CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2025-51396

    Last Modified: 7 Aug 2025

    A stored cross-site scripting (XSS) vulnerability in Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Telegram Bot Username parameter.

    Published: 21 Jul 2025
    5.4
    Medium

    CVE-2025-51397

    Last Modified: 7 Aug 2025

    A stored cross-site scripting (XSS) vulnerability in the Facebook Chat module of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Surname parameter under the Recipient' Lists.

    Published: 21 Jul 2025
    5.4
    Medium

    CVE-2025-51400

    Last Modified: 7 Aug 2025

    A stored cross-site scripting (XSS) vulnerability in the Personal Canned Messages of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.

    Published: 21 Jul 2025
    5.4
    Medium

    CVE-2025-51401

    Last Modified: 7 Aug 2025

    A stored cross-site scripting (XSS) vulnerability in the chat transfer function of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the operator name parameter.

    Published: 21 Jul 2025
    6.5
    Medium

    CVE-2025-51403

    Last Modified: 7 Aug 2025

    A stored cross-site scripting (XSS) vulnerability in the department assignment editing module of of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Alias Nick parameter.

    Published: 21 Jul 2025
    7.5
    High

    CVE-2025-51869

    Last Modified: 15 Apr 2026

    Insecure Direct Object Reference (IDOR) vulnerability in Liner thru 2025-06-03 allows attackers to gain sensitive information via crafted space_id, thread_id, and message_id parameters to the v1/space/{space_id}/thread/{thread_id}/message/{message_id} endpoint.

    Published: 21 Jul 2025
    5.1
    Medium

    CVE-2025-52372

    Last Modified: 8 Aug 2025

    An issue in hMailServer v.5.8.6 allows a local attacker to obtain sensitive information via the hmailserver/installation/hMailServerInnoExtension.iss and hMailServer.ini components.

    Published: 21 Jul 2025
    4.6
    Medium

    CVE-2025-52373

    Last Modified: 7 Aug 2025

    Use of hardcoded cryptographic key in BlowFish.cpp in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passwords used in database connections from hMailServer.ini config file.

    Published: 21 Jul 2025
    3.7
    Low

    CVE-2025-54352

    Last Modified: 15 Apr 2026

    WordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private and draft posts via pingback.ping XML-RPC requests. NOTE: the Supplier is not changing this behavior.

    Published: 21 Jul 2025
    6.5
    Medium

    CVE-2025-7777

    Last Modified: 15 Apr 2026

    The mirror-registry doesn't properly sanitize the host header HTTP header in HTTP request received, allowing an attacker to perform malicious redirects to attacker-controlled domains or phishing campaigns.

    Published: 21 Jul 2025
    7.5
    High

    CVE-2025-51868

    Last Modified: 15 Apr 2026

    Insecure Direct Object Reference (IDOR) vulnerability in Dippy (chat.dippy.ai) v2 allows attackers to gain sensitive information via the conversation_id parameter to the conversation_history endpoint.

    Published: 21 Jul 2025
    7.4
    High

    CVE-2025-7913

    Last Modified: 23 Jul 2025

    A vulnerability, which was classified as critical, was found in TOTOLINK T6 4.1.5cu.748_B20211015. Affected is the function updateWifiInfo of the component MQTT Service. The manipulation of the argument serverIp leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 20 Jul 2025
    7.4
    High

    CVE-2025-7912

    Last Modified: 23 Jul 2025

    A vulnerability, which was classified as critical, has been found in TOTOLINK T6 4.1.5cu.748_B20211015. This issue affects the function recvSlaveUpgstatus of the component MQTT Service. The manipulation of the argument s leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 20 Jul 2025
    7.4
    High

    CVE-2025-7911

    Last Modified: 8 Aug 2025

    A vulnerability classified as critical was found in D-Link DI-8100 1.0. This vulnerability affects the function sprintf of the file /upnp_ctrl.asp of the component jhttpd. The manipulation of the argument remove_ext_proto/remove_ext_port leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 20 Jul 2025
    6.5
    Medium

    CVE-2025-53771

    Last Modified: 13 Feb 2026

    Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

    Published: 20 Jul 2025
    7.4
    High

    CVE-2025-7910

    Last Modified: 25 Jul 2025

    A vulnerability classified as critical has been found in D-Link DIR-513 1.10. This affects the function sprintf of the file /goform/formSetWanNonLogin of the component Boa Webserver. The manipulation of the argument curTime leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 20 Jul 2025
    7.4
    High

    CVE-2025-7909

    Last Modified: 25 Jul 2025

    A vulnerability was found in D-Link DIR-513 1.0. It has been rated as critical. Affected by this issue is the function sprintf of the file /goform/formLanSetupRouterSettings of the component Boa Webserver. The manipulation of the argument curTime leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 20 Jul 2025
    7.4
    High

    CVE-2025-7908

    Last Modified: 25 Jul 2025

    A vulnerability was found in D-Link DI-8100 1.0. It has been declared as critical. Affected by this vulnerability is the function sprintf of the file /ddns.asp?opt=add of the component jhttpd. The manipulation of the argument mx leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 20 Jul 2025
    2.1
    Low

