CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2025-54031

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Schiocco Support Board supportboard allows PHP Local File Inclusion.This issue affects Support Board: from n/a through <= 3.8.0.

    Published: 20 Aug 2025
    7.1
    High

    CVE-2025-54032

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebCodingPlace Real Estate Manager Pro real-estate-manager-pro allows Reflected XSS.This issue affects Real Estate Manager Pro: from n/a through <= 12.7.3.

    Published: 20 Aug 2025
    7.5
    High

    CVE-2025-54034

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Tribulant Software Newsletters newsletters-lite allows PHP Local File Inclusion.This issue affects Newsletters: from n/a through <= 4.10.

    Published: 20 Aug 2025
    6.5
    Medium

    CVE-2025-54040

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Webba Appointment Booking Webba Booking webba-booking-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Webba Booking: from n/a through <= 5.1.20.

    Published: 20 Aug 2025
    7.1
    High

    CVE-2025-54044

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in _CreativeMedia_ Elite Video Player elite-video-player allows Reflected XSS.This issue affects Elite Video Player: from n/a through <= 10.0.5.

    Published: 20 Aug 2025
    6.5
    Medium

    CVE-2025-54046

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs Cost Calculator ql-cost-calculator allows Stored XSS.This issue affects Cost Calculator: from n/a through <= 7.4.

    Published: 20 Aug 2025
    9.3
    Critical

    CVE-2025-54048

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in miniOrange Custom API for WP custom-api-for-wp allows SQL Injection.This issue affects Custom API for WP: from n/a through <= 4.2.2.

    Published: 20 Aug 2025
    9.9
    Critical

    CVE-2025-54049

    Last Modified: 23 Apr 2026

    Incorrect Privilege Assignment vulnerability in miniOrange Custom API for WP custom-api-for-wp allows Privilege Escalation.This issue affects Custom API for WP: from n/a through <= 4.2.2.

    Published: 20 Aug 2025
    7.5
    High

    CVE-2025-54052

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Realtyna Realtyna Organic IDX plugin real-estate-listing-realtyna-wpl allows PHP Local File Inclusion.This issue affects Realtyna Organic IDX plugin: from n/a through <= 5.0.0.

    Published: 20 Aug 2025
    6.6
    Medium

    CVE-2025-54053

    Last Modified: 23 Apr 2026

    Deserialization of Untrusted Data vulnerability in Adrian Tobey Groundhogg groundhogg allows Object Injection.This issue affects Groundhogg: from n/a through <= 4.2.2.

    Published: 20 Aug 2025
    7.1
    High

    CVE-2025-54055

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Druco druco allows Reflected XSS.This issue affects Druco: from n/a through <= 1.5.2.

    Published: 20 Aug 2025
    7.1
    High

    CVE-2025-54056

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Responsive HTML5 Audio Player PRO With Playlist lbg-audio2-html5 allows Reflected XSS.This issue affects Responsive HTML5 Audio Player PRO With Playlist: from n/a through <= 3.5.8.

    Published: 20 Aug 2025
    7.1
    High

    CVE-2025-54670

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bobbingwide oik oik allows Reflected XSS.This issue affects oik: from n/a through <= 4.15.2.

    Published: 20 Aug 2025
    9.1
    Critical

    CVE-2025-54677

    Last Modified: 23 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows Using Malicious Files.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through <= 4.5.3.

    Published: 20 Aug 2025
    9.8
    Critical

    CVE-2025-54713

    Last Modified: 23 Apr 2026

    Authentication Bypass Using an Alternate Path or Channel vulnerability in magepeopleteam Taxi Booking Manager for WooCommerce ecab-taxi-booking-manager allows Authentication Abuse.This issue affects Taxi Booking Manager for WooCommerce: from n/a through <= 1.3.0.

    Published: 20 Aug 2025
    9.3
    Critical

    CVE-2025-54726

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Miguel Useche JS Archive List jquery-archive-list-widget allows SQL Injection.This issue affects JS Archive List: from n/a through < 6.1.6.

