Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-8498

A security vulnerability has been detected in code-projects Online Medicine Guide 1.0. This vulnerability affects unknown code of the file /cart/index.php. Such manipulation of the argument uname leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

PUBLISHED
Vendor
code-projects
Product
Online Medicine Guide
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-8497

A weakness has been identified in code-projects Online Medicine Guide 1.0. This affects an unknown part of the file /cusfindphar2.php. This manipulation of the argument Search causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited.

PUBLISHED
Vendor
code-projects
Product
Online Medicine Guide
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-8496

A vulnerability has been found in projectworlds Online Admission System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /viewform.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
projectworlds
Product
Online Admission System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-8495

A vulnerability, which was classified as critical, was found in code-projects Intern Membership Management System 1.0. Affected is an unknown function of the file /admin/edit_admin_query.php. The manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Intern Membership Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-8494

A vulnerability, which was classified as critical, has been found in code-projects Intern Membership Management System 1.0. This issue affects some unknown processing of the file /admin/delete_student.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Intern Membership Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-8493

A vulnerability classified as critical was found in code-projects Intern Membership Management System 1.0. This vulnerability affects unknown code of the file /admin/edit_student_query.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Intern Membership Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-8492

The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax function in all versions up to, and including, 10.22. This makes it possible for unauthenticated attackers to execute AJAX actions, including limited file uploads.

PUBLISHED
Vendor
wordpresschef
Product
Salon Booking System – Free Version
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8491

The Easy restaurant menu manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.2. This is due to missing or incorrect nonce validation on the nsc_eprm_save_menu() function. This makes it possible for unauthenticated attackers to upload a menu file via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PUBLISHED
Vendor
nikelschubert
Product
Easy restaurant menu manager
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8490

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Import in all versions up to, and including, 7.97 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has bee

PUBLISHED
Vendor
servmask
Product
All-in-One WP Migration and Backup
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8489

The King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor plugin for WordPress is vulnerable to privilege escalation in versions 24.12.92 to 51.1.14 . This is due to the plugin not properly restricting the roles that users can register with. This makes it possible for unauthenticated attackers to register with administrator-level user accounts.

PUBLISHED
Vendor
kingaddons
Product
King Addons for Elementor – 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementor
Provider severity
CRITICAL
Conflicts
0

CVE-2025-8488

The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_hfe_compatibility_option_callback ()function in all versions up to, and including, 2.4.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the compatibility option setting.

PUBLISHED
Vendor
brainstormforce
Product
Ultimate Addons for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8487

The Kubio AI Page Builder plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the kubio-image-hub-install-plugin AJAX action in all versions up to, and including, 2.6.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install the Image Hub plugin.

PUBLISHED
Vendor
extendthemes
Product
Kubio AI Page Builder
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8486

A potential vulnerability was reported in PC Manager that could allow a local authenticated user to execute code with elevated privileges.

PUBLISHED
Vendor
Lenovo
Product
PC Manager
Provider severity
HIGH
Conflicts
1

CVE-2025-8485

An improper permissions vulnerability was reported in Lenovo App Store that could allow a local authenticated user to execute code with elevated privileges during installation of an application.

PUBLISHED
Vendor
Lenovo
Product
App Store
Provider severity
HIGH
Conflicts
1

CVE-2025-8484

The Code Quality Control Tool plugin for WordPress is vulnerable to Sensitive Information Exposure in version 2.1 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed log files.

PUBLISHED
Vendor
nickclarkweb
Product
Code Quality Control Tool
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8483

The The Discussion Board – WordPress Forum Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.5.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes.

PUBLISHED
Vendor
marketingfire
Product
Discussion Board – WordPress Forum Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8482

The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of data in version 2.8.4. This is due to a missing capability check on the migrate_from_wp_user_avatar() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to migrate avatar metadata for all users.

