CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2014-125121

    Last Modified: 15 Apr 2026

    Array Networks vAPV (version 8.3.2.17) and vxAG (version 9.2.0.34) appliances are affected by a privilege escalation vulnerability caused by a combination of hardcoded SSH credentials (or SSH private key) and insecure permissions on a startup script. The devices ship with a default SSH login or a hardcoded DSA private key, allowing an attacker to authenticate remotely with limited privileges. Once authenticated, an attacker can overwrite the world-writable /ca/bin/monitor.sh script with arbitrary commands. Since this script is executed with elevated privileges through the backend binary, enabling the debug monitor via backend -c "debug monitor on" triggers execution of the attacker's payload as root. This allows full system compromise.

    Published: 31 Jul 2025
    8.8
    High

    CVE-2014-125125

    Last Modified: 15 Apr 2026

    A path traversal vulnerability exists in A10 Networks AX Loadbalancer versions 2.6.1-GR1-P5, 2.7.0, and earlier. The vulnerability resides in the handling of the filename parameter in the /xml/downloads endpoint, which fails to properly sanitize user input. An unauthenticated attacker can exploit this flaw by sending crafted HTTP requests containing directory traversal sequences to read arbitrary files outside the intended directory. The files returned by the vulnerable endpoint are deleted from the system after retrieval. This can lead to unauthorized disclosure of sensitive information such as SSL certificates and private keys, as well as unintended file deletion.

    Published: 31 Jul 2025
    5.5
    Medium

    CVE-2025-8407

    Last Modified: 5 Aug 2025

    A vulnerability, which was classified as critical, has been found in code-projects Vehicle Management 1.0. This issue affects some unknown processing of the file /filter2.php. The manipulation of the argument from leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Jul 2025
    6.3
    Medium

    CVE-2025-54589

    Last Modified: 22 Sept 2025

    Copyparty is a portable file server. In versions 1.18.6 and below, when accessing the recent uploads page at `/?ru`, users can filter the results using an input field at the top. This field appends a filter parameter to the URL, which reflects its value directly into a `<script>` block without proper escaping, allowing for reflected Cross-Site Scripting (XSS) and can be exploited against both authenticated and unauthenticated users. This is fixed in version 1.18.7.

    Published: 31 Jul 2025
    7.2
    High

    CVE-2025-8213

    Last Modified: 21 Apr 2026

    The NinjaScanner – Virus & Malware scan plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'nscan_ajax_quarantine' and 'nscan_quarantine_select' functions in all versions up to, and including, 3.2.5. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary files on the server, including files outside the WordPress root directory.

    Published: 31 Jul 2025
    2.1
    Low

    CVE-2025-8382

    Last Modified: 6 Aug 2025

    A vulnerability, which was classified as critical, was found in Campcodes Online Hotel Reservation System 1.0. Affected is an unknown function of the file /admin/edit_room.php. The manipulation of the argument room_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Jul 2025
    2.1
    Low

    CVE-2025-8381

    Last Modified: 6 Aug 2025

    A vulnerability, which was classified as critical, has been found in Campcodes Online Hotel Reservation System 1.0. This issue affects some unknown processing of the file /add_reserve.php. The manipulation of the argument room_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Jul 2025
    4.3
    Medium

    CVE-2025-8068

    Last Modified: 20 Apr 2026

    The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification and loss of data due to an improper capability check on the 'ajax_trash_templates' function in all versions up to, and including, 2.9.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary attachment files, and move arbitrary posts, pages, and templates to the Trash.

    Published: 31 Jul 2025
    4.3
    Medium

    CVE-2025-8401

    Last Modified: 21 Apr 2026

    The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.1 via the 'get_post_data' function. This makes it possible for authenticated attackers, with Author-level access and above, to extract sensitive data including the content of private, password-protected, and draft posts and pages.

    Published: 31 Jul 2025
    4.3
    Medium

    CVE-2025-8151

    Last Modified: 21 Apr 2026

    The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.9.1 via the 'save_block_css' function. This makes it possible for authenticated attackers, with Author-level access and above, to create CSS files in any directory, and delete CSS files in any directory in a Windows environment.

    Published: 31 Jul 2025
    2
    Low

    CVE-2025-8380

    Last Modified: 6 Aug 2025

    A vulnerability classified as problematic was found in Campcodes Online Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /admin/add_query_account.php. The manipulation of the argument Name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Jul 2025
    2
    Low

    CVE-2025-8379

    Last Modified: 6 Aug 2025

    A vulnerability classified as critical has been found in Campcodes Online Hotel Reservation System 1.0. This affects an unknown part of the file /admin/edit_room.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Jul 2025
    7.5
    High

    CVE-2025-2813

    Last Modified: 15 Apr 2026

    An unauthenticated remote attacker can cause a Denial of Service by sending a large number of requests to the http service on port 80.