    CVE-2025-7907

    Last Modified: 8 Aug 2025

    A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1. It has been classified as problematic. Affected is an unknown function of the file ruoyi-admin/src/main/resources/application-druid.yml of the component Druid. The manipulation leads to use of default credentials. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 20 Jul 2025
    2.1
    Low

    CVE-2025-7906

    Last Modified: 11 Sept 2025

    A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1 and classified as critical. This issue affects the function uploadFile of the file ruoyi-admin/src/main/java/com/ruoyi/web/controller/common/CommonController.java. The manipulation of the argument File leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 20 Jul 2025
    2.1
    Low

    CVE-2025-7905

    Last Modified: 23 Jul 2025

    A vulnerability has been found in itsourcecode Insurance Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /insertPayment.php. The manipulation of the argument recipt_no leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 20 Jul 2025
    2.1
    Low

    CVE-2025-7904

    Last Modified: 23 Jul 2025

    A vulnerability, which was classified as critical, was found in itsourcecode Insurance Management System 1.0. This affects an unknown part of the file /insertNominee.php. The manipulation of the argument nominee_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 20 Jul 2025
    2.1
    Low

    CVE-2025-7903

    Last Modified: 11 Sept 2025

    A vulnerability classified as problematic was found in yangzongzhuan RuoYi up to 4.8.1. Affected by this vulnerability is an unknown functionality of the component Image Source Handler. The manipulation leads to improper restriction of rendered ui layers. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 20 Jul 2025
    2
    Low

    CVE-2025-7902

    Last Modified: 8 Aug 2025

    A vulnerability classified as problematic has been found in yangzongzhuan RuoYi up to 4.8.1. Affected is the function addSave of the file com/ruoyi/web/controller/system/SysNoticeController.java. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 20 Jul 2025
    5.3
    Medium

    CVE-2025-7901

    Last Modified: 11 Sept 2025

    A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1. It has been rated as problematic. This issue affects some unknown processing of the file /swagger-ui/index.html of the component Swagger UI. The manipulation of the argument configUrl leads to cross site scripting. The attack may be initiated remotely.

    Published: 20 Jul 2025
    2
    Low

    CVE-2025-7898

    Last Modified: 5 Aug 2025

    A vulnerability was found in Codecanyon iDentSoft 2.0. It has been classified as critical. This affects an unknown part of the file /clinica/profile/updateSetting of the component Account Setting Page. The manipulation of the argument photo leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 20 Jul 2025
    6.9
    Medium

    CVE-2025-7897

    Last Modified: 20 Nov 2025

    A vulnerability was found in harry0703 MoneyPrinterTurbo up to 1.2.6 and classified as critical. Affected by this issue is the function verify_token of the file app/controllers/base.py of the component API Endpoint. The manipulation leads to missing authentication. The attack may be launched remotely.

    Published: 20 Jul 2025
    5.3
    Medium

    CVE-2025-7896

    Last Modified: 20 Nov 2025

    A vulnerability has been found in harry0703 MoneyPrinterTurbo up to 1.2.6 and classified as critical. Affected by this vulnerability is the function download_video/delete_video of the file app/controllers/v1/video.py. The manipulation leads to path traversal. The attack can be launched remotely.

    Published: 20 Jul 2025
    8.6
    High

    CVE-2025-46385

    Last Modified: 15 Apr 2026

    CWE-918 Server-Side Request Forgery (SSRF)

    Published: 20 Jul 2025
    8.8
    High

    CVE-2025-46384

    Last Modified: 15 Apr 2026

    CWE-434 Unrestricted Upload of File with Dangerous Type

    Published: 20 Jul 2025
    6.1
    Medium

    CVE-2025-46383

    Last Modified: 15 Apr 2026

    CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

    Published: 20 Jul 2025
    5.3
    Medium

    CVE-2025-7895

    Last Modified: 20 Nov 2025

    A vulnerability, which was classified as critical, was found in harry0703 MoneyPrinterTurbo up to 1.2.6. Affected is the function upload_bgm_file of the file app/controllers/v1/video.py of the component File Extension Handler. The manipulation of the argument File leads to unrestricted upload. It is possible to launch the attack remotely.

    Published: 20 Jul 2025
    5.3
    Medium

    CVE-2025-46382

    Last Modified: 15 Apr 2026

    CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

    Published: 20 Jul 2025
    2.1
    Low

    CVE-2025-7894

    Last Modified: 17 Sept 2025

    A vulnerability, which was classified as critical, has been found in Onyx up to 0.29.1. This issue affects the function generate_simple_sql of the file backend/onyx/agents/agent_search/kb_search/nodes/a3_generate_simple_sql.py of the component Chat Interface. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 20 Jul 2025
    1.9
    Low

    CVE-2025-7893

    Last Modified: 17 Sept 2025

    A vulnerability classified as problematic was found in Foresight News App up to 2.6.4 on Android. This vulnerability affects unknown code of the file AndroidManifest.xml of the component pro.foresightnews.appa. The manipulation leads to improper export of android application components. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 20 Jul 2025
    1.9
    Low

