2026

    Reflected Cross-Site Scripting (XSS) vulnerability in Azon Dominator. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL using the “q” parameter in /search via GET. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.

    Published: 10 Sept 2025
    7
    High

    CVE-2025-10215

    Last Modified: 20 Jan 2026

    DLL search path hijacking vulnerability in the UPDF.exe executable for Windows version 1.8.5.0 allows attackers with local access to execute arbitrary code by placing a FREngine.dll file of their choice in the 'C:\Users\Public\AppData\Local\UPDF\FREngine\Bin64\' directory, which could lead to arbitrary code execution and persistence.

    Published: 10 Sept 2025
    7
    High

    CVE-2025-10214

    Last Modified: 29 Jan 2026

    DLL search path hijacking vulnerability in the UPDF.exe executable for Windows version 1.8.5.0 allows attackers with local access to execute arbitrary code by placing a FREngine.dll file of their choice in the 'C:\Users\<user>\AppData\Local\UPDF\FREngine\Bin64\' directory, which could lead to arbitrary code execution and persistence.

    Published: 10 Sept 2025
    7
    High

    CVE-2025-10213

    Last Modified: 29 Jan 2026

    DLL search path hijacking vulnerability in the UPDF.exe executable for Windows version 1.8.5.0 allows attackers with local access to execute arbitrary code by placing a dxtn.dll file of their choice in the 'C:\Users\<user>\AppData\Local\Microsoft\WindowsApps\' directory, which could lead to arbitrary code execution and persistence.

    Published: 10 Sept 2025
    7
    High

    CVE-2025-40979

    Last Modified: 15 Apr 2026

    DLL search order hijacking vulnerability in the wave.exe executable for Windows 11, version 1.27.8. Exploitation of this vulnerability could allow attackers with local access to execute arbitrary code by placing an arbitrary file in the 'C:\Users<user>\AppData\Local\Temp' directory, which could lead to arbitrary code execution and persistence. This vulnerability is only replicable in versions of Windows 11 and does not affect earlier versions.

    Published: 10 Sept 2025
    8.7
    High

    CVE-2025-36759

    Last Modified: 15 Apr 2026

    Through the provision of user names, SolaX Cloud will suggest (similar) user accounts and thereby leak sensitive information such as user email addresses and phone numbers.

    Published: 10 Sept 2025
    6.3
    Medium

    CVE-2025-36757

    Last Modified: 15 Apr 2026

    It is possible to bypass the administrator login screen on SolaX Cloud. An attacker could use parameter tampering to bypass the login screen and gain limited access to the system.

    Published: 10 Sept 2025
    6.3
    Medium

    CVE-2025-36758

    Last Modified: 15 Apr 2026

    It is possible to bypass the clipping level of authentication attempts in SolaX Cloud through the use of the 'Forgot Password' functionality as an oracle.

    Published: 10 Sept 2025
    5.8
    Medium

    CVE-2025-36756

    Last Modified: 15 Apr 2026

    A problem with missing authorization on SolaX Cloud platform allows taking over any SolaX solarpanel inverter of which the serial number is known.

    Published: 10 Sept 2025
    8.8
    High

    CVE-2025-41714

    Last Modified: 15 Apr 2026

    The upload endpoint insufficiently validates the 'Upload-Key' request header. By supplying path traversal sequences, an authenticated attacker can cause the server to create upload-related artifacts outside the intended storage location. In certain configurations this enables arbitrary file write and may be leveraged to achieve remote code execution.

    Published: 10 Sept 2025
    9.1
    Critical

    CVE-2025-9943

    Last Modified: 15 Apr 2026

    An SQL injection vulnerability has been identified in the "ID" attribute of the SAML response when the replay cache of the Shibboleth Service Provider (SP) is configured to use an SQL database as storage service. An unauthenticated attacker can exploit this issue via blind SQL injection, allowing for the extraction of arbitrary data from the database, if the database connection is configured to use the ODBC plugin. The vulnerability arises from insufficient escaping of single quotes in the class SQLString (file odbc-store.cpp, lines 253-271). This issue affects Shibboleth Service Provider through 3.5.0.

