CVE Feed

    Dashboard / CVE

    8.4
    High

    CVE-2025-25269

    Last Modified: 11 Jul 2025

    An unauthenticated local attacker can inject a command that is subsequently executed as root, leading to a privilege escalation.

    Published: 8 Jul 2025
    8.8
    High

    CVE-2025-25268

    Last Modified: 11 Jul 2025

    An unauthenticated adjacent attacker can modify configuration by sending specific requests to an API-endpoint resulting in read and write access due to missing authentication.

    Published: 8 Jul 2025
    7.8
    High

    CVE-2025-24006

    Last Modified: 11 Jul 2025

    A low privileged local attacker can leverage insecure permissions via SSH on the affected devices to escalate privileges to root.

    Published: 8 Jul 2025
    7.8
    High

    CVE-2025-24005

    Last Modified: 11 Jul 2025

    A local attacker with a local user account can leverage a vulnerable script via SSH to escalate privileges to root due to improper input validation.

    Published: 8 Jul 2025
    5.2
    Medium

    CVE-2025-24004

    Last Modified: 11 Jul 2025

    A physical attacker with access to the device display via USB-C can send a message to the device which triggers an unsecure copy to a buffer resulting in loss of integrity and a temporary denial-of-service for the stations until they got restarted by the watchdog.

    Published: 8 Jul 2025
    8.2
    High

    CVE-2025-24003

    Last Modified: 11 Jul 2025

    An unauthenticated remote attacker can use MQTT messages to trigger out-of-bounds writes in charging stations complying with German Calibration Law, resulting in a loss of integrity for only EichrechtAgents and potential denial-of-service for these stations.

    Published: 8 Jul 2025
    5.3
    Medium

    CVE-2025-24002

    Last Modified: 11 Jul 2025

    An unauthenticated remote attacker can use MQTT messages to crash a service on charging stations complying with German Calibration Law, resulting in a temporary denial-of-service for these stations until they got restarted by the watchdog.

    Published: 8 Jul 2025
    6.1
    Medium

    CVE-2025-42956

    Last Modified: 27 Oct 2025

    SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to create a malicious link which they can make publicly available. When an authenticated victim clicks on this malicious link, injected input data will be used by the web site page generation to create content which when executed in the victim's browser leading to low impact on Confidentiality and Integrity with no effect on Availability of the application.

    Published: 8 Jul 2025
    8.8
    High

    CVE-2025-6746

    Last Modified: 21 Apr 2026

    The WoodMart plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.2.3 via the 'layout' attribute. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php files can be uploaded and included.

    Published: 8 Jul 2025
    6.4
    Medium

    CVE-2025-6743

    Last Modified: 21 Apr 2026

    The Woodmart theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'multiple_markers' attribute in all versions up to, and including, 8.2.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 8 Jul 2025
    2.1
    Low

    CVE-2025-7166

    Last Modified: 9 Jul 2025

    A vulnerability was found in code-projects Responsive Blog Site 1.0. It has been classified as critical. This affects an unknown part of the file /single.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Jul 2025
    5.5
    Medium

    CVE-2025-7165

    Last Modified: 8 Jul 2025

    A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /forgot-password.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Jul 2025
    5.5
    Medium

    CVE-2025-7164

    Last Modified: 8 Jul 2025

    A vulnerability has been found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Jul 2025
    8.8
    High

    CVE-2025-7327

    Last Modified: 22 Apr 2026

    The Widget for Google Reviews plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.0.15 via the layout parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included. This is limited to just PHP files.

    Published: 8 Jul 2025
    2.1
    Low

    CVE-2025-7163

    Last Modified: 13 Jul 2025

    A vulnerability, which was classified as critical, was found in PHPGurukul Zoo Management System 2.1. Affected is an unknown function of the file /admin/add-animals.php. The manipulation of the argument cnum leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Jul 2025
    2.1
    Low

    CVE-2025-7162

    Last Modified: 13 Jul 2025

    A vulnerability, which was classified as critical, has been found in PHPGurukul Zoo Management System 2.1. This issue affects some unknown processing of the file /admin/add-foreigners-ticket.php. The manipulation of the argument cprice leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Jul 2025
    5.3
    Medium

    CVE-2025-5957

    Last Modified: 21 Apr 2026

    The Guest Support – Complete customer support ticket system for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'deleteMassTickets' function in all versions up to, and including, 1.2.2. This makes it possible for unauthenticated attackers to delete arbitrary support tickets.

