CVE Feed

    Dashboard / CVE

    Unknown

    CVE-2025-53706

    Last Modified: 10 Mar 2026

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2025. Notes: none.

    Published: 29 Jul 2025
    Unknown

    CVE-2025-53517

    Last Modified: 16 Mar 2026

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2025. Notes: none.

    Published: 29 Jul 2025
    Unknown

    CVE-2025-54758

    Last Modified: 16 Mar 2026

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2025. Notes: none.

    Published: 29 Jul 2025
    8.1
    High

    CVE-2025-6505

    Last Modified: 2 Oct 2025

    Unauthorized access and impersonation can occur in versions 4.6.2.3226 and below of Progress Software's Hybrid Data Pipeline Server on Linux. This vulnerability allows attackers to combine credentials from different sources, potentially leading to client impersonation and unauthorized access.  When OAuth Clients perform an OAuth handshake with the Hybrid Data Pipeline Server, the server accepts client credentials from both HTTP headers and request parameters.

    Published: 29 Jul 2025
    8.4
    High

    CVE-2025-6504

    Last Modified: 2 Oct 2025

    In HDP Server versions below 4.6.2.2978 on Linux, unauthorized access could occur via IP spoofing using the X-Forwarded-For header.  Since XFF is a client-controlled header, it could be spoofed, allowing unauthorized access if the spoofed IP matched a whitelisted range. This vulnerability could be exploited to bypass IP restrictions, though valid user credentials would still be required for resource access.

    Published: 29 Jul 2025
    6.9
    Medium

    CVE-2025-54422

    Last Modified: 4 Aug 2025

    Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions 1.16.1 and below, a critical security vulnerability exists in password handling mechanisms. During encrypted sandbox creation, user passwords are transmitted via shared memory, exposing them to potential interception. The vulnerability is particularly severe during password modification operations, where both old and new passwords are passed as plaintext command-line arguments to the Imbox process without any encryption or obfuscation. This implementation flaw allows any process within the user session, including unprivileged processes, to retrieve these sensitive credentials by reading the command-line arguments, thereby bypassing standard privilege requirements and creating a significant security risk. This is fixed in version 1.16.2.

    Published: 29 Jul 2025
    6.9
    Medium

    CVE-2025-7458

    Last Modified: 11 Aug 2025

    An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive information from process memory via a crafted SELECT statement with a large number of expressions in the ORDER BY clause.

    Published: 29 Jul 2025
    5.4
    Medium

    CVE-2025-6060

    Last Modified: 5 Jun 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in DECE Software Geodi allows Cross-Site Scripting (XSS). This issue affects Geodi: before GEODI Setup 9.0.146.

    Published: 29 Jul 2025
    4.4
    Medium

    CVE-2025-41241

    Last Modified: 15 Apr 2026

    VMware vCenter contains a denial-of-service vulnerability. A malicious actor who is authenticated through vCenter and has permission to perform API calls for guest OS customisation may trigger this vulnerability to create a denial-of-service condition.

    Published: 29 Jul 2025
    7.2
    High

    CVE-2025-6175

    Last Modified: 5 Jun 2026

    Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in DECE Software Geodi allows HTTP Request Splitting. This issue affects Geodi: before GEODI Setup 9.0.146.

    Published: 29 Jul 2025
    4.8
    Medium

    CVE-2025-40686

    Last Modified: 4 Aug 2025

    Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the 'employeeid' parameter in/detailview.php.

    Published: 29 Jul 2025
    4.8
    Medium

    CVE-2025-40685

    Last Modified: 4 Aug 2025

    Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the 'searcstate' parameter in/state.php.

    Published: 29 Jul 2025
    4.8
    Medium

    CVE-2025-40684

    Last Modified: 4 Aug 2025

    Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the 'searccountry' parameter in/country.php.

    Published: 29 Jul 2025
    4.8
    Medium

    CVE-2025-40683

    Last Modified: 4 Aug 2025

    Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the 'searccity' parameter in /city.php.

    Published: 29 Jul 2025
    8.7
    High

    CVE-2025-40682

    Last Modified: 4 Aug 2025

    SQL injection vulnerability in Human Resource Management System version 1.0, which allows an attacker to retrieve, create, update and delete databases via the “city” and “state” parameters in the /controller/ccity.php endpoint.

    Published: 29 Jul 2025
    6.4
    Medium

    CVE-2025-5587

    Last Modified: 22 Apr 2026

    The Appzend theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘progressbarLayout’ parameter in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 29 Jul 2025
    6.4
    Medium

    CVE-2025-6692

    Last Modified: 20 Apr 2026

    The YouTube Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘instance’ parameter in all versions up to, and including, 10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 29 Jul 2025
    8.8
    High

    CVE-2025-7689

    Last Modified: 15 Apr 2026

    The Hydra Booking plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the tfhb_reset_password_callback() function in versions 1.1.0 to 1.1.18. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset the password of an Administrator user, achieving full privilege escalation.

