Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-9379

A vulnerability was determined in Belkin AX1800 1.1.00.016. Affected by this vulnerability is an unknown functionality of the component Firmware Update Handler. This manipulation causes insufficient verification of data authenticity. The attack can be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Belkin
Product
AX1800
Provider severity
HIGH
Conflicts
1

CVE-2025-9378

The Vayu Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple attributes in the Lottie block in all versions up to, and including, 1.3.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
themehunk
Product
Vayu Blocks – Website Builder for the Block Editor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9377

The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7(EU) V2 and TL-WR841N/ND(MS) V9. This issue affects Archer C7(EU) V2: before 241108 and TL-WR841N/ND(MS) V9: before 241108. Both products have reached the status of EOL (end-of-life). It's recommending to purchase the new product to ensure better performance and security. If replacement is not an option in the short term, please use the second reference link to download

PUBLISHEDCISA KEV
Vendor
TP-Link Systems Inc., TP-Link Systems Inc.
Product
TL-WR841N/ND(MS) V9, Archer C7(EU) V2
Provider severity
HIGH
Conflicts
1

CVE-2025-9376

The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for WordPress is vulnerable to unauthorized access of data due to an insufficient capability check on the 'stopbadbots_check_wordpress_logged_in_cookie' function in all versions up to, and including, 11.58. This makes it possible for unauthenticated attackers to bypass blocklists, rate limits, and other plugin functionality.

PUBLISHED
Vendor
sminozzi
Product
Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9374

The Ultimate Tag Warrior Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to import tags granted they can trick a site administrator into performing an action such as clicking on a link.

PUBLISHED
Vendor
briancolinger
Product
Ultimate Tag Warrior Importer
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9372

The Ultimate Multi Design Video Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PUBLISHED
Vendor
gbsdeveloper
Product
Ultimate Multi Design Video Carousel
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9371

The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘page_title’ parameter in all versions up to, and including, 28.1.6 due to insufficient input sanitization and output escaping of theme breadcrumbs. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
MuffinGroup
Product
Betheme
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9368

A security issue exists within 432ES-IG3 Series A, which affects GuardLink® EtherNet/IP Interface, resulting in denial-of-service. A manual power cycle is required to recover the device.

PUBLISHED
Vendor
Rockwell Automation
Product
432ES-IG3 Series A
Provider severity
HIGH
Conflicts
0

CVE-2025-9367

The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 2.11.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disab

PUBLISHED
Vendor
uscnanbu
Product
Welcart e-Commerce
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9365

Fuji Electric FRENIC-Loader 4 is vulnerable to a deserialization of untrusted data when importing a file through a specified window, which may allow an attacker to execute arbitrary code.

PUBLISHED
Vendor
Fuji Electric
Product
FRENIC-Loader 4
Provider severity
HIGH
Conflicts
1

CVE-2025-9364

An open database issue exists in the affected product and version. The security issue stems from an over permissive Redis instance. This could result in an attacker on the intranet accessing sensitive data and potential alteration of data.

PUBLISHED
Vendor
Rockwell Automation
Product
FactoryTalk® Analytics™ LogixAI®
Provider severity
HIGH
Conflicts
0

CVE-2025-9363

A vulnerability has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This affects the function portTriggerManageRule of the file /goform/portTriggerManageRule. The manipulation of the argument triggerRuleName/schedule leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure bu

PUBLISHED
Vendor
Linksys, Linksys, Linksys, Linksys, Linksys, Linksys
Product
RE6250, RE6350, RE9000, RE6500, RE6300, RE7000
Provider severity
HIGH
Conflicts
3

CVE-2025-9362

A flaw has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. The impacted element is the function urlFilterManageRule of the file /goform/urlFilterManageRule. Executing manipulation of the argument urlFilterRuleName/scheduleUrl/addURLFilter can lead to stack-based buffer overflow. The attack may be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Linksys, Linksys, Linksys, Linksys, Linksys, Linksys
Product
RE7000, RE9000, RE6350, RE6250, RE6300, RE6500
Provider severity
MEDIUM
Conflicts
3

CVE-2025-9361

A vulnerability was detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. The affected element is the function ipRangeBlockManageRule of the file /goform/ipRangeBlockManageRule. Performing manipulation of the argument ipRangeBlockRuleName/scheduleIp/ipRangeBlockRuleIpAddr results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used. The vendor was contacted early ab

PUBLISHED
Vendor
Linksys, Linksys, Linksys, Linksys, Linksys, Linksys
Product
RE6350, RE6250, RE7000, RE6300, RE9000, RE6500
Provider severity
HIGH
Conflicts
3

CVE-2025-9360

A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Impacted is the function accessControlAdd of the file /goform/accessControlAdd. Such manipulation of the argument ruleName/schedule leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in

PUBLISHED
Vendor
Linksys, Linksys, Linksys, Linksys, Linksys, Linksys
Product
RE6500, RE6350, RE9000, RE7000, RE6300, RE6250
Provider severity
HIGH
Conflicts
3