    Published: 31 Jul 2025
    7.2
    High

    CVE-2025-41688

    Last Modified: 15 Apr 2026

    A high privileged remote attacker can execute arbitrary OS commands using an undocumented method allowing to escape the implemented LUA sandbox.

    Published: 31 Jul 2025
    5.5
    Medium

    CVE-2025-8378

    Last Modified: 6 Aug 2025

    A vulnerability was found in Campcodes Online Hotel Reservation System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/index.php of the component Login. The manipulation of the argument username/password leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Jul 2025
    5.1
    Medium

    CVE-2025-40980

    Last Modified: 15 Apr 2026

    A Stored Cross Site Scripting vulnerability has been found in UltimatePOS by UltimateFosters. This vulnerability is due to the lack of proper validation of user inputs via ‘/products/<PRODUCT_ID>/edit’, affecting to ‘name’ parameter via POST. The vulnerability could allow a remote attacker to send a specially crafted query to an authenticated user and steal his/her session cookies details.

    Published: 31 Jul 2025
    5.5
    Medium

    CVE-2025-8376

    Last Modified: 5 Aug 2025

    A vulnerability classified as critical has been found in code-projects Vehicle Management 1.0. Affected is an unknown function of the file /updatebal.php. The manipulation of the argument company leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Jul 2025
    5.5
    Medium

    CVE-2025-8375

    Last Modified: 5 Aug 2025

    A vulnerability was found in code-projects Vehicle Management 1.0. It has been rated as critical. This issue affects some unknown processing of the file /addvehicle.php. The manipulation of the argument vehicle leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Jul 2025
    6.1
    Medium

    CVE-2025-24854

    Last Modified: 4 Nov 2025

    A carefully crafted request using the Image plugin could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.12.3 or later.

    Published: 31 Jul 2025
    7.5
    High

    CVE-2025-24853

    Last Modified: 4 Nov 2025

    A carefully crafted request when creating a header link using the wiki markup syntax, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Further research by the JSPWiki team showed that the markdown parser allowed this kind of attack too. Apache JSPWiki users should upgrade to 2.12.3 or later.

    Published: 31 Jul 2025
    5.5
    Medium

    CVE-2025-8374

    Last Modified: 5 Aug 2025

    A vulnerability was found in code-projects Vehicle Management 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /addcompany.php. The manipulation of the argument company leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Jul 2025
    6.9
    Medium

    CVE-2025-8192

    Last Modified: 15 Apr 2026

    There exists a TOCTOU race condition in TvSettings AppRestrictionsFragment.java that lead to start of attacker supplied activity in Settings’ context, i.e. system-uid context, thus lead to launchAnyWhere. The core idea is to utilize the time window between the check of Intent and the use to Intent to change the target component’s state, thus bypass the original security sanitize function.

    Published: 31 Jul 2025
    Unknown

    CVE-2025-54846

    Last Modified: 1 Aug 2025

    Not used

    Published: 31 Jul 2025
    Unknown

    CVE-2025-54847

    Last Modified: 1 Aug 2025

    Not used

    Published: 31 Jul 2025
    Unknown

    CVE-2025-54844

    Last Modified: 1 Aug 2025

    Not used

    Published: 31 Jul 2025
    Unknown

    CVE-2025-54845

    Last Modified: 1 Aug 2025

    Not used

    Published: 31 Jul 2025
    Unknown

    CVE-2025-54839

    Last Modified: 1 Aug 2025

    Not used

    Published: 31 Jul 2025
    Unknown

    CVE-2025-54840

    Last Modified: 1 Aug 2025

    Not used

    Published: 31 Jul 2025
    Unknown

    CVE-2025-54841

    Last Modified: 1 Aug 2025

    Not used

    Published: 31 Jul 2025
    Unknown

    CVE-2025-54842

    Last Modified: 1 Aug 2025

    Not used

    Published: 31 Jul 2025
    Unknown

    CVE-2025-54843

    Last Modified: 1 Aug 2025

    Not used

    Published: 31 Jul 2025
    5.5
    Medium

    CVE-2025-8373

    Last Modified: 5 Aug 2025

    A vulnerability was found in code-projects Vehicle Management 1.0. It has been classified as critical. This affects an unknown part of the file /print.php. The manipulation of the argument sno leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Jul 2025
    5.5
    Medium

    CVE-2025-8372

    Last Modified: 5 Aug 2025

    A vulnerability was found in code-projects Exam Form Submission 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/update_s7.php. The manipulation of the argument credits leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Jul 2025
    5.3
    Medium

    CVE-2025-36563

    Last Modified: 6 Aug 2025

    Reflected cross-site scripting vulnerability exists in multiple versions of PowerCMS. If a product administrator accesses a crafted URL, an arbitrary script may be executed on the browser.

