CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2025-8497

    Last Modified: 29 Sept 2025

    A weakness has been identified in code-projects Online Medicine Guide 1.0. This affects an unknown part of the file /cusfindphar2.php. This manipulation of the argument Search causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited.

    Published: 3 Aug 2025
    5.5
    Medium

    CVE-2025-8496

    Last Modified: 8 Aug 2025

    A vulnerability has been found in projectworlds Online Admission System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /viewform.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 3 Aug 2025
    5.5
    Medium

    CVE-2025-8495

    Last Modified: 8 Aug 2025

    A vulnerability, which was classified as critical, was found in code-projects Intern Membership Management System 1.0. Affected is an unknown function of the file /admin/edit_admin_query.php. The manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 3 Aug 2025
    3.7
    Low

    CVE-2025-54350

    Last Modified: 3 Nov 2025

    In iperf before 3.19.1, iperf_auth.c has a Base64Decode assertion failure and application exit upon a malformed authentication attempt.

    Published: 3 Aug 2025
    3.2
    Low

    CVE-2025-54956

    Last Modified: 15 Apr 2026

    The gh package before 1.5.0 for R delivers an HTTP response in a data structure that includes the Authorization header from the corresponding HTTP request.

    Published: 3 Aug 2025
    6.4
    Medium

    CVE-2025-52132

    Last Modified: 15 Apr 2026

    The Mocca Calendar application before 2.15 for XWiki allows XSS via a title to the view event page.

    Published: 3 Aug 2025
    6.4
    Medium

    CVE-2025-52133

    Last Modified: 15 Apr 2026

    The Mocca Calendar application before 2.15 for XWiki allows XSS via a title upon calendar import.

    Published: 3 Aug 2025
    8.9
    High

    CVE-2025-54351

    Last Modified: 17 Oct 2025

    In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).

    Published: 3 Aug 2025
    6.5
    Medium

    CVE-2025-54349

    Last Modified: 3 Nov 2025

    In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow.

    Published: 3 Aug 2025
    6.4
    Medium

    CVE-2025-52131

    Last Modified: 15 Apr 2026

    The Mocca Calendar application before 2.15 for XWiki allows XSS via the background or text color field.

    Published: 3 Aug 2025
    5.5
    Medium

    CVE-2025-8494

    Last Modified: 5 Aug 2025

    A vulnerability, which was classified as critical, has been found in code-projects Intern Membership Management System 1.0. This issue affects some unknown processing of the file /admin/delete_student.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 2 Aug 2025
    5.5
    Medium

    CVE-2025-8493

    Last Modified: 5 Aug 2025

    A vulnerability classified as critical was found in code-projects Intern Membership Management System 1.0. This vulnerability affects unknown code of the file /admin/edit_student_query.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 2 Aug 2025
    5.9
    Medium

    CVE-2023-32253

    Last Modified: 29 Jun 2026

    A flaw was found in the Linux kernel's ksmbd component. A deadlock is triggered by sending multiple concurrent session setup requests, possibly leading to a denial of service.

    Published: 2 Aug 2025
    5.3
    Medium

    CVE-2023-32255

    Last Modified: 29 Jun 2026

    A flaw was found in the Linux kernel's ksmbd component. A memory leak can occur if a client sends a session setup request with an unknown NTLMSSP message type, potentially leading to resource exhaustion.

    Published: 2 Aug 2025
    2.5
    Low

    CVE-2025-23290

    Last Modified: 15 Apr 2026

    NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a guest could get global GPU metrics which may be influenced by work in other VMs. A successful exploit of this vulnerability might lead to information disclosure.

    Published: 2 Aug 2025
    5.5
    Medium

    CVE-2025-23285

    Last Modified: 15 Apr 2026

    NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where it allows a guest to access global resources. A successful exploit of this vulnerability might lead to denial of service.

    Published: 2 Aug 2025
    7.8
    High

    CVE-2025-23284

    Last Modified: 15 Apr 2026

    NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause a stack buffer overflow. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, or data tampering.

    Published: 2 Aug 2025
    7.8
    High

    CVE-2025-23283

    Last Modified: 15 Apr 2026

    NVIDIA vGPU software for Linux-style hypervisors contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause stack buffer overflow. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.