CVE-2025-9359

A weakness has been identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This issue affects the function RP_checkCredentialsByBBS of the file /goform/RP_checkCredentialsByBBS. This manipulation of the argument ssidhex/pwd causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure b

PUBLISHED
Vendor
Linksys, Linksys, Linksys, Linksys, Linksys, Linksys
Product
RE6500, RE6350, RE9000, RE7000, RE6250, RE6300
Provider severity
HIGH
Conflicts
3

CVE-2025-9358

A security flaw has been discovered in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This vulnerability affects the function setSysAdm of the file /goform/setSysAdm. The manipulation of the argument admpasshint results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not res

PUBLISHED
Vendor
Linksys, Linksys, Linksys, Linksys, Linksys, Linksys
Product
RE6300, RE7000, RE6500, RE6350, RE9000, RE6250
Provider severity
HIGH
Conflicts
3

CVE-2025-9357

A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This affects the function langSwitchByBBS of the file /goform/langSwitchByBBS. The manipulation of the argument langSelectionOnly leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any wa

PUBLISHED
Vendor
Linksys, Linksys, Linksys, Linksys, Linksys, Linksys
Product
RE7000, RE6500, RE9000, RE6350, RE6250, RE6300
Provider severity
HIGH
Conflicts
3

CVE-2025-9356

A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected by this issue is the function inboundFilterAdd of the file /goform/inboundFilterAdd. Executing manipulation of the argument ruleName can lead to stack-based buffer overflow. The attack may be performed from a remote location. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure bu

PUBLISHED
Vendor
Linksys, Linksys, Linksys, Linksys, Linksys, Linksys
Product
RE7000, RE9000, RE6250, RE6500, RE6300, RE6350
Provider severity
HIGH
Conflicts
3

CVE-2025-9355

A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected by this vulnerability is the function scheduleAdd of the file /goform/scheduleAdd. Performing manipulation of the argument ruleName results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond

PUBLISHED
Vendor
Linksys, Linksys, Linksys, Linksys, Linksys, Linksys
Product
RE6500, RE6350, RE9000, RE6300, RE6250, RE7000
Provider severity
HIGH
Conflicts
3

CVE-2025-9353

The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 7.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability was partially patched in version 7.6.9.

PUBLISHED
Vendor
themifyme
Product
Themify Builder
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9352

The Pronamic Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the description field in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
pronamic
Product
Pronamic Google Maps
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9346

The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 10.14.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
wpdevelop
Product
Booking Calendar
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9345

The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.4.8 via the ajax_downloadfile() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform actions on files outside of the originally intended directory.

PUBLISHED
Vendor
softdiscover
Product
File Manager, Code Editor, and Backup by Managefy
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9344

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'uwp_profile' and 'uwp_profile_header' shortcodes in all versions up to, and including, 1.2.42 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in page

PUBLISHED
Vendor
stiofansisland
Product
UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9343

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ticket subjects in all versions up to, and including, 3.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
elextensions
Product
ELEX WordPress HelpDesk & Customer Ticketing System
Provider severity
HIGH
Conflicts
0

CVE-2025-9342

Authorization Bypass Through User-Controlled Key vulnerability in Anadolu Hayat Emeklilik Inc. AHE Mobile allows Privilege Abuse. This issue affects AHE Mobile: from 1.9.7 before 1.9.9.

PUBLISHED
Vendor
Anadolu Hayat Emeklilik Inc.
Product
AHE Mobile
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9341

Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS bc-fips on All (API modules), Legion of the Bouncy Castle Inc. Bouncy Castle for Java LTS bcprov-lts8on on All (API modules) allows Excessive Allocation. This vulnerability is associated with program files org/bouncycastle/crypto/fips/AESNativeCBC.Java, org/bouncycastle/crypto/engines/AESNativeCBC.Java. This issue affects Bouncy Castle for Java FIPS: 2.1.0; Bouncy Castle for Java LTS:

PUBLISHED
Vendor
Legion of the Bouncy Castle Inc., Legion of the Bouncy Castle Inc.
Product
Bouncy Castle for Java FIPS, Bouncy Castle for Java LTS
Provider severity
MEDIUM
Conflicts
1

CVE-2025-9340

Out-of-bounds Write vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java bc-fips on All (API modules). This vulnerability is associated with program files org/bouncycastle/jcajce/provider/BaseCipher. This issue affects Bouncy Castle for Java: from BC-FJA 2.1.0 through 2.1.0.

PUBLISHED
Vendor
Legion of the Bouncy Castle Inc.
Product
Bouncy Castle for Java
Provider severity
NONE
Conflicts
0

CVE-2025-9339

SQL injection vulnerability in the fields of warehouse document filtering form in SIMPLE.ERP software allows logged-in user a malicious query injection. Potential exploitation is limited by the 20-character limit in form fields. Identified use case allows to delete tables with a name of maximum 6 characters. We weren't able to identify a way to exfiltrate data within query character limit. This issue affects SIMPLE.ERP in versions before 6.30@a04.3.

