CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2024-12827

    Last Modified: 15 Apr 2026

    The DWT - Directory & Listing WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.3.6. This is due to the plugin not properly checking for an empty token value prior to resetting a user's password through the dwt_listing_reset_password() function. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

    Published: 27 Jun 2025
    7.2
    High

    CVE-2025-2940

    Last Modified: 22 Apr 2026

    The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.0.18 via the args[url] parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

    Published: 27 Jun 2025
    7
    High

    CVE-2025-5306

    Last Modified: 16 Sept 2025

    Improper Neutralization of Special Elements in the Netflow directory field may allow OS command injection. This issue affects Pandora FMS 774 through 778

    Published: 27 Jun 2025
    9.8
    Critical

    CVE-2025-6688

    Last Modified: 13 Jul 2025

    The Simple Payment plugin for WordPress is vulnerable to Authentication Bypass in versions 1.3.6 to 2.3.8. This is due to the plugin not properly verifying a user's identity prior to logging them in through the create_user() function. This makes it possible for unauthenticated attackers to log in as administrative users.

    Published: 27 Jun 2025
    4.3
    Medium

    CVE-2025-5936

    Last Modified: 22 Apr 2026

    The VR Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.7. This is due to missing or incorrect nonce validation on the syncCalendar() function. This makes it possible for unauthenticated attackers to trigger a calendar sync via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 27 Jun 2025
    6.4
    Medium

    CVE-2025-5940

    Last Modified: 22 Apr 2026

    The Osom Blocks – Custom Post Type listing block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class_name’ parameter in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 27 Jun 2025
    6.4
    Medium

    CVE-2025-6550

    Last Modified: 22 Apr 2026

    The The Pack Elementor addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘slider_options’ parameter in all versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 27 Jun 2025
    6.4
    Medium

    CVE-2025-4587

    Last Modified: 22 Apr 2026

    The A/B Testing for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ab-testing-for-wp/ab-test-block' block in all versions up to, and including, 1.18.2 due to insufficient input sanitization and output escaping on the 'id' parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 27 Jun 2025
    6.4
    Medium

    CVE-2025-6689

    Last Modified: 22 Apr 2026

    The FL3R Accessibility Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's fl3raccessibilitysuite shortcode in all versions up to, and including, 1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 27 Jun 2025
    4.3
    Medium

    CVE-2025-5526

    Last Modified: 3 Jul 2025

    The BuddyPress Docs WordPress plugin before 2.2.5 lacks proper access controls and allows a logged in user to view and download files belonging to another user

    Published: 27 Jun 2025
    4.8
    Medium

    CVE-2025-5194

    Last Modified: 13 Jul 2025

    The WP Map Block WordPress plugin before 2.0.3 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

    Published: 27 Jun 2025
    5.4
    Medium

    CVE-2025-5093

    Last Modified: 1 Jul 2025

    The Responsive Lightbox & Gallery WordPress plugin before 2.5.2 use the Swipebox library which does not validate and escape title attributes before outputting them back in a page/post where used, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

    Published: 27 Jun 2025
    5.4
    Medium

    CVE-2025-5035

    Last Modified: 1 Jul 2025

    The Firelight Lightbox WordPress plugin before 2.3.16 does not sanitise and escape title attributes before outputting them in the page, which could allow users with a role as low as contributors to perform stored Cross-Site Scripting attacks.

    Published: 27 Jun 2025
    6.9
    Medium

    CVE-2025-41418

    Last Modified: 15 Apr 2026

    Buffer Overflow vulnerability exists in multiple versions of TB-eye network recorders and AHD recorders. The CGI process may be terminated abnormally by processing a specially crafted request.

    Published: 27 Jun 2025
    8.6
    High

    CVE-2025-36529

    Last Modified: 15 Apr 2026

    An OS command injection issue exists in multiple versions of TB-eye network recorders and AHD recorders. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who is logging in to the device.