    Published: 29 Jul 2025
    6.4
    Medium

    CVE-2025-6681

    Last Modified: 21 Apr 2026

    The Fan Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ parameter in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 29 Jul 2025
    6.4
    Medium

    CVE-2025-8196

    Last Modified: 22 Apr 2026

    The Magical Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Custom Attributes in all versions up to, and including, 1.3.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 29 Jul 2025
    4.3
    Medium

    CVE-2025-6730

    Last Modified: 22 Apr 2026

    The Bonanza – WooCommerce Free Gifts Lite plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the xlo_optin_call() function in all versions up to, and including, 1.0.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to set the opt in status to success.

    Published: 29 Jul 2025
    6.4
    Medium

    CVE-2025-8216

    Last Modified: 22 Apr 2026

    The Sky Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Multiple widgets in all versions up to, and including, 3.1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 29 Jul 2025
    5.3
    Medium

    CVE-2025-26400

    Last Modified: 17 Nov 2025

    SolarWinds Web Help Desk was reported to be affected by an XML External Entity Injection (XXE) vulnerability that could lead to information disclosure. A valid, low-privilege access is required unless the attacker had access to the local server to modify configuration files.

    Published: 29 Jul 2025
    6.1
    Medium

    CVE-2025-53082

    Last Modified: 11 Aug 2025

    An 'Arbitrary File Deletion' in Samsung DMS(Data Management Server) allows attackers to delete arbitrary files from unintended locations on the filesystem. Exploitation is restricted to specific, authorized private IP addresses.

    Published: 29 Jul 2025
    6.4
    Medium

    CVE-2025-53081

    Last Modified: 11 Aug 2025

    An 'Arbitrary File Creation' in Samsung DMS(Data Management Server) allows attackers to create arbitrary files in unintended locations on the filesystem. Exploitation is restricted to specific, authorized private IP addresses.

    Published: 29 Jul 2025
    7.1
    High

    CVE-2025-53080

    Last Modified: 11 Aug 2025

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Samsung DMS(Data Management Server) allows authenticated attackers to create arbitrary files in unintended locations on the filesystem

    Published: 29 Jul 2025
    4.9
    Medium

    CVE-2025-53079

    Last Modified: 11 Aug 2025

    Absolute Path Traversal in Samsung DMS(Data Management Server) allows authenticated attacker (Administrator) to read sensitive files

    Published: 29 Jul 2025
    8
    High

    CVE-2025-53078

    Last Modified: 11 Aug 2025

    Deserialization of Untrusted Data in Samsung DMS(Data Management Server) allows attackers to execute arbitrary code via write file to system

    Published: 29 Jul 2025
    6.5
    Medium

    CVE-2025-53077

    Last Modified: 11 Aug 2025

    An execution after redirect in Samsung DMS(Data Management Server) allows attackers to execute limited functions without permissions. An attacker could compromise the integrity of the platform by executing this vulnerability.

    Published: 29 Jul 2025
    7.9
    High

    CVE-2025-8264

    Last Modified: 15 Apr 2026

    Versions of the package z-push/z-push-dev before 2.7.6 are vulnerable to SQL Injection due to unparameterized queries in the IMAP backend. An attacker can inject malicious commands by manipulating the username field in basic authentication. This allows the attacker to access and potentially modify or delete sensitive data from a linked third-party database. **Note:** This vulnerability affects Z-Push installations that utilize the IMAP backend and have the IMAP_FROM_SQL_QUERY option configured. Mitigation Change configuration to use the default or LDAP in backend/imap/config.php php define('IMAP_DEFAULTFROM', ''); or php define('IMAP_DEFAULTFROM', 'ldap');

    Published: 29 Jul 2025
    5.9
    Medium

    CVE-2025-53649

    Last Modified: 15 Apr 2026

    "SwitchBot" App for iOS/Android contains an insertion of sensitive information into log file vulnerability in versions V6.24 through V9.12. If this vulnerability is exploited, sensitive user information may be exposed to an attacker who has access to the application logs.

    Published: 29 Jul 2025
    5.3
    Medium

    CVE-2025-4370

    Last Modified: 20 Apr 2026

    The Brizy – Page Builder plugin for WordPress is vulnerable to limited file uploads due to missing authorization on process_external_asset_urls function as well as missing path validation in store_file function in all versions up to, and including, 2.6.20. This makes it possible for unauthenticated attackers to upload .TXT files on the affected site's server.

    Published: 29 Jul 2025
    6.4
    Medium

    CVE-2025-4566

    Last Modified: 20 Apr 2026

    The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-text DOM element attribute in Text Path widget in all versions up to, and including, 3.30.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This attack affects only Chrome/Edge browsers

    Published: 29 Jul 2025
    6.4
    Medium

    CVE-2025-3075

    Last Modified: 21 Apr 2026

    The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'elementor-element' shortcode in all versions up to, and including, 3.29.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only impacts sites with 'Element Caching' enabled.