    Published: 8 Jul 2025
    6.4
    Medium

    CVE-2025-5537

    Last Modified: 21 Apr 2026

    The Lightbox & Modal Popup WordPress Plugin – FooBox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alternative texts in all versions up to, and including, 2.7.34 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 8 Jul 2025
    2.1
    Low

    CVE-2025-7161

    Last Modified: 13 Jul 2025

    A vulnerability classified as critical was found in PHPGurukul Zoo Management System 2.1. This vulnerability affects unknown code of the file /admin/add-normal-ticket.php. The manipulation of the argument cprice leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Jul 2025
    5.5
    Medium

    CVE-2025-7160

    Last Modified: 13 Jul 2025

    A vulnerability classified as critical has been found in PHPGurukul Zoo Management System 2.1. This affects an unknown part of the file /admin/index.php. The manipulation of the argument Username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Jul 2025
    2.1
    Low

    CVE-2025-7159

    Last Modified: 13 Jul 2025

    A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/manage-animals.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Jul 2025
    2.1
    Low

    CVE-2025-7158

    Last Modified: 13 Jul 2025

    A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/manage-normal-ticket.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Jul 2025
    5.5
    Medium

    CVE-2025-7157

    Last Modified: 9 Jul 2025

    A vulnerability was found in code-projects Online Note Sharing 1.0. It has been classified as critical. Affected is an unknown function of the file /login.php. The manipulation of the argument username/password leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Jul 2025
    6.5
    Medium

    CVE-2025-20695

    Last Modified: 14 Jul 2025

    In Bluetooth FW, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09741871; Issue ID: MSV-3317.

    Published: 8 Jul 2025
    6.5
    Medium

    CVE-2025-20694

    Last Modified: 14 Jul 2025

    In Bluetooth FW, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09752821; Issue ID: MSV-3342.

    Published: 8 Jul 2025
    6.5
    Medium

    CVE-2025-20693

    Last Modified: 9 Jul 2025

    In wlan STA driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09812521; Issue ID: MSV-3421.

    Published: 8 Jul 2025
    5.5
    Medium

    CVE-2025-20692

    Last Modified: 9 Jul 2025

    In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00418040; Issue ID: MSV-3476.

    Published: 8 Jul 2025
    5.5
    Medium

    CVE-2025-20691

    Last Modified: 9 Jul 2025

    In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00418039; Issue ID: MSV-3477.

    Published: 8 Jul 2025
    5.5
    Medium

    CVE-2025-20690

    Last Modified: 9 Jul 2025

    In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00418038; Issue ID: MSV-3478.

    Published: 8 Jul 2025
    5.5
    Medium

    CVE-2025-20689

    Last Modified: 9 Jul 2025

    In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00418048; Issue ID: MSV-3479.

    Published: 8 Jul 2025
    5.5
    Medium

    CVE-2025-20688

    Last Modified: 9 Jul 2025

    In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00418047; Issue ID: MSV-3480.

    Published: 8 Jul 2025
    5.5
    Medium

    CVE-2025-20687

    Last Modified: 14 Jul 2025

    In Bluetooth driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00418045; Issue ID: MSV-3481.

    Published: 8 Jul 2025
    8.8
    High

    CVE-2025-20686

    Last Modified: 9 Jul 2025

    In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00415570; Issue ID: MSV-3404.

    Published: 8 Jul 2025
    8.8
    High

    CVE-2025-20685

    Last Modified: 13 Jul 2025

    In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00416226; Issue ID: MSV-3409.

    Published: 8 Jul 2025
    9.8
    Critical

    CVE-2025-20684

    Last Modified: 13 Jul 2025

    In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00416939; Issue ID: MSV-3422.

    Published: 8 Jul 2025
    9.8
    Critical

    CVE-2025-20683

    Last Modified: 9 Jul 2025

    In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00416938; Issue ID: MSV-3444.

    Published: 8 Jul 2025
    9.8
    Critical

    CVE-2025-20682

    Last Modified: 13 Jul 2025

    In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00416937; Issue ID: MSV-3445.