PUBLISHED
Vendor
Simple SA
Product
SIMPLE.ERP
Provider severity
HIGH
Conflicts
0

CVE-2025-9338

A improper restriction of operations within the bounds of a memory buffer exists in AsIO3.sys driver. This vulnerability can be triggered by manually executing a specially crafted process, potentially leading to local privilage escalation. For additional information, please refer to the 'Security Update for Armoury Crate App' section of the ASUS Security Advisory.

PUBLISHED
Vendor
ASUS
Product
Armoury Crate
Provider severity
HIGH
Conflicts
0

CVE-2025-9337

A null pointer dereference has been identified in the AsIO3.sys driver. The vulnerability can be triggered by a specially crafted input, which may lead to a system crash (BSOD). Refer to the 'Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.

PUBLISHED
Vendor
ASUS
Product
Armoury Crate
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9336

A stack buffer overflow has been identified in the AsIO3.sys driver. This vulnerability can be triggered by input manipulation, may leading to a system crash (BSOD) or other potentially undefined execution. Refer to the 'Security Update for Armoury Crate App' section on the ASUS Security Advisory for more information.

PUBLISHED
Vendor
ASUS
Product
Armoury Crate
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9334

The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Limited Code Injection in all versions up to, and including, 1.7.7. This is due to insufficient input validation and restriction on the 'rtafar_ajax' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to call arbitrary plugin functions and execute code within those functions.

PUBLISHED
Vendor
codesolz
Product
Better Find and Replace – AI-Powered Suggestions
Provider severity
HIGH
Conflicts
0

CVE-2025-9333

The Smart Docs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been di

PUBLISHED
Vendor
ibachal
Product
Smart Docs
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9332

The Interactive Human Anatomy with Clickable Body Parts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installa

PUBLISHED
Vendor
clickanatomy
Product
Interactive Human Anatomy with Clickable Body Parts
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9331

The Spacious theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'welcome_notice_import_handler' function in all versions up to, and including, 1.9.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to import demo data into the site.

PUBLISHED
Vendor
themegrill
Product
Spacious
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9330

Foxit PDF Reader Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Foxit Reader Update Service. The product loads a library from an unsecured location. An attacker can leverage

PUBLISHED
Vendor
Foxit
Product
PDF Reader
Provider severity
HIGH
Conflicts
0

CVE-2025-9329

Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PRC files. The issue results from the lack of proper validation of user-supplied data, which can result in a read

PUBLISHED
Vendor
Foxit
Product
PDF Reader
Provider severity
HIGH
Conflicts
0

CVE-2025-9328

Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PRC files. The issue results from the lack of proper validation of user-supplied data, which can result in a read

PUBLISHED
Vendor
Foxit
Product
PDF Reader
Provider severity
HIGH
Conflicts
0

CVE-2025-9327

Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PRC files. The issue results from the lack of proper validation of user-supplied data, which can result i

PUBLISHED
Vendor
Foxit
Product
PDF Reader
Provider severity
LOW
Conflicts
0

CVE-2025-9326

Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PRC files. The issue results from the lack of proper validation of user-supplied data, which can result in a read

PUBLISHED
Vendor
Foxit
Product
PDF Reader
Provider severity
HIGH
Conflicts
0

CVE-2025-9325

Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PRC files. The issue results from the lack of proper validation of user-supplied data, which can result i

PUBLISHED
Vendor
Foxit
Product
PDF Reader
Provider severity
LOW
Conflicts
0

CVE-2025-9324

Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PRC files. The issue results from the lack of proper validation of user-supplied data, which can result i

PUBLISHED
Vendor
Foxit
Product
PDF Reader
Provider severity
LOW
Conflicts
0

CVE-2025-9323

Foxit PDF Reader JP2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JP2 files. The issue results from the lack of proper validation of user-supplied data, which can result i

PUBLISHED
Vendor
Foxit
Product
PDF Reader
Provider severity
LOW
Conflicts
0

CVE-2025-9322

The Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions plugin for WordPress is vulnerable to SQL Injection via the 'wpfs-form-name' parameter in all versions up to, and including, 8.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensi

PUBLISHED
Vendor
themeisle
Product
Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions
Provider severity
HIGH
Conflicts
0

CVE-2025-9321

The WPCasa plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 1.4.1. This is due to insufficient input validation and restriction on the 'api_requests' function. This makes it possible for unauthenticated attackers to call arbitrary functions and execute code.

PUBLISHED
Vendor
wpsight
Product
WPCasa
Provider severity
CRITICAL
Conflicts
0

CVE-2025-9319

A potential vulnerability was reported in the Lenovo Wallpaper Client that could allow arbitrary code execution under certain conditions.

PUBLISHED
Vendor
Lenovo
Product
Wallpaper Client
Provider severity
HIGH
Conflicts
1

CVE-2025-9318

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based SQL Injection via the ‘is_linking’ parameter in all versions up to, and including, 10.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to e

PUBLISHED
Vendor
expresstech
Product
Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9317

The vulnerability, if exploited, could allow a miscreant with read access to Edge Project files or Edge Offline Cache files to reverse engineer Edge users' app-native or Active Directory passwords through computational brute-forcing of weak hashes.

PUBLISHED
Vendor
AVEVA
Product
Edge
Provider severity
HIGH
Conflicts
1