CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2025-41362

    Last Modified: 15 Apr 2026

    Code injection vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. This vulnerability allows an attacker to store malicious payload in software that will run in the victim's browser. Exploiting this vulnerability requires authenticating to the device and executing certain commands that can be executed with view permission.

    Published: 6 Jun 2025
    8.5
    High

    CVE-2025-47584

    Last Modified: 22 Jan 2026

    Deserialization of Untrusted Data vulnerability in ThemeGoods Photography.This issue affects Photography: from n/a through 7.5.2.

    Published: 6 Jun 2025
    8.7
    High

    CVE-2025-41360

    Last Modified: 15 Apr 2026

    Uncontrolled resource consumption vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. The device is vulnerable to a packet flooding denial of service attack.

    Published: 6 Jun 2025
    9
    Critical

    CVE-2025-47586

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Motors - Events stm-motors-events allows PHP Local File Inclusion.This issue affects Motors - Events: from n/a through <= 1.4.7.

    Published: 6 Jun 2025
    5.4
    Medium

    CVE-2025-48335

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in CyberChimps Responsive Plus responsive-add-ons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Responsive Plus: from n/a through <= 3.2.0.

    Published: 6 Jun 2025
    4.3
    Medium

    CVE-2025-48328

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Daman Jeet Real Time Validation for Gravity Forms real-time-validation-for-gravity-forms allows Cross Site Request Forgery.This issue affects Real Time Validation for Gravity Forms: from n/a through <= 1.7.0.

    Published: 6 Jun 2025
    6.5
    Medium

    CVE-2025-49076

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite the-plus-addons-for-elementor-page-builder allows Stored XSS.This issue affects The Plus Addons for Elementor Page Builder Lite: from n/a through <= 6.2.7.

    Published: 6 Jun 2025
    6.5
    Medium

    CVE-2025-49075

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Wishlist wishlist allows Stored XSS.This issue affects Wishlist: from n/a through <= 1.0.43.

    Published: 6 Jun 2025
    6.5
    Medium

    CVE-2025-49074

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Abu Huraira Bin Aman WidgetKit widgetkit-for-elementor allows Stored XSS.This issue affects WidgetKit: from n/a through <= 2.5.4.

    Published: 6 Jun 2025
    6.5
    Medium

    CVE-2025-49068

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in oceanwp Ocean Extra ocean-extra allows Stored XSS.This issue affects Ocean Extra: from n/a through <= 2.4.8.

    Published: 6 Jun 2025
    6.5
    Medium

    CVE-2025-49067

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NasaTheme Nasa Core nasa-core allows Stored XSS.This issue affects Nasa Core: from n/a through < 6.4.1.

    Published: 6 Jun 2025
    2.1
    Low

    CVE-2025-5761

    Last Modified: 10 Jun 2025

    A vulnerability, which was classified as critical, has been found in PHPGurukul BP Monitoring Management System 1.0. This issue affects some unknown processing of the file /edit-family-member.php. The manipulation of the argument memberage leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Jun 2025
    4.3
    Medium

    CVE-2025-49077

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ThemeHigh Dynamic Pricing and Discount Rules discount-and-dynamic-pricing allows Cross Site Request Forgery.This issue affects Dynamic Pricing and Discount Rules: from n/a through <= 2.2.9.

    Published: 6 Jun 2025
    5.3
    Medium

    CVE-2025-48337

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in QuickcabWP QuickCab.This issue affects QuickCab: from n/a through 1.3.3.

    Published: 6 Jun 2025
    6.4
    Medium

    CVE-2025-5239

    Last Modified: 20 Apr 2026

    The Domain For Sale plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class_name’ parameter in all versions up to, and including, 3.0.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 6 Jun 2025
    4.9
    Medium

    CVE-2025-5760

    Last Modified: 20 Apr 2026

    The Simple History plugin for WordPress is vulnerable to sensitive data exposure via Detective Mode due to improper sanitization within the append_debug_info_to_context() function in versions prior to 5.8.1. When Detective Mode is enabled, the plugin’s logger captures the entire contents of $_POST (and sometimes raw request bodies or $_GET) without redacting any password‐related keys. As a result, whenever a user submits a login form, whether via native wp_login or a third‐party login widget, their actual password is written in clear text into the logs. An authenticated attacker or any user whose actions generate a login event will have their password recorded; an administrator (or anyone with database read access) can then read those logs and retrieve every captured password.