    Published: 27 Jun 2025
    6.4
    Medium

    CVE-2025-6488

    Last Modified: 22 Apr 2026

    The isMobile plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘device’ parameter in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 27 Jun 2025
    2.1
    Low

    CVE-2025-6753

    Last Modified: 15 Apr 2026

    A vulnerability was found in huija bicycleSharingServer 1.0 and classified as critical. This issue affects the function selectAdminByNameLike of the file AdminController.java. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 Jun 2025
    7.4
    High

    CVE-2025-6752

    Last Modified: 15 Apr 2026

    A vulnerability has been found in Linksys WRT1900ACS, EA7200, EA7450 and EA7500 up to 20250619 and classified as critical. This vulnerability affects the function SetDefaultConnectionService of the file /upnp/control/Layer3Forwarding of the component IGD. The manipulation of the argument NewDefaultConnectionService leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 27 Jun 2025
    7.4
    High

    CVE-2025-6751

    Last Modified: 15 Apr 2026

    A vulnerability, which was classified as critical, was found in Linksys E8450 up to 1.2.00.360516. This affects the function set_device_language of the file portal.cgi of the component HTTP POST Request Handler. The manipulation of the argument dut_language leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 27 Jun 2025
    1.9
    Low

    CVE-2025-6750

    Last Modified: 1 Jul 2025

    A vulnerability, which was classified as problematic, has been found in HDF5 1.14.6. Affected by this issue is the function H5O__mtime_new_encode of the file src/H5Omtime.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

    Published: 27 Jun 2025
    2.1
    Low

    CVE-2025-6749

    Last Modified: 15 Apr 2026

    A vulnerability classified as critical was found in huija bicycleSharingServer up to 7b8a3ba48ad618604abd4797d2e7cf3b5ac7625a. Affected by this vulnerability is the function searchAdminMessageShow of the file AdminController.java. The manipulation of the argument Title leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable.

    Published: 27 Jun 2025
    0.9
    Low

    CVE-2025-6748

    Last Modified: 15 Apr 2026

    A vulnerability classified as problematic has been found in Bharti Airtel Thanks App 4.105.4 on Android. Affected is an unknown function of the file /Android/data/com.myairtelapp/files/. The manipulation leads to cleartext storage in a file or on disk. It is possible to launch the attack on the physical device. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 27 Jun 2025
    2.1
    Low

    CVE-2025-6738

    Last Modified: 15 Apr 2026

    A vulnerability, which was classified as critical, has been found in huija bicycleSharingServer up to 7b8a3ba48ad618604abd4797d2e7cf3b5ac7625a. Affected by this issue is the function userDao.selectUserByUserNameLike of the file UserServiceImpl.java. The manipulation of the argument Username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.

    Published: 27 Jun 2025
    6.3
    Medium

    CVE-2025-45729

    Last Modified: 1 Jul 2026

    D-Link DIR-823-Pro 1.02 has improper permission control, allowing unauthorized users to turn on and access Telnet services.

    Published: 27 Jun 2025
    5.6
    Medium

    CVE-2025-52993

    Last Modified: 15 Apr 2026

    A race condition in the Nix, Lix, and Guix package managers enables changing the ownership of arbitrary files to the UID and GID of the build user (e.g., nixbld* or guixbuild*). This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.

    Published: 27 Jun 2025
    3.2
    Low

    CVE-2025-52992

    Last Modified: 15 Apr 2026

    The Nix, Lix, and Guix package managers fail to properly set permissions when a derivation build fails. This may allow arbitrary processes to modify the content of a store outside of the build sandbox. This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.

    Published: 27 Jun 2025
    3.2
    Low

    CVE-2025-52991

    Last Modified: 15 Apr 2026

    The Nix, Lix, and Guix package managers default to using temporary build directories in a world-readable and world-writable location. This allows standard users to deceive the package manager into using directories with pre-existing content, potentially leading to unauthorized actions or data manipulation. This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.