    Published: 20 Aug 2025
    8.8
    High

    CVE-2025-54735

    Last Modified: 23 Apr 2026

    Incorrect Privilege Assignment vulnerability in Imran Tauqeer CubeWP cubewp-framework allows Privilege Escalation.This issue affects CubeWP: from n/a through <= 1.1.24.

    Published: 20 Aug 2025
    7.5
    High

    CVE-2025-54750

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Aman Funnel Builder by FunnelKit funnel-builder allows PHP Local File Inclusion.This issue affects Funnel Builder by FunnelKit: from n/a through <= 3.11.1.

    Published: 20 Aug 2025
    7.5
    High

    CVE-2025-55715

    Last Modified: 23 Apr 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in Themeisle Otter - Gutenberg Block otter-blocks allows Retrieve Embedded Sensitive Data.This issue affects Otter - Gutenberg Block: from n/a through <= 3.1.0.

    Published: 20 Aug 2025
    5.5
    Medium

    CVE-2025-9225

    Last Modified: 15 Apr 2026

    Stored cross-site scripting (XSS) in the web interface of MiR software versions prior to 3.0.0 on MiR Robots and MiR Fleet allows execution of arbitrary JavaScript code in a victim’s browser

    Published: 20 Aug 2025
    4.3
    Medium

    CVE-2025-9202

    Last Modified: 20 Apr 2026

    The ColorMag theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the welcome_notice_import_handler() function in all versions up to, and including, 4.0.19. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install the ThemeGrill Demo Importer plugin.

    Published: 20 Aug 2025
    5.3
    Medium

    CVE-2025-54551

    Last Modified: 15 Apr 2026

    Synapse Mobility 8.0, 8.0.1, 8.0.2, 8.1, and 8.1.1 contain a privilege escalation vulnerability through external control of Web parameter. If exploited, a user of the product may escalate the privilege and access data that the user do not have permission to view by altering the parameters of the search function.

    Published: 20 Aug 2025
    6.4
    Medium

    CVE-2025-8618

    Last Modified: 22 Apr 2026

    The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woosq_btn shortcode in all versions up to, and including, 4.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 20 Aug 2025
    5.1
    Medium

    CVE-2025-55706

    Last Modified: 15 Apr 2026

    URL redirection to untrusted site ('Open Redirect') issue exists in Movable Type. If this vulnerability is exploited, an invalid parameter may be inserted into the password reset page, which may lead to redirection to an arbitrary URL.

    Published: 20 Aug 2025
    6.9
    Medium

    CVE-2025-53522

    Last Modified: 15 Apr 2026

    Movable Type contains an issue with use of less trusted source. If exploited, tampered email to reset a password may be sent by a remote unauthenticated attacker.

    Published: 20 Aug 2025
    6.9
    Medium

    CVE-2025-57791

    Last Modified: 10 Sept 2025

    A security vulnerability has been identified that allows remote attackers to inject or manipulate command-line arguments passed to internal components due to insufficient input validation. Successful exploitation results in a valid user session for a low privilege role.

    Published: 20 Aug 2025
    8.7
    High

    CVE-2025-57790

    Last Modified: 11 Sept 2025

    A security vulnerability has been identified that allows remote attackers to perform unauthorized file system access through a path traversal issue. The vulnerability may lead to remote code execution.

    Published: 20 Aug 2025
    5.3
    Medium

    CVE-2025-57789

    Last Modified: 26 Feb 2026

    During the brief window between installation and the first administrator login, remote attackers may exploit the default credential to gain admin control. This is limited to the setup phase, before any jobs have been configured.

    Published: 20 Aug 2025
    8.8
    High

    CVE-2025-8141

    Last Modified: 20 Apr 2026

    The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_associated_files function in all versions up to, and including, 3.2.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

    Published: 20 Aug 2025
    7.5
    High

    CVE-2025-8289

    Last Modified: 20 Apr 2026

    The Redirection for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.2.4 via deserialization of untrusted input in the delete_associated_files function. This makes it possible for unauthenticated attackers to inject a PHP Object. This vulnerability may be exploited by unauthenticated attackers when a form is present on the site with a file upload action, and doesn't affect sites with PHP version > 8. This vulnerability also requires the 'Redirection For Contact Form 7 Extension - Create Post' extension to be installed and activated in order to be exploited. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present. We confirmed there is a usable gadget in Contact Form 7 plugin that makes arbitrary file deletion possible when installed with this plugin. Given Contact Form 7 is a requirement of this plugin, it is likely that any site with this plugin and the 'Redirection For Contact Form 7 Extension - Create Post' extension enabled is vulnerable to arbitrary file deletion.