    Published: 2 Aug 2025
    3.3
    Low

    CVE-2025-23288

    Last Modified: 15 Apr 2026

    NVIDIA GPU Display Driver for Windows contains a vulnerability  where an attacker may cause an exposure of sensitive system information with local unprivileged system access. A successful exploit of this vulnerability may lead to Information disclosure.

    Published: 2 Aug 2025
    3.3
    Low

    CVE-2025-23287

    Last Modified: 15 Apr 2026

    NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker may access sensitive system-level information. A successful exploit of this vulnerability may lead to Information disclosure.

    Published: 2 Aug 2025
    4.4
    Medium

    CVE-2025-23286

    Last Modified: 15 Apr 2026

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an attacker could read invalid memory. A successful exploit of this vulnerability might lead to information disclosure.

    Published: 2 Aug 2025
    7
    High

    CVE-2025-23281

    Last Modified: 15 Apr 2026

    NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker with local unprivileged access that can win a race condition might be able to trigger a use-after-free error. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, or information disclosure.

    Published: 2 Aug 2025
    7
    High

    CVE-2025-23279

    Last Modified: 15 Apr 2026

    NVIDIA .run Installer for Linux and Solaris contains a vulnerability where an attacker could use a race condition to escalate privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, denial of service, or data tampering.

    Published: 2 Aug 2025
    7.1
    High

    CVE-2025-23278

    Last Modified: 15 Apr 2026

    NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker might cause an improper index validation by issuing a call with crafted parameters. A successful exploit of this vulnerability might lead to data tampering  or denial of service.

    Published: 2 Aug 2025
    7.3
    High

    CVE-2025-23277

    Last Modified: 15 Apr 2026

    NVIDIA Display Driver for Linux and Windows contains a vulnerability in the kernel mode driver, where an attacker could access memory outside bounds permitted under normal use cases. A successful exploit of this vulnerability might lead to denial of service, data tampering, or information disclosure.

    Published: 2 Aug 2025
    7.8
    High

    CVE-2025-23276

    Last Modified: 15 Apr 2026

    NVIDIA Installer for Windows contains a vulnerability where an attacker may be able to escalate privileges. A successful exploit of this vulnerability may lead to escalation of privileges, denial of service, code execution, information disclosure and data tampering.

    Published: 2 Aug 2025
    5.5
    Medium

    CVE-2025-8471

    Last Modified: 5 Aug 2025

    A vulnerability, which was classified as critical, has been found in projectworlds Online Admission System 1.0. This issue affects some unknown processing of the file /adminlogin.php. The manipulation of the argument a_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 2 Aug 2025
    5.5
    Medium

    CVE-2025-8470

    Last Modified: 5 Aug 2025

    A vulnerability classified as critical was found in SourceCodester Online Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /admin/deleteroom.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 2 Aug 2025
    5.5
    Medium

    CVE-2025-8469

    Last Modified: 5 Aug 2025

    A vulnerability classified as critical has been found in SourceCodester Online Hotel Reservation System 1.0. This affects an unknown part of the file /admin/deletegallery.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 2 Aug 2025
    5.5
    Medium

    CVE-2025-8468

    Last Modified: 5 Aug 2025

    A vulnerability was found in code-projects Wazifa System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /controllers/reset.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 2 Aug 2025
    6.4
    Medium

    CVE-2025-7500

    Last Modified: 21 Apr 2026

    The Ocean Social Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via social icon titles in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 2 Aug 2025
    9.8
    Critical

    CVE-2025-7710

    Last Modified: 21 Apr 2026

    The Brave Conversion Engine (PRO) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 0.7.7. This is due to the plugin not properly restricting a claimed identity while authenticating with Facebook. This makes it possible for unauthenticated attackers to log in as other users, including administrators.

    Published: 2 Aug 2025
    5.5
    Medium

    CVE-2025-8467

    Last Modified: 5 Aug 2025

    A vulnerability was found in code-projects Wazifa System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /controllers/regcontrol.php. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 2 Aug 2025
    4.3
    Medium

    CVE-2025-8488

    Last Modified: 21 Apr 2026

    The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_hfe_compatibility_option_callback ()function in all versions up to, and including, 2.4.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the compatibility option setting.