    Published: 27 Jun 2025
    7.5
    High

    CVE-2025-45851

    Last Modified: 15 Apr 2026

    An issue in Hikvision DS-2CD1321-I V5.7.21 build 230819 allows attackers to cause a Denial of Service (DoS) via sending a crafted POST request to the endpoint /ISAPI/Security/challenge. The vendor has stated that upgrading to V5.7.23_SP2 fixes the issue.

    Published: 27 Jun 2025
    6.5
    Medium

    CVE-2025-44559

    Last Modified: 15 Apr 2026

    An issue in the Bluetooth Low Energy (BLE) stack of Realtek RTL8762E BLE SDK v1.4.0 allows attackers within Bluetooth range to cause a Denial of Service (DoS) via sending a specific sequence of crafted control packets.

    Published: 27 Jun 2025
    7.3
    High

    CVE-2025-50528

    Last Modified: 1 Jul 2025

    A buffer overflow vulnerability exists in the fromNatStaticSetting function of Tenda AC6 <=V15.03.05.19 via the page parameter.

    Published: 27 Jun 2025
    6.5
    Medium

    CVE-2025-50369

    Last Modified: 1 Jul 2025

    A Cross-Site Request Forgery (CSRF) vulnerability exists in the Manage Card functionality (/mcgs/admin/manage-card.php) of PHPGurukul Medical Card Generation System 1.0. The vulnerable endpoint allows an authorized admin to delete medical card records by sending a simple GET request without verifying the origin of the request.

    Published: 27 Jun 2025
    6.1
    Medium

    CVE-2025-50367

    Last Modified: 1 Jul 2025

    A stored blind XSS vulnerability exists in the Contact Page of the Phpgurukul Medical Card Generation System 1.0 mcgs/contact.php. The name field fails to properly sanitize user input, allowing an attacker to inject malicious JavaScript.

    Published: 27 Jun 2025
    6.5
    Medium

    CVE-2025-50370

    Last Modified: 13 Jul 2025

    A Cross-Site Request Forgery (CSRF) vulnerability exists in the Inquiry Management functionality /mcgs/admin/readenq.php of the Phpgurukul Medical Card Generation System 1.0. The vulnerable endpoint allows an authenticated admin to delete inquiry records via a simple GET request, without requiring a CSRF token or validating the origin of the request.

    Published: 27 Jun 2025
    2.2
    Low

    CVE-2025-47823

    Last Modified: 23 Oct 2025

    Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have a hardcoded password for a system.

    Published: 27 Jun 2025
    9.9
    Critical

    CVE-2025-52207

    Last Modified: 15 Apr 2026

    PBXCoreREST/Controllers/Files/PostController.php in MikoPBX through 2024.1.114 allows uploading a PHP script to an arbitrary directory.

    Published: 27 Jun 2025
    6.3
    Medium

    CVE-2025-44163

    Last Modified: 10 Nov 2025

    RaspAP raspap-webgui 3.3.1 is vulnerable to Directory Traversal in ajax/networking/get_wgkey.php. An authenticated attacker can send a crafted POST request with a path traversal payload in the `entity` parameter to overwrite arbitrary files writable by the web server via abuse of the `tee` command used in shell execution.

    Published: 27 Jun 2025
    8.1
    High

    CVE-2025-44557

    Last Modified: 15 Apr 2026

    A state machine transition flaw in the Bluetooth Low Energy (BLE) stack of Cypress PSoC4 v3.66 allows attackers to bypass the pairing process and authentication via a crafted pairing_failed packet.

    Published: 27 Jun 2025
    6.5
    Medium

    CVE-2025-45737

    Last Modified: 15 Oct 2025

    An issue in NetEase (Hangzhou) Network Co., Ltd NeacSafe64 Driver before v1.0.0.8 allows attackers to escalate privileges via sending crafted IOCTL commands to the NeacSafe64.sys component.