    Published: 20 Aug 2025
    8.8
    High

    CVE-2025-8145

    Last Modified: 22 Apr 2026

    The Redirection for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.2.4 via deserialization of untrusted input in the get_lead_fields function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain in a Contact Form 7 plugin allows attackers to delete arbitrary files. Additionally, in certain server configurations, Remote Code Execution is possible

    Published: 20 Aug 2025
    9.3
    Critical

    CVE-2024-12223

    Last Modified: 15 Apr 2026

    Prism Central versions prior to 2024.3.1 are vulnerable to a stored cross-site scripting attack via the Events component, allowing an attacker to hijack a victim user’s session and perform actions in their security context.

    Published: 20 Aug 2025
    8.8
    High

    CVE-2025-9132

    Last Modified: 26 Feb 2026

    Out of bounds write in V8 in Google Chrome prior to 139.0.7258.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 20 Aug 2025
    2
    Low

    CVE-2025-9193

    Last Modified: 15 Apr 2026

    A flaw has been found in TOTVS Portal Meu RH up to 12.1.17. Impacted is an unknown function of the component Password Reset Handler. Executing manipulation of the argument redirectUrl can lead to open redirect. The attack may be performed from a remote location. The exploit has been published and may be used. Upgrading to version 12.1.2410.274, 12.1.2502.178 and 12.1.2506.121 is recommended to address this issue. It is recommended to upgrade the affected component. The vendor explains, that "[o]ur internal validation (...) confirms that the reported behavior does not exist in currently supported releases. In these tests, the redirectUrl parameter is ignored, and no malicious redirection occurs." This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 20 Aug 2025
    6.9
    Medium

    CVE-2025-54364

    Last Modified: 15 Apr 2026

    Microsoft Knack 0.12.0 allows Regular expression Denial of Service (ReDoS) in the knack.introspection module. option_descriptions employs an inefficient regular expression pattern: "\s(:param)\s+(.+?)\s:(.*)" that is susceptible to catastrophic backtracking when processing crafted docstrings containing a large volume of whitespace without a terminating colon. An attacker who can control or inject docstring content into affected applications can trigger excessive CPU consumption. This software is used by Azure CLI.

    Published: 20 Aug 2025
    6.9
    Medium

    CVE-2025-54363

    Last Modified: 15 Apr 2026

    Microsoft Knack 0.12.0 allows Regular expression Denial of Service (ReDoS) in the knack.introspection module. extract_full_summary_from_signature employs an inefficient regular expression pattern: "\s(:param)\s+(.+?)\s:(.*)" that is susceptible to catastrophic backtracking when processing crafted docstrings containing a large volume of whitespace without a terminating colon. An attacker who can control or inject docstring content into affected applications can trigger excessive CPU consumption. This software is used by Azure CLI.

    Published: 20 Aug 2025
    6.5
    Medium

    CVE-2025-50864

    Last Modified: 15 Apr 2026

    An Origin Validation Error in the elysia-cors library thru 1.3.0 allows attackers to bypass Cross-Origin Resource Sharing (CORS) restrictions. The library incorrectly validates the supplied origin by checking if it is a substring of any domain in the site's CORS policy, rather than performing an exact match. For example, a malicious origin like "notexample.com", "example.common.net" is whitelisted when the site's CORS policy specifies "example.com." This vulnerability enables unauthorized access to user data on sites using the elysia-cors library for CORS validation.

    Published: 20 Aug 2025
    8.8
    High

    CVE-2025-50503

    Last Modified: 15 Apr 2026

    A vulnerability in the password reset workflow of the Touch Lebanon Mobile App 2.20.2 allows an attacker to bypass the OTP reset password mechanism. By manipulating the reset process, an unauthorized user may be able to reset the password and gain access to the account without needing to provide a legitimate authentication factor, such as an OTP. This compromises account security and allows for potential unauthorized access to user data.