    Published: 29 Jul 2025
    7.5
    High

    CVE-2025-6495

    Last Modified: 21 Apr 2026

    The Bricks theme for WordPress is vulnerable to blind SQL Injection via the ‘p’ parameter in all versions up to, and including, 1.12.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 29 Jul 2025
    6.4
    Medium

    CVE-2025-7811

    Last Modified: 20 Apr 2026

    The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'data-uuid' attribute in all versions up to, and including, 1.4.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 29 Jul 2025
    6.4
    Medium

    CVE-2025-7809

    Last Modified: 20 Apr 2026

    The StreamWeasels Twitch Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'data-uuid' attribute in all versions up to, and including, 1.9.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 29 Jul 2025
    5.4
    Medium

    CVE-2025-7810

    Last Modified: 21 Apr 2026

    The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'data-uuid' attribute in all versions up to, and including, 1.1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 29 Jul 2025
    7.3
    High

    CVE-2025-52490

    Last Modified: 6 Aug 2025

    An issue was discovered in Couchbase Sync Gateway before 3.2.6. In sgcollect_info_options.log and sync_gateway.log, there are cleartext passwords in redacted and unredacted output.

    Published: 29 Jul 2025
    6.3
    Medium

    CVE-2025-52358

    Last Modified: 6 Aug 2025

    A cross-site scripting vulnerability in Vivaldi United Group iCONTROL+ Server including Firmware version 4.7.8.0.eden Logic version 5.32 and below. This issue allows attackers to inject JavaScript payloads within the error or edit-menu-item parameters which are then executed in the victim's browser session.

    Published: 29 Jul 2025
    6.5
    Medium

    CVE-2025-52284

    Last Modified: 15 Sept 2025

    Totolink X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_4184C0 function via the tz parameter. This vulnerability allows unauthenticated attackers to execute arbitrary commands via a crafted request.

    Published: 29 Jul 2025
    7.7
    High

    CVE-2025-51970

    Last Modified: 13 Nov 2025

    A SQL Injection vulnerability exists in the action.php endpoint of PuneethReddyHC Online Shopping System Advanced 1.0 due to improper sanitization of user-supplied input in the keyword POST parameter.

    Published: 29 Jul 2025
    6.4
    Medium

    CVE-2024-43018

    Last Modified: 6 Aug 2025

    Piwigo 13.8.0 and below is vulnerable to SQL Injection in the parameters max_level and min_register. These parameters are used in ws_user_gerList function from file include\ws_functions\pwg.users.php and this same function is called by ws.php file at some point can be used for searching users in advanced way in /admin.php?page=user_list.

    Published: 29 Jul 2025
    9.8
    Critical

    CVE-2025-46059

    Last Modified: 15 Apr 2026

    langchain-ai v0.3.51 was discovered to contain an indirect prompt injection vulnerability in the GmailToolkit component. This vulnerability allows attackers to execute arbitrary code and compromise the application via a crafted email message. NOTE: this is disputed by the Supplier because the code-execution issue was introduced by user-written code that does not adhere to the LangChain security practices.

    Published: 29 Jul 2025
    8.2
    High

    CVE-2025-44137

    Last Modified: 20 Jan 2026

    MapTiler Tileserver-php v2.0 is vulnerable to Directory Traversal. The renderTile function within tileserver.php is responsible for delivering tiles that are stored as files on the server via web request. Creating the path to a file allows the insertion of "../" and thus read any file on the web server. Affected GET parameters are "TileMatrix", "TileRow", "TileCol" and "Format"

    Published: 29 Jul 2025
    7.5
    High

    CVE-2024-42644

    Last Modified: 6 Aug 2025

    FlashMQ v1.14.0 was discovered to contain an assertion failure in the function PublishCopyFactory::getNewPublish, which occurs when the QoS value of the publish object is greater than 0.

    Published: 29 Jul 2025
    7.5
    High

    CVE-2024-42645

    Last Modified: 6 Aug 2025

    An issue in FlashMQ v1.14.0 allows attackers to cause an assertion failure via sending a crafted retain message, leading to a Denial of Service (DoS).

    Published: 29 Jul 2025
    7.5
    High

    CVE-2024-42651

    Last Modified: 6 Aug 2025

    NanoMQ v0.17.9 was discovered to contain a heap use-after-free vulnerability via the component sub_Ctx_handle. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SUBSCRIBE message.

    Published: 29 Jul 2025
    8.8
    High

    CVE-2024-42655

    Last Modified: 6 Aug 2025

    An access control issue in NanoMQ v0.21.10 allows attackers to bypass security restrictions and access sensitive system topic messages using MQTT wildcard characters.

    Published: 29 Jul 2025
    7.6
    High

    CVE-2025-28170

    Last Modified: 6 Aug 2025

    Grandstream Networks GXP1628 <=1.0.4.130 is vulnerable to Incorrect Access Control. The device is configured with directory listing enabled, allowing unauthorized access to sensitive directories and files.

    Published: 29 Jul 2025