PUBLISHED
Vendor
10up
Product
Simple Local Avatars
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8481

The Blog Designer For Elementor – Post Slider, Post Carousel, Post Grid plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.1.7. This is due to missing or incorrect nonce validation on the bdfe_install_activate_rswpbs_only function. This makes it possible for unauthenticated attackers to install the 'rs-wp-books-showcase' plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PUBLISHED
Vendor
mdimran41
Product
Blog Designer For Elementor – Post Slider, Post Carousel, Post Grid
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8480

Alpine iLX-507 Command Injection Remote Code Execution. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine iLX-507 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Tidal music streaming application. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute co

PUBLISHED
Vendor
Alpine
Product
iLX-507
Provider severity
HIGH
Conflicts
0

CVE-2025-8479

The Zoho Flow plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.14.1. This is due to missing or incorrect nonce validation on the zoho_flow_deactivate_plugin function. This makes it possible for unauthenticated attackers to modify typography settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PUBLISHED
Vendor
zohoflow
Product
Zoho Flow – Integrate 100+ plugins with 1000+ business apps, no-code workflow automation
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8477

Alpine iLX-507 vCard Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Alpine iLX-507 devices. User interaction is required to exploit this vulnerability in that the target must connect to a malicious Bluetooth device. The specific flaw exists within the parsing of vCard data. The issue results from the lack of proper validation of user-supplied data prior to copying it to a fixed-l

PUBLISHED
Vendor
Alpine
Product
iLX-507
Provider severity
HIGH
Conflicts
0

CVE-2025-8476

Alpine iLX-507 TIDAL Improper Certificate Validation Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine iLX-507 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the TIDAL music streaming application. The issue results from improper certificate validation. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the conte

PUBLISHED
Vendor
Alpine
Product
iLX-507
Provider severity
HIGH
Conflicts
0

CVE-2025-8475

Alpine iLX-507 AVRCP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine iLX-507 devices. User interaction is required to exploit this vulnerability in that the target must connect to a malicious Bluetooth device. The specific flaw exists within the implementation of the AVRCP protocol. The issue results from the lack of proper validation of the length of user-supplied

PUBLISHED
Vendor
Alpine
Product
iLX-507
Provider severity
HIGH
Conflicts
0

CVE-2025-8474

Alpine iLX-507 CarPlay Stack-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Alpine iLX-507 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the Apple CarPlay protocol. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based b

PUBLISHED
Vendor
Alpine
Product
iLX-507
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8473

Alpine iLX-507 UPDM_wstpCBCUpdStart Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Alpine iLX-507 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the UPDM_wstpCBCUpdStart function. The issue results from the lack of proper validation of user-supplied data before using it to execute a system call. An attacker can leverage this vulnerability to exe

PUBLISHED
Vendor
Alpine
Product
iLX-507
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8472

Alpine iLX-507 vCard Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine iLX-507 devices. User interaction is required to exploit this vulnerability in that the target must connect to a malicious Bluetooth device. The specific flaw exists within the parsing of vCard data. The issue results from the lack of proper validation of the length of user-supplied data p

PUBLISHED
Vendor
Alpine
Product
iLX-507
Provider severity
HIGH
Conflicts
0

CVE-2025-8471

A vulnerability, which was classified as critical, has been found in projectworlds Online Admission System 1.0. This issue affects some unknown processing of the file /adminlogin.php. The manipulation of the argument a_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
projectworlds
Product
Online Admission System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-8470

A vulnerability classified as critical was found in SourceCodester Online Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /admin/deleteroom.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
SourceCodester
Product
Online Hotel Reservation System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-8469

A vulnerability classified as critical has been found in SourceCodester Online Hotel Reservation System 1.0. This affects an unknown part of the file /admin/deletegallery.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
SourceCodester
Product
Online Hotel Reservation System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-8468

A vulnerability was found in code-projects Wazifa System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /controllers/reset.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Wazifa System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-8467

A vulnerability was found in code-projects Wazifa System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /controllers/regcontrol.php. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Wazifa System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-8466

A vulnerability was found in code-projects Online Farm System 1.0. It has been classified as critical. Affected is an unknown function of the file /forgot_passfarmer.php. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Online Farm System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-8464

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.3.9.0 via the wpcf7_guest_user_id cookie. This makes it possible for unauthenticated attackers to upload and delete files outside of the originally intended directory. The impact of this vulnerability is limited, as file types are validated and only safe ones can be uploaded, while deletion is limited to the plugin's uploads folder.

PUBLISHED
Vendor
glenwpcoder
Product
Drag and Drop Multiple File Upload for Contact Form 7
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8463

Authorization Bypass Through User-Controlled Key vulnerability in SecHard Information Technologies SecHard allows Forceful Browsing. This issue affects SecHard: before 3.6.2-20250805.