    Published: 20 Aug 2025
    8.8
    High

    CVE-2024-57491

    Last Modified: 15 Apr 2026

    Authentication Bypass vulnerability in jobx up to v1.0.1-RELEASE allows an attacker can exploit this vulnerability to access sensitive API without any token via the preHandle function.

    Published: 20 Aug 2025
    9.8
    Critical

    CVE-2024-57157

    Last Modified: 15 Apr 2026

    Incorrect access control in Jantent v1.1 allows attackers to bypass authentication and access sensitive APIs without a token.

    Published: 20 Aug 2025
    9.8
    Critical

    CVE-2024-57155

    Last Modified: 15 Apr 2026

    Incorrect access control in radar v1.0.8 allows attackers to bypass authentication and access sensitive APIs without a token.

    Published: 20 Aug 2025
    9.8
    Critical

    CVE-2024-50640

    Last Modified: 15 Apr 2026

    jeewx-boot 1.3 has an authentication bypass vulnerability in the preHandle function

    Published: 20 Aug 2025
    5.9
    Medium

    CVE-2025-8415

    Last Modified: 15 Apr 2026

    A vulnerability was found in the Cryostat HTTP API. Cryostat's HTTP API binds to all network interfaces, allowing possible external visibility and access to the API port if Network Policies are disabled, allowing an unauthenticated, malicious attacker to jeopardize the environment.

    Published: 20 Aug 2025
    4.8
    Medium

    CVE-2025-51990

    Last Modified: 11 Sept 2025

    XWiki through version 17.3.0 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities in the Administration interface, specifically under the Presentation section of the Global Preferences panel. An authenticated administrator can inject arbitrary JavaScript payloads into the HTTP Meta Info, Footer Copyright, and Footer Version fields. These inputs are stored and subsequently rendered without proper output encoding or sanitization on public-facing pages. As a result, the injected scripts are persistently executed in the browser context of any visitor to the affected instances including both authenticated and unauthenticated users. No user interaction is required beyond visiting a page that includes the malicious content. Successful exploitation can lead to session hijacking, credential theft, unauthorized actions via session riding, or further compromise of the application through client-side attacks. The vulnerability introduces significant risk in any deployment, especially in shared or internet-facing environments where administrator credentials may be compromised.

    Published: 20 Aug 2025
    7.5
    High

    CVE-2024-53495

    Last Modified: 11 Sept 2025

    Incorrect access control in the preHandle function of my-site v1.0.2.RELEASE allows attackers to access sensitive components without authentication.

    Published: 20 Aug 2025
    9.8
    Critical

    CVE-2024-57154

    Last Modified: 15 Apr 2026

    Incorrect access control in dts-shop v0.0.1-SNAPSHOT allows attackers to bypass authentication via sending a crafted payload to /admin/auth/index.

    Published: 20 Aug 2025
    7.5
    High

    CVE-2024-57152

    Last Modified: 11 Sept 2025

    Incorrect access control in the preHandle function of my-site v1.0.2 allows attackers to access sensitive components without authentication via the cn.luischen.interceptor.BaseInterceptor class

    Published: 20 Aug 2025
    8.6
    High

    CVE-2025-28041

    Last Modified: 10 Sept 2025

    Incorrect access control in the doFilter function of itranswarp up to 2.19 allows attackers to access sensitive components without authentication.

    Published: 20 Aug 2025
    9.8
    Critical

    CVE-2025-50901

    Last Modified: 11 Sept 2025

    JeeWMS 771e4f5d0c01ffdeae1671be4cf102b73a3fe644 (2025-05-19) contains incorrect authentication bypass vulnerability, which can lead to arbitrary file reading.

    Published: 20 Aug 2025
    9.8
    Critical

    CVE-2025-50904

    Last Modified: 11 Sept 2025

    There is an authentication bypass vulnerability in WinterChenS my-site thru commit 6c79286 (2025-06-11). An attacker can exploit this vulnerability to access /admin/ API without any token.

    Published: 20 Aug 2025