    Published: 27 Jun 2025
    3.2
    Low

    CVE-2025-46415

    Last Modified: 15 Apr 2026

    A race condition in the Nix, Lix, and Guix package managers allows the removal of content from arbitrary folders. This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.

    Published: 27 Jun 2025
    2.9
    Low

    CVE-2025-46416

    Last Modified: 15 Apr 2026

    The Nix, Lix, and Guix package managers allow a bypass of build isolation in which a user can elevate their privileges to the build user account (e.g., nixbld or guixbuild). This affects Nix through 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix through 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.

    Published: 27 Jun 2025
    2.2
    Low

    CVE-2025-47818

    Last Modified: 24 Oct 2025

    Flock Safety Gunshot Detection devices before 1.3 have a hard-coded password for a connection.

    Published: 27 Jun 2025
    6.4
    Medium

    CVE-2025-47819

    Last Modified: 24 Oct 2025

    Flock Safety Gunshot Detection devices before 1.3 have an on-chip debug interface with improper access control.

    Published: 27 Jun 2025
    2.2
    Low

    CVE-2025-47821

    Last Modified: 23 Oct 2025

    Flock Safety Gunshot Detection devices before 1.3 have a hardcoded password for a system.

    Published: 27 Jun 2025
    6.4
    Medium

    CVE-2025-47822

    Last Modified: 23 Oct 2025

    Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have an on-chip debug interface with improper access control.

    Published: 27 Jun 2025
    2
    Low

    CVE-2025-47824

    Last Modified: 23 Oct 2025

    Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have cleartext storage of code.

    Published: 27 Jun 2025
    2
    Low

    CVE-2025-47820

    Last Modified: 24 Oct 2025

    Flock Safety Gunshot Detection devices before 1.3 have cleartext storage of code.

    Published: 27 Jun 2025
    2.1
    Low

    CVE-2025-6736

    Last Modified: 11 Jul 2025

    A vulnerability classified as critical was found in juzaweb CMS 3.4.2. Affected by this vulnerability is an unknown functionality of the file /admin-cp/theme/install of the component Add New Themes Page. The manipulation leads to improper authorization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 26 Jun 2025
    2.1
    Low

    CVE-2025-6735

    Last Modified: 11 Jul 2025

    A vulnerability classified as critical has been found in juzaweb CMS 3.4.2. Affected is an unknown function of the file /admin-cp/imports of the component Import Page. The manipulation leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 26 Jun 2025
    7.4
    High

    CVE-2025-6734

    Last Modified: 8 Jan 2026

    A vulnerability was found in UTT HiPER 840G up to 3.1.1-190328. It has been rated as critical. This issue affects the function sub_484E40 of the file /goform/formP2PLimitConfig of the component API. The manipulation of the argument except leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 26 Jun 2025
    9.8
    Critical

    CVE-2025-3699

    Last Modified: 15 Apr 2026

    Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation G-50 all versions, G-50-W all versions, G-50A all versions, GB-50 all versions, GB-50A all versions, GB-24A all versions, G-150AD all versions, AG-150A-A all versions, AG-150A-J all versions, GB-50AD all versions, GB-50ADA-A all versions, GB-50ADA-J all versions, EB-50GU-A all versions, EB-50GU-J all versions, AE-200J all versions, AE-200A all versions, AE-200E all versions, AE-50J all versions, AE-50A all versions, AE-50E all versions, EW-50J all versions, EW-50A all versions, EW-50E all versions, TE-200A all versions, TE-50A all versions, TW-50A all versions, and CMS-RMD-J all versions allows a remote unauthenticated attacker to bypass authentication and then control the air conditioning systems illegally, or disclose information in them by exploiting this vulnerability. In addition, the attacker may tamper with firmware for them using the disclosed information.

    Published: 26 Jun 2025