    Published: 8 Jul 2025
    9.8
    Critical

    CVE-2025-20681

    Last Modified: 9 Jul 2025

    In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00416936; Issue ID: MSV-3446.

    Published: 8 Jul 2025
    9.8
    Critical

    CVE-2025-20680

    Last Modified: 26 Feb 2026

    In Bluetooth driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00418044; Issue ID: MSV-3482.

    Published: 8 Jul 2025
    5.4
    Medium

    CVE-2025-5570

    Last Modified: 21 Apr 2026

    The AI Engine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the mwai_chatbot shortcode 'id' parameter in all versions up to, and including, 2.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 8 Jul 2025
    6.4
    Medium

    CVE-2025-6244

    Last Modified: 22 Apr 2026

    The Essential Addons for Elementor – Popular Elementor Templates and Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the via `Calendar` And `Business Reviews` Widgets attributes in all versions up to, and including, 6.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 8 Jul 2025
    2.1
    Low

    CVE-2025-7156

    Last Modified: 15 Apr 2026

    A vulnerability has been found in hitsz-ids airda 0.0.3 and classified as critical. This vulnerability affects the function execute of the file /v1/chat/completions. The manipulation of the argument question leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 8 Jul 2025
    8.7
    High

    CVE-2025-7146

    Last Modified: 15 Apr 2026

    The iPublish System developed by Jhenggao has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers to read arbitrary system file.

    Published: 8 Jul 2025
    5.5
    Medium

    CVE-2025-7155

    Last Modified: 13 Jul 2025

    A vulnerability, which was classified as critical, was found in PHPGurukul Online Notes Sharing System 1.0. This affects an unknown part of the file /Dashboard of the component Cookie Handler. The manipulation of the argument sessionid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The original researcher disclosure suspects an XPath Injection vulnerability; however, the provided attack payload appears to be characteristic of an SQL Injection attack.

    Published: 8 Jul 2025
    6.9
    Medium

    CVE-2025-43001

    Last Modified: 15 Apr 2026

    SAPCAR allows an attacker logged in with high privileges to override the permissions of the current and parent directories of the user or process extracting the archive, leading to privilege escalation. On successful exploitation, an attacker could modify the critical files by tampering with signed archives without breaking the signature, but it has a low impact on the confidentiality and availability of the system.

    Published: 8 Jul 2025
    6.9
    Medium

    CVE-2025-42992

    Last Modified: 15 Apr 2026

    SAPCAR allows an attacker logged in with high privileges to create a malicious SAR archive in SAPCAR. This could enable the attacker to exploit critical files and directory permissions without breaking signature validation, resulting in potential privilege escalation. This has high impact on integrity, but low impact on confidentiality and availability of the system.

    Published: 8 Jul 2025
    4.3
    Medium

    CVE-2025-42986

    Last Modified: 27 Oct 2025

    Due to a missing authorization check in an obsolete RFC enabled function module in SAP BASIS, an authenticated low-privileged attacker could call a Remote Function Call (RFC), potentially accessing restricted system information. This results in low impact on confidentiality, with no impact on integrity or availability of the application.

    Published: 8 Jul 2025
    6.1
    Medium

    CVE-2025-42985

    Last Modified: 15 Apr 2026

    Due to insufficient sanitization in the SAP BusinessObjects Content Administrator Workbench, attackers could craft malicious URLs and execute scripts in a victim�s browser. This could potentially lead to the exposure or modification of web client data, resulting in low impact on confidentiality and integrity, with no impact on application availability.

    Published: 8 Jul 2025
    6.1
    Medium

    CVE-2025-42981

    Last Modified: 15 Apr 2026

    Due to an open redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft a URL link embedding a malicious script at a location not properly sanitized. When a victim clicks on this link, the script executes within the victim's browser, redirecting them to a site controlled by the attacker. This allows the attacker to access and/or modify restricted information related to the web client. While the vulnerability poses no impact on data availability, it presents a considerable risk to confidentiality and integrity.

    Published: 8 Jul 2025
    9.1
    Critical

    CVE-2025-42980

    Last Modified: 15 Apr 2026

    SAP NetWeaver Enterprise Portal Federated Portal Network is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.

    Published: 8 Jul 2025