    Published: 10 Sept 2025
    4.9
    Medium

    CVE-2025-10142

    Last Modified: 21 Apr 2026

    The PagBank / PagSeguro Connect para WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'status' parameter in all versions up to, and including, 4.44.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 10 Sept 2025
    6.4
    Medium

    CVE-2025-9857

    Last Modified: 20 Apr 2026

    The Heateor Login – Social Login Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Heateor_Facebook_Login' shortcode in all versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 10 Sept 2025
    6.4
    Medium

    CVE-2025-10126

    Last Modified: 21 Apr 2026

    The MyBrain Utilities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugins's 'mbumap' shortcode in all versions up to, and including, 1.0.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 10 Sept 2025
    7.2
    High

    CVE-2025-10001

    Last Modified: 21 Apr 2026

    The Import any XML, CSV or Excel File to WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the import functionality in all versions up to, and including, 3.9.3. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload unsafe files like .phar files on the affected site's server which may make remote code execution possible.

    Published: 10 Sept 2025
    4.3
    Medium

    CVE-2025-9888

    Last Modified: 20 Apr 2026

    The Maspik – Ultimate Spam Protection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.6. This is due to missing or incorrect nonce validation on the clear_log function. This makes it possible for unauthenticated attackers to clear all spam logs via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 10 Sept 2025
    4.3
    Medium

    CVE-2025-9622

    Last Modified: 21 Apr 2026

    The WP Blast | SEO & Performance Booster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.6. This is due to missing or incorrect nonce validation on multiple administrative actions in the Settings class. This makes it possible for unauthenticated attackers to trigger cache purging, sitemap clearing, plugin data purging, and score resetting operations via forged requests granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 10 Sept 2025
    7.7
    High

    CVE-2025-10040

    Last Modified: 22 Apr 2026

    The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_ftp_details' AJAX action in all versions up to, and including, 7.27. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve a configured set of SFTP/FTP credentials.

    Published: 10 Sept 2025
    6.4
    Medium

    CVE-2025-7843

    Last Modified: 21 Apr 2026

    The Auto Save Remote Images (Drafts) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.9 via the fetch_images() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

    Published: 10 Sept 2025
    6.5
    Medium

    CVE-2025-7826

    Last Modified: 21 Apr 2026

    The Testimonial plugin for WordPress is vulnerable to SQL Injection via the 'iNICtestimonial' shortcode in all versions up to, and including, 2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 10 Sept 2025
    5.5
    Medium

    CVE-2025-9367

    Last Modified: 21 Apr 2026

    The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 2.11.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 10 Sept 2025
    4.3
    Medium

    CVE-2025-9979

    Last Modified: 21 Apr 2026

    The Maspik plugin for WordPress is vulnerable to Missing Authorization in version 2.5.6 and prior. This is due to missing capability checks on the Maspik_spamlog_download_csv function. This makes it possible for authenticated attackers, with subscriber-level access and above, to export and download the spam log database containing blocked submission attempts, which may include misclassified but legitimate submissions with sensitive data.

    Published: 10 Sept 2025
    4.3
    Medium

    CVE-2025-8778

    Last Modified: 21 Apr 2026

    The NitroPack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the nitropack_set_compression_ajax() function in all versions up to, and including, 1.18.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the nitropack-enableCompression option and effectively change plugin compression settings.

    Published: 10 Sept 2025
    6.5
    Medium

    CVE-2025-9463

    Last Modified: 21 Apr 2026

    The Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_by’ parameter in all versions up to, and including, 1.117.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 10 Sept 2025
    6.5
    Medium

    CVE-2025-6189

    Last Modified: 22 Apr 2026

    The Duplicate Page and Post plugin for WordPress is vulnerable to time-based SQL Injection via the ‘meta_key’ parameter in all versions up to, and including, 2.9.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 10 Sept 2025
    8.8
    High

    CVE-2025-7049

    Last Modified: 22 Apr 2026

    The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 67.7.0 via the 'MJ_gmgt_gmgt_add_user' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change the email, password, and other details of any user, including Administrator users.

    Published: 10 Sept 2025
    7.2
    High

    CVE-2025-10049

    Last Modified: 22 Apr 2026

    The Responsive Filterable Portfolio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the HdnMediaSelection_image field in all versions up to, and including, 1.0.24. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

    Published: 10 Sept 2025
    6.4
    Medium

    CVE-2025-8388

    Last Modified: 22 Apr 2026

    The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cursor_url’ parameter in all versions up to, and including, 2.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 10 Sept 2025
    2.1
    Low

    CVE-2025-10197

    Last Modified: 15 Apr 2026

    A vulnerability was found in HJSoft HCM Human Resources Management System up to 20250822. Affected by this vulnerability is an unknown functionality of the file /templates/attestation/../../selfservice/lawresource/downlawbase. Performing manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 10 Sept 2025
    1.9
    Low

    CVE-2025-10195

    Last Modified: 15 Apr 2026

    A vulnerability has been found in Seismic App 2.4.2 on Android. Affected is an unknown function of the file AndroidManifest.xml of the component com.seismic.doccenter. Such manipulation leads to improper export of android application components. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 10 Sept 2025
    5.7
    Medium

    CVE-2025-56578

    Last Modified: 15 Apr 2026

    An issue in RTSPtoWeb v.2.4.3 allows a remote attacker to obtain sensitive information and executearbitrary code via the lack of authentication mechanisms

    Published: 10 Sept 2025
    5.6
    Medium

    CVE-2025-29592

    Last Modified: 19 Nov 2025

    oasys v1.1 is vulnerable to Directory Traversal in ProcedureController.