    Published: 31 Jul 2025
    5.1
    Medium

    CVE-2025-41391

    Last Modified: 6 Aug 2025

    Stored cross-site scripting vulnerability exists in multiple versions of PowerCMS. If a product user accesses a malicious page, an arbitrary script may be executed on the browser.

    Published: 31 Jul 2025
    5.4
    Medium

    CVE-2025-7205

    Last Modified: 21 Apr 2026

    The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the donor notes parameter in all versions up to, and including, 4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with GiveWP worker-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Additionally, they need to trick an administrator into visiting the legacy version of the site.

    Published: 31 Jul 2025
    5.3
    Medium

    CVE-2025-41396

    Last Modified: 6 Aug 2025

    A path traversal issue exists in file uploading feature of multiple versions of PowerCMS. Arbitrary files may be overwritten by a product user.

    Published: 31 Jul 2025
    8.6
    High

    CVE-2025-46359

    Last Modified: 6 Aug 2025

    A path traversal issue exists in backup and restore feature of multiple versions of PowerCMS. A product administrator may execute arbitrary code by restoring a crafted backup file.

    Published: 31 Jul 2025
    4.8
    Medium

    CVE-2025-54752

    Last Modified: 6 Aug 2025

    Multiple versions of PowerCMS improperly neutralize formula elements in a CSV file. If a product user creates a malformed entry and a victim user downloads it as a CSV file and opens it in the user's environment, the embedded code may be executed.

    Published: 31 Jul 2025
    5.1
    Medium

    CVE-2025-54757

    Last Modified: 6 Aug 2025

    Multiple versions of PowerCMS allow unrestricted upload of dangerous files. If a product administrator accesses a malicious file uploaded by a product user, an arbitrary script may be executed on the browser.

    Published: 31 Jul 2025
    5.5
    Medium

    CVE-2025-8371

    Last Modified: 5 Aug 2025

    A vulnerability has been found in code-projects Exam Form Submission 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/update_s5.php. The manipulation of the argument credits leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Jul 2025
    2.1
    Low

    CVE-2025-8370

    Last Modified: 5 Aug 2025

    A vulnerability, which was classified as problematic, was found in Portabilis i-Educar 2.9. Affected is an unknown function of the file /intranet/educar_escolaridade_lst.php. The manipulation of the argument descricao leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Jul 2025
    2.1
    Low

    CVE-2025-8369

    Last Modified: 5 Aug 2025

    A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar 2.9. This issue affects some unknown processing of the file /intranet/educar_avaliacao_desempenho_lst.php. The manipulation of the argument titulo_avaliacao leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Jul 2025
    8.7
    High

    CVE-2025-53558

    Last Modified: 15 Apr 2026

    ZXHN-F660T and ZXHN-F660A provided by ZTE Japan K.K. use a common credential for all installations. With the knowledge of the credential, an attacker may log in to the affected devices.

    Published: 31 Jul 2025
    2.1
    Low

    CVE-2025-8368

    Last Modified: 5 Aug 2025

    A vulnerability classified as problematic was found in Portabilis i-Educar 2.9. This vulnerability affects unknown code of the file /intranet/pesquisa_pessoa_lst.php. The manipulation of the argument campo_busca/cpf leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Jul 2025
    2.1
    Low

    CVE-2025-8367

    Last Modified: 5 Aug 2025

    A vulnerability classified as problematic has been found in Portabilis i-Educar 2.9. This affects an unknown part of the file /intranet/funcionario_vinculo_lst.php. The manipulation of the argument nome leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Jul 2025
    2.1
    Low

    CVE-2025-8366

    Last Modified: 5 Aug 2025

    A vulnerability was found in Portabilis i-Educar 2.9. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /intranet/educar_servidor_lst.php. The manipulation of the argument nome/matricula_servidor leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Jul 2025
    6.4
    Medium

    CVE-2025-5720

    Last Modified: 22 Apr 2026

    The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author’ parameter in all versions up to, and including, 5.80.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 31 Jul 2025
    8.8
    High

    CVE-2025-7847

    Last Modified: 15 Apr 2026

    The AI Engine plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rest_simpleFileUpload() function in versions 2.9.3 and 2.9.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server when the REST API is enabled, which may make remote code execution possible.

    Published: 31 Jul 2025
    2
    Low

    CVE-2025-8365

    Last Modified: 5 Aug 2025

    A vulnerability was found in Portabilis i-Educar 2.10. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file atendidos_cad.php. The manipulation of the argument nome/nome_social/email leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Jul 2025