PUBLISHED
Vendor
SecHard Information Technologies
Product
SecHard
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8462

The RT Easy Builder – Advanced addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the social URL parameter in all versions up to, and including, 2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
risetheme
Product
RT Easy Builder – Advanced addons for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8461

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Seres Software syWEB allows Reflected XSS. This issue affects syWEB: through 03022026.  NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Seres Software
Product
syWEB
Provider severity
HIGH
Conflicts
0

CVE-2025-8460

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Notification rules, Open tickets module) allows Stored XSS by users with elevated privileges.This issue affects Infra Monitoring: from 24.10.0 before 24.10.5, from 24.04.0 before 24.04.5, from 23.10.0 before 23.10.4.

PUBLISHED
Vendor
Centreon
Product
Infra Monitoring
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8459

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Monitoring recurrent downtime scheduler modules) allows Stored XSS.This issue affects Infra Monitoring: from 24.10.0 before 24.10.13, from 24.04.0 before 24.04.18, from 23.10.0 before 23.10.28.

PUBLISHED
Vendor
Centreon
Product
Infra Monitoring
Provider severity
HIGH
Conflicts
0

CVE-2025-8456

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kod8 Software Technologies Trade Ltd. Co. Kod8 Individual and SME Website allows Reflected XSS. This issue affects Kod8 Individual and SME Website: through 03022026.  NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Kod8 Software Technologies Trade Ltd. Co.
Product
Kod8 Individual and SME Website
Provider severity
HIGH
Conflicts
0

CVE-2025-8454

It was discovered that uscan, a tool to scan/watch upstream sources for new releases of software, included in devscripts (a collection of scripts to make the life of a Debian Package maintainer easier), skips OpenPGP verification if the upstream source is already downloaded from a previous run even if the verification failed back then.

PUBLISHED
Vendor
Debian
Product
devscripts
Provider severity
CRITICAL
Conflicts
0

CVE-2025-8453

CWE-269: Improper Privilege Management vulnerability exists that could cause privilege escalation and arbitrary code execution when a privileged engineer user with console access modifies a configuration file used by a root-level daemon to execute custom scripts.

PUBLISHED
Vendor
Schneider Electric, Schneider Electric
Product
Saitel DP RTU, Saitel DR RTU
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-8452

By using the "uscan" protocol provided by the eSCL specification, an attacker can discover the serial number of multi-function printers that implement the Brother-provided firmware. This serial number can, in turn, can be leveraged by the flaw described by CVE-2024-51978 to calculate the default administrator password. This flaw is similar to CVE-2024-51977, with the only difference being the protocol by which an attacker can use to learn the remote device's serial number. The eSCL/uscan vector