    CVE-2025-7892

    Last Modified: 17 Sept 2025

    A vulnerability classified as problematic has been found in IDnow App up to 9.6.0 on Android. This affects an unknown part of the file AndroidManifest.xml of the component de.idnow. The manipulation leads to improper export of android application components. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 20 Jul 2025
    1.9
    Low

    CVE-2025-7891

    Last Modified: 17 Sept 2025

    A vulnerability was found in InstantBits Web Video Cast App up to 5.12.4 on Android. It has been rated as problematic. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.instantbits.cast.webvideo. The manipulation leads to improper export of android application components. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 20 Jul 2025
    1.9
    Low

    CVE-2025-7890

    Last Modified: 17 Sept 2025

    A vulnerability was found in Dunamu StockPlus App up to 7.62.10 on Android. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.dunamu.stockplus. The manipulation leads to improper export of android application components. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 20 Jul 2025
    1.9
    Low

    CVE-2025-7889

    Last Modified: 15 Sept 2025

    A vulnerability was found in CallApp Caller ID App up to 2.0.4 on Android. It has been classified as problematic. Affected is an unknown function of the file AndroidManifest.xml of the component caller.id.phone.number.block. The manipulation leads to improper export of android application components. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 20 Jul 2025
    2.1
    Low

    CVE-2025-7888

    Last Modified: 11 Sept 2025

    A vulnerability was found in TDuckCloud tduck-platform 5.1 and classified as critical. This issue affects the function UserFormDataMapper of the file src/main/java/com/tduck/cloud/form/mapper/UserFormDataMapper.java. The manipulation of the argument formKey leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 20 Jul 2025
    2.1
    Low

    CVE-2025-7887

    Last Modified: 15 Sept 2025

    A vulnerability has been found in Zavy86 WikiDocs up to 1.0.78 and classified as problematic. This vulnerability affects unknown code of the file template.inc.php. The manipulation of the argument path leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 20 Jul 2025
    5.5
    Medium

    CVE-2025-7886

    Last Modified: 15 Apr 2026

    A vulnerability, which was classified as critical, was found in pmTicket Project-Management-Software up to 2ef379da2075f4761a2c9029cf91d073474e7486. This affects the function getUserLanguage of the file classes/class.database.php. The manipulation of the argument user_id leads to sql injection. It is possible to initiate the attack remotely. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 20 Jul 2025
    2.1
    Low

    CVE-2025-7885

    Last Modified: 15 Sept 2025

    A vulnerability, which was classified as problematic, has been found in Huashengdun WebSSH up to 1.6.2. Affected by this issue is some unknown functionality of the component Login Page. The manipulation of the argument hostname/port leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 20 Jul 2025
    1.9
    Low

    CVE-2025-7884

    Last Modified: 15 Sept 2025

    A vulnerability classified as problematic was found in Eluktronics Control Center 5.23.51.41. Affected by this vulnerability is an unknown functionality of the component REG File Handler. The manipulation leads to insufficient verification of data authenticity. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 20 Jul 2025
    7.1
    High

    CVE-2025-7883

    Last Modified: 15 Sept 2025

    A vulnerability classified as critical has been found in Eluktronics Control Center 5.23.51.41. Affected is an unknown function of the file \AiStoneService\MyControlCenter\Command of the component Powershell Script Handler. The manipulation leads to command injection. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 20 Jul 2025
    1.3
    Low

    CVE-2025-7882

    Last Modified: 15 Apr 2026

    A vulnerability was found in Mercusys MW301R 1.0.2 Build 190726 Rel.59423n. It has been rated as problematic. This issue affects some unknown processing of the component Login. The manipulation leads to improper restriction of excessive authentication attempts. The attack can only be initiated within the local network. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 20 Jul 2025
    2
    Low

    CVE-2025-7881

    Last Modified: 15 Apr 2026

    A vulnerability was found in Mercusys MW301R 1.0.2 Build 190726 Rel.59423n. It has been declared as problematic. This vulnerability affects unknown code of the component Web Interface. The manipulation of the argument code leads to weak password recovery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 20 Jul 2025
    2.1
    Low

    CVE-2025-7880

    Last Modified: 27 Aug 2025

    A vulnerability was found in Metasoft 美特软件 MetaCRM up to 6.4.2 and classified as critical. Affected by this issue is some unknown functionality of the file /business/common/sms/sendsms.jsp. The manipulation of the argument File leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 20 Jul 2025
    2.1
    Low

    CVE-2025-7879

    Last Modified: 27 Aug 2025

    A vulnerability has been found in Metasoft 美特软件 MetaCRM up to 6.4.2 and classified as critical. Affected by this vulnerability is an unknown functionality of the file mobileupload.jsp. The manipulation of the argument File leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 20 Jul 2025
    2.1
    Low

    CVE-2025-7878

    Last Modified: 27 Aug 2025

    A vulnerability, which was classified as critical, was found in Metasoft 美特软件 MetaCRM up to 6.4.2. Affected is an unknown function of the file /common/jsp/upload2.jsp. The manipulation of the argument File leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 20 Jul 2025