    Published: 10 Sept 2025
    7.5
    High

    CVE-2025-56406

    Last Modified: 15 Apr 2026

    An issue was discovered in mcp-neo4j 0.3.0 allowing attackers to obtain sensitive information or execute arbitrary commands via the SSE service. NOTE: the Supplier's position is that authentication is not mandatory for MCP servers, and the mcp-neo4j MCP server is only intended for use in a local environment where authentication realistically would not be needed. Also, the Supplier provides middleware to help isolate the MCP server from external access (if needed).

    Published: 10 Sept 2025
    6.1
    Medium

    CVE-2025-57520

    Last Modified: 16 Sept 2025

    A Cross Site Scripting (XSS) vulnerability exists in Decap CMS thru 3.8.3. Input fields such as body, tags, title, and description are not properly sanitized before being rendered in the content preview pane. This enables an attacker to inject arbitrary JavaScript which executes whenever a user views the preview panel. The vulnerability affects multiple input vectors and does not require user interaction beyond viewing the affected content.

    Published: 10 Sept 2025
    5.6
    Medium

    CVE-2025-57572

    Last Modified: 17 Sept 2025

    Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the onlineList parameter in goform/setParentControl.

    Published: 10 Sept 2025
    8.4
    High

    CVE-2025-55976

    Last Modified: 17 Oct 2025

    Intelbras IWR 3000N 1.9.8 exposes the Wi-Fi password in plaintext via the /api/wireless endpoint. Any unauthenticated user on the local network can directly obtain the Wi-Fi network password by querying this endpoint.

    Published: 10 Sept 2025
    8.8
    High

    CVE-2025-56407

    Last Modified: 6 Oct 2025

    A vulnerability has been found in HuangDou UTCMS V9 and classified as critical. This vulnerability affects the function RunSql of the file app/modules/ut-data/admin/mysql.php. The manipulation of the argument sql leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 10 Sept 2025
    7.5
    High

    CVE-2025-56466

    Last Modified: 6 Oct 2025

    Hardcoded credentials in Dietly v1.25.0 for android allows attackers to gain sensitive information.

    Published: 10 Sept 2025
    7.8
    High

    CVE-2025-50892

    Last Modified: 20 Oct 2025

    The eudskacs.sys driver version 20250328 shipped with EaseUs Todo Backup 1.2.0.1 fails to properly validate privileges for I/O requests (IRP_MJ_READ/IRP_MJ_WRITE) sent to its device object. This allows a local, low-privileged attacker to perform arbitrary raw disk reads and writes, leading to sensitive information disclosure, denial of service, or local privilege escalation.

    Published: 10 Sept 2025
    7.5
    High

    CVE-2025-56404

    Last Modified: 17 Sept 2025

    An issue was discovered in MariaDB MCP 0.1.0 allowing attackers to gain sensitive information via the SSE service as the SSE service lacks user validation.

    Published: 10 Sept 2025
    7.5
    High

    CVE-2025-56405

    Last Modified: 17 Sept 2025

    An issue was discovered in litmusautomation litmus-mcp-server thru 0.0.1 allowing unauthorized attackers to control the target's MCP service through the SSE protocol.

    Published: 10 Sept 2025
    7.8
    High

    CVE-2025-57392

    Last Modified: 17 Sept 2025

    BenimPOS Masaustu 3.0.x is affected by insecure file permissions. The application installation directory grants Everyone and BUILTIN\Users groups FILE_ALL_ACCESS, allowing local users to replace or modify .exe and .dll files. This may lead to privilege escalation or arbitrary code execution upon launch by another user or elevated context.

    Published: 10 Sept 2025
    5.6
    Medium

    CVE-2025-57569

    Last Modified: 17 Sept 2025

    Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the portList parameter in /goform/setNAT.

    Published: 10 Sept 2025
    5.6
    Medium

    CVE-2025-57570

    Last Modified: 17 Sept 2025

    Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the QosList parameter in goform/setQoS.

    Published: 10 Sept 2025