PUBLISHED
Vendor
Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Konica Minolta, Inc., Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Konica Minolta, Inc., Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Konica Minolta, Inc., Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Toshiba Tec, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Toshiba Tec, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Konica Minolta, Inc., Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd, Brother Industries, Ltd
Product
MFC-L2802DW, DCP-L2620DW, ADS-4500W, DCP-9030CDN, DCP-B7535DW, DCP-L5518DN, DCP-B7640DWB, MFC-L2760DW, MFC-J6959DW, MFC-L2750DW, DCP-L5502DN, MFC-J6535DW, MFC-J5830DW, MFC-L5850DW, DCP-L2605DW, MFC-L8340CDW, bizhub 5000i, DCP-L2628DW, MFC-B7800DN, MFC-B7810DWB, DCP-T830DW, MFC-L6800DW, DCP-T226, NFC-J903N, bizhub 4020i, MFC-L6950DW, DCP-L2660DW, MFC-L3755CDW, MFC-J998DN, DCP-T510W(for China), MFC-J738DWN, MFC-L8900CDW, MFC-L6720DW, MFC-L2710DWR, MFC-L5710DN, DCP-J582N, MFC-L8610CDW, DCP-L2551DN, MFC-L2710DW, MFC-J497DW, MFC-L6810DW, MFC-L2802DN, MFC-8530DN, MFC-L2715DW(for Tiwan, Koria), MFC-L5750DW, bizhub 4000i, MFC-L6910DN, MFC-J5730DW, MFC-J1500N, MFC-J4540DW(XL), DCP-B7600DB, DCP-T439W, MFC-J5800CDW, MFC-L5715DN, DCP-B7640DW, ADS-4700W, MFC-J6583CDW, MFC-T925DW, MFC-L2820DWXL, MFC-J6940DW, DCP-L5610DN, DCP-J528N, DCP-T426W, MFC-EX910, DCP-B7600D, MFC-J5845DW(XL), DCP-7190DW, MFC-L6902DW, DCP-J928N-WB, MFC-L2716DW, MFC-J491DW, MFC-J4440N, MFC-J739DN, MFC-J6555DW XL, MFC-L2713DW, MFC-J7700CDW, DCP-T825DW, MFC-B7720DN, DCP-J1200N, MFC-T935DW, MFC-J5345DW, DCP-L6600DW, e-STUDIO302DNF, MFC-L2717DW, MFC-J3930DW, MFC-L2980DW, DCP-J4143N, DCP-L3520CDWE, DCP-L2518DW, DCP-B7558W, DCP-J987N-B, MFC-J3530DW, DCP-L3560CDW, MFC-L3765CDW, DCP-C1210N, MFC-L6915DN CSP, MFC-9350CDW, MFC-L3710CDW, MFC-L2886DW, DCP-L3568CDW, MFC-J2340DW, DCP-J981N, MFC-J898N, MFC-J904N, MFC-L5718DN, DCP-L3515CDW, MFC-J6980CDW, MFC-J1300DW, DCP-T820DW, MFC-L9570CDW(for Japan), DCP-J1203N, DCP-T536DW, MFC-J4443N, MFC-EX670W, MFC-L2750DWR, MFC-L2880DW, DCP-L2640DN, HL-J6000CDW, MFC-L5700DW, MFC-L2860DWE, MFC-J893N, MFC-L5802DW, MFC-L2880DWXL, DCP-L2665DW, DCP-B7620DWB, DCP-B7578DW, DCP-J1200W(XL), MFC-L5902DW, DCP-J1800DW, MFC-L5700DN, MFC-L2750DWXL, MFC-L2690DW, MFC-L2827DW, MFC-L5715DW, NFC-EX670, MFC-L9570CDW, MFC-J939DN, ADS-1350W, HL-L3300CDW, DCP-L2550DN, MFC-T4500DW, MFC-L2807DW, DCP-J1200WE, MFC-J815DW XL, MFC-9150CDN, e-STUDIO301DN, MFC-L3730CDN, MFC-L6900DWG, MFC-L2710DNR, MFC-J1215W, DCP-L2531DW, MFC-L5728DW, MFC-L6970DW, MFC-J926N-WB, ADS-4300N, MFC-J5335DW, MFC-L3760CDW, MFC-L6912DW, DCP-J914N, MFC-J6947DW, MFC-L2771DW, HL-L2395DW, DCP-B7658DW, MFC-L3770CDW, DCP-T220, DCP-B7530DN, DCP-L3517CDW, DCP-T420W, MFC-7895DW, MFC-L2806DW, MFC-L3740CDW, ADS-4900W, DCP-T725DW, MFC-EX915DW, DCP-L2530DWR, MFC-L2827DWXL, MFC-J6995CDW, MFC-L2900DW, DCP-J1050DW, DCP-T730DW, DCP-L1848W, MFC-L9670CDN, ADS-3300W, DCP-B7650DW, DCP-T510W, MFC-L5710DW, DCP-T520W, MFC-J805DW, MFC-J6540DW, MFC-J5945DW, DCP-T735DW, MFC-L8690CDW, DCP-T436W, MFC-L5900DW, MFC-J4440DW, MFC-J7500CDW, DCP-T710W, DCP-J982N-W/B, MFC-L5702DW, DCP-J577N, MFC-L2862DW, MFC-L2715DW, FAX-L2710DN, MFC-J5955DW, MFC-L6915DW, HL-L3290CDW, MFC-L2960DW, DCP-J987N-W, DCP-L2627DWE, ADS-2700We, MFC-J5855DW