    Published: 2 Aug 2025
    5.3
    Medium

    CVE-2025-6722

    Last Modified: 22 Apr 2026

    The BitFire Security – Firewall, WAF, Bot/Spam Blocker, Login Security plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5 via the bitfire_* directory that automatically gets created and stores potentially sensitive files without any access restrictions. This makes it possible for unauthenticated attackers to extract sensitive data from various files like config.ini, debug.log, and more when directory listing is enabled on the server and the ~/wp-content/plugins/index.php file is missing or ignored.

    Published: 2 Aug 2025
    5.5
    Medium

    CVE-2025-8466

    Last Modified: 5 Aug 2025

    A vulnerability was found in code-projects Online Farm System 1.0. It has been classified as critical. Affected is an unknown function of the file /forgot_passfarmer.php. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 2 Aug 2025
    6.4
    Medium

    CVE-2025-8391

    Last Modified: 20 Apr 2026

    The Magic Edge – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘height’ parameter in all versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 2 Aug 2025
    6.1
    Medium

    CVE-2025-8400

    Last Modified: 20 Apr 2026

    The Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 2 Aug 2025
    6.1
    Medium

    CVE-2025-6832

    Last Modified: 21 Apr 2026

    The All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nonce' parameter in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 2 Aug 2025
    6.4
    Medium

    CVE-2025-8399

    Last Modified: 22 Apr 2026

    The Mmm Unity Loader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘attributes’ parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 2 Aug 2025
    6.4
    Medium

    CVE-2025-8317

    Last Modified: 20 Apr 2026

    The Custom Word Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘angle’ parameter in all versions up to, and including, 0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 2 Aug 2025
    6.4
    Medium

    CVE-2025-4588

    Last Modified: 20 Apr 2026

    The 360 Photo Spheres plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sphere' shortcode in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 2 Aug 2025
    6.4
    Medium

    CVE-2025-8212

    Last Modified: 21 Apr 2026

    The Medical Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typewriter widget in all versions up to, and including, 1.6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 2 Aug 2025
    5.3
    Medium

    CVE-2025-8152

    Last Modified: 21 Apr 2026

    The WP CTA – Call To Action Plugin, Sticky CTA, Sticky Buttons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_cta_status' and 'change_sticky_sidebar_name' functions in all versions up to, and including, 1.7.0. This makes it possible for unauthenticated attackers to update the status of a sticky and update the name displayed in the back-end WP CTA Dashboard.

    Published: 2 Aug 2025
    4.4
    Medium

    CVE-2025-6626

    Last Modified: 22 Apr 2026

    The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the API URL Setting in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 2 Aug 2025
    8.8
    High

    CVE-2025-6754

    Last Modified: 22 Apr 2026

    The SEO Metrics plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks in both the seo_metrics_handle_connect_button_click() AJAX handler and the seo_metrics_handle_custom_endpoint() function in all versions up to, and including, 1.0.15. Because the AJAX action only verifies a nonce, without checking the caller’s capabilities, a subscriber-level user can retrieve the token and then access the custom endpoint to obtain full administrator cookies.

    Published: 2 Aug 2025
    6.4
    Medium

    CVE-2025-8146

    Last Modified: 15 Apr 2026

    The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's TypeOut Text widget in all versions up to, and including, 1.9.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 2 Aug 2025
    6.8
    Medium

    CVE-2025-7694

    Last Modified: 21 Apr 2026

    The Woffice Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the woffice_file_manager_delete() function in all versions up to, and including, 5.4.26. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

    Published: 2 Aug 2025
    5.4
    Medium

    CVE-2025-6078

    Last Modified: 15 Apr 2026

    Partner Software's Partner Software application and Partner Web application allows an authenticated user to add notes on the 'Notes' page when viewing a job but does not completely sanitize input, making it possible to add notes with HTML tags and JavaScript, enabling an attacker to add a note containing malicious JavaScript, leading to stored XSS (cross-site scripting).

    Published: 2 Aug 2025
    9.8
    Critical

    CVE-2025-6077

    Last Modified: 15 Apr 2026

    Partner Software's Partner Software Product and corresponding Partner Web application use the same default username and password for the administrator account across all versions.

    Published: 2 Aug 2025