    Published: 6 Jun 2025
    5.5
    Medium

    CVE-2025-5759

    Last Modified: 10 Jun 2025

    A vulnerability classified as critical was found in PHPGurukul Local Services Search Engine Management System 2.1. This vulnerability affects unknown code of the file /admin/edit-person-detail.php?editid=2. The manipulation of the argument editid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Jun 2025
    5.5
    Medium

    CVE-2025-5758

    Last Modified: 10 Jun 2025

    A vulnerability classified as critical has been found in SourceCodester Open Source Clinic Management System 1.0. This affects an unknown part of the file /doctor.php. The manipulation of the argument doctorname leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

    Published: 6 Jun 2025
    2
    Low

    CVE-2025-5757

    Last Modified: 13 Nov 2025

    A vulnerability was found in code-projects Traffic Offense Reporting System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /save-reported.php. The manipulation of the argument offence_id/vehicle_no/driver_license/name/address/gender/officer_reporting/offence leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Jun 2025
    5.5
    Medium

    CVE-2025-5756

    Last Modified: 23 Oct 2025

    A vulnerability was found in code-projects Real Estate Property Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /Admin/EditCity.php. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Jun 2025
    5.5
    Medium

    CVE-2025-5755

    Last Modified: 10 Jun 2025

    A vulnerability was found in SourceCodester Open Source Clinic Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /email_config.php. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Jun 2025
    8.8
    High

    CVE-2025-48784

    Last Modified: 4 Feb 2026

    A missing authorization vulnerability in Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to modify system settings without prior authorization.

    Published: 6 Jun 2025
    8.8
    High

    CVE-2025-48783

    Last Modified: 4 Feb 2026

    An external control of file name or path vulnerability in the delete file function of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to delete partial files by specifying arbitrary file paths.

    Published: 6 Jun 2025
    9.9
    Critical

    CVE-2025-48782

    Last Modified: 4 Feb 2026

    An unrestricted upload of file with dangerous type vulnerability in the upload file function of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to execute arbitrary system commands via a malicious file.

    Published: 6 Jun 2025
    8.7
    High

    CVE-2025-48781

    Last Modified: 4 Feb 2026

    An external control of file name or path vulnerability in the download file function of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to obtain partial files by specifying arbitrary file paths.

    Published: 6 Jun 2025
    9.9
    Critical

    CVE-2025-48780

    Last Modified: 4 Feb 2026

    A deserialization of untrusted data vulnerability in the download file function of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to execute arbitrary system commands via a crafted serialized object.

    Published: 6 Jun 2025
    9.3
    Critical

    CVE-2025-5192

    Last Modified: 4 Feb 2026

    A missing authentication for critical function vulnerability in the client application of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to bypass authentication and access application functions.

    Published: 6 Jun 2025
    7.4
    High

    CVE-2025-5739

    Last Modified: 20 Jun 2025

    A vulnerability classified as critical has been found in TOTOLINK X15 1.0.0-B20230714.1105. This affects an unknown part of the file /boafrm/formSaveConfig of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Jun 2025
    7.4
    High

    CVE-2025-5738

    Last Modified: 24 Jun 2025

    A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been rated as critical. Affected by this issue is some unknown functionality of the file /boafrm/formStats of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Jun 2025
    7.4
    High

    CVE-2025-5737

    Last Modified: 24 Jun 2025

    A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formDosCfg of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Jun 2025
    9.8
    Critical

    CVE-2025-3365

    Last Modified: 15 Apr 2026

    A missing protection against path traversal allows to access any file on the server.

    Published: 6 Jun 2025
    10
    Critical

    CVE-2025-3322

    Last Modified: 15 Apr 2026

    An improper neutralization of inputs used in expression language allows remote code execution with the highest privileges on the server.

    Published: 6 Jun 2025
    9.4
    Critical

    CVE-2025-3321

    Last Modified: 15 Apr 2026

    A predefined administrative account is not documented and cannot be deactivated. This account cannot be misused from the network, only by local users on the server.

    Published: 6 Jun 2025
    7.4
    High

    CVE-2025-5736

    Last Modified: 24 Jun 2025

    A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been classified as critical. Affected is an unknown function of the file /boafrm/formNtp of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Jun 2025
    7.4
    High

    CVE-2025-5735

    Last Modified: 24 Jun 2025

    A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105 and classified as critical. This issue affects some unknown processing of the file /boafrm/formSetLg of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Jun 2025
    7.4
    High

    CVE-2025-5734

    Last Modified: 23 Jun 2025

    A vulnerability has been found in TOTOLINK X15 1.0.0-B20230714.1105 and classified as critical. This vulnerability affects unknown code of the file /boafrm/formWlanRedirect of the component HTTP POST Request Handler. The manipulation of the argument redirect-url leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Jun 2025
    2.1
    Low

    CVE-2025-5732

    Last Modified: 13 Nov 2025

    A vulnerability, which was classified as problematic, was found in code-projects Traffic Offense Reporting System 1.0. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Jun 2025
    2.1
    Low

    CVE-2025-5729

    Last Modified: 25 Jun 2025

    A vulnerability, which was classified as critical, was found in code-projects Health Center Patient Record Management System 1.0. Affected is an unknown function of the file /birthing_record.php. The manipulation of the argument itr_no leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Jun 2025
    2.1
    Low

    CVE-2025-5728

    Last Modified: 10 Jun 2025

    A vulnerability classified as critical was found in SourceCodester Open Source Clinic Management System 1.0. This vulnerability affects unknown code of the file /manage_website.php. The manipulation of the argument website_image leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Jun 2025
    6.7
    Medium

    CVE-2025-48908

    Last Modified: 11 Jul 2025

    Ability Auto Startup service vulnerability in the foundation process Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 6 Jun 2025
    8.2
    High

    CVE-2025-48911

    Last Modified: 11 Jul 2025

    Vulnerability of improper permission assignment in the note sharing module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 6 Jun 2025
    5.5
    Medium

    CVE-2025-48910

    Last Modified: 11 Jul 2025

    Buffer overflow vulnerability in the DFile module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 6 Jun 2025
    7.1
    High

    CVE-2025-48909

    Last Modified: 11 Jul 2025

    Bypass vulnerability in the device management channel Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 6 Jun 2025
    6.4
    Medium

    CVE-2025-5686

    Last Modified: 20 Apr 2026

    The Paged Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gallery' shortcode in all versions up to, and including, 0.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 6 Jun 2025
    6.5
    Medium

    CVE-2025-5563

    Last Modified: 20 Apr 2026

    The WP-Addpub plugin for WordPress is vulnerable to SQL Injection via the 'wp-addpub' shortcode in all versions up to, and including, 1.2.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 6 Jun 2025
    9.8
    Critical

    CVE-2025-5486

    Last Modified: 15 Apr 2026

    The WP Email Debug plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the WPMDBUG_handle_settings() function in versions 1.0 to 1.1.0. This makes it possible for unauthenticated attackers to enable debugging and send all emails to an attacker controlled address and then trigger a password reset for an administrator to gain access to an administrator account.

    Published: 6 Jun 2025
    6.4
    Medium

    CVE-2025-5541

    Last Modified: 20 Apr 2026

    The Runners Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'runnerslog' shortcode in all versions up to, and including, 3.9.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 6 Jun 2025
    6.4
    Medium

    CVE-2025-5565

    Last Modified: 21 Apr 2026

    The Hide It plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hideit' shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 6 Jun 2025
    5.4
    Medium

    CVE-2025-2935

    Last Modified: 20 Apr 2026

    The Anti-Spam: Spam Protection | Block Spam Users, Comments, Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2024.7. This is due to missing or incorrect nonce validation in the 'ss_option_maint.php' and 'ss_user_filter_list' files. This makes it possible for unauthenticated attackers to delete pending comments, and re-enable a previously blocked user via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 6 Jun 2025
    6.4
    Medium

    CVE-2025-5538

    Last Modified: 20 Apr 2026

    The BNS Featured Category plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bnsfc' shortcode in all versions up to, and including, 2.8.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 6 Jun 2025