XL, MFC-J5340DW, MFC-L6700DW, DCP-J587N, MFC-J5630CDW, MFC-L8395CDW, DCP-L3520CDW, MFC-J4345DW XL, MFC-J1170DW, MFC-T930DW, MFC-L2732DW, MFC-L2885DW, DCP-J774DW, MFC-L8610CDW(for Japan), MFC-L6820DW, MFC-L2712DN, HL-J6000DW, MFC-L3750CDW, MFC-J690DW, HL-L5218DN, DCP-L8410CDW, DCP-C421W, DCP-L3555CDW, DCP-J526N, DCP-L5602DN, MFC-J995DW, MFC-L5800DW, MFC-J6555DW, DCP-L3528CDW, MFC-L2712DW, MFC-L5912DW, MFC-J7300CDW, DCP-L2625DW, DCP-J973N-W/B, DCP-T535DW, HL-L2464DW, DCP-L5510DW, DCP-J4543N, MFC-B7715DW, DCP-T710W(for China), DCP-L2627DW, DCP-L5662DN, MFC-L2730DW, MFC-J3540DW, DCP-L2640DW, MFC-J6957DW, DCP-T720DW, DCP-L2550DW(TWN), DCP-J572N, DCP-L5600DN, MFC-J1205W(XL), MFC-J5330DW, DCP-L2600D, MFC-L2835DW, MFC-J4540N, DCP-B7648DW, MFC-J805DW XL, DS/MDS-940DW, DCP-T835DW, MFC-J905N, DCP-L2648DW, MFC-J6955DW, DCP-T425W, MFC-L2730DWR, MFC-4340DWE, DCP-B7638DN, HL-L2465DW, MFC-L2730DN, DCP-L2508DW, MFC-J939DWN, DCP-L2548DW, MFC-J6530DW, MFC-J4340DW(XL), MFC-L5915DW, DCP-T530DW, DCP-L3551CDW, HL-L2480DW, MFC-L9630CDN, HL-J6100DW, MFC-J2330DW, MFC-L3780CDW, MFC-J1012DW, MFC-L2860DW, MFC-L2765DW, DCP-7195DW, MFC-T810W, DCP-L2552DN, DCP-L2550DNR, MFC-L2710DN, DCP-L2600DW, MFC-L3745CDW, DCP-J1700DW, MFC-L9577CDW, MFC-L5755DW, DCP-L2622DW, DCP-J4140N, DCP-J972N, DCP-L2535DW, MFC-J6983CDW, DCP-L2551DW, MFC-L8390CDW, ADS-1800W, MFC-L6750DW, DCP-L5500DN, MFC-B7810DW, DCP-L5512DN, MFC-J6999CDW, DCP-B7548W, MFC-T810W(for China), MFC-L2820DW, MFC-L3768CDW, DCP-L5510DN, HL-L2390DW, DCP-L3550CDW, DCP-L2532DW, DCP-L1638W, DCP-L5650DN, DCP-T430W, DCP-J1140DW, DCP-J915N, DCP-L1630W, MFC-L2817DW, HL-L5228DW, MFC-J6540DWE, DCP-B7628DW, MFC-J4335DW(XL), MFC-J7600CDW, DCP-L2530DW, MFC-J890DW, MFC-L6915DN, DCP-L5660DN, MFC-J6935DW, MFC-7890DN, MFC-J5340DWE, MFC-L9610CDN, MFC-B7811DW, MFC-L3740CDWE, MFC-J995DW XL, DCP-L2647DW, MFC-L2800DW, MFC-L6900DW, bizhub 5020i, MFC-J895DW, MFC-J7100CDW, MFC-J998DWN, MFC-L2751DW, MFC-8540DN, DCP-T435W, DCP-7090DW, DCP-L3510CDW, MFC-L3720CDW, DCP-T225, MFC-J6580CDW, MFC-L2861DW, FAX-L2800DW, MFC-J1605DN, MFC-J5930DW, MFC-J3940DW, MFC-J739DWN, DCP-L2680DW, MFC-J4940DN, DCP-J772DW, DCP-J1100DW, DCP-B7608W, MFC-J2730DW, MFC-T910DW, MFC-J6740DW, MFC-J6997CDW, MFC-L2770DW, MFC-L9635CDN, MFC-L2922DW, MFC-J738DN, MFC-J1010DW, MFC-L6710DW, DCP-J988N, DCP-J572DW, DCP-L2537DW, MFC-L2805DW, MFC-J6945DW, MFC-L2920DW, MFC-J5855DW, MFC-L5717DW, MFC-J6730DW, DCP-B7520DW, DCP-B7620DW, DCP-L2627DWXL, DCP-L1632W, MFC-J4535DW(XL), DCP-J978N-W/B, MFC-J6930DW, DCP-T428W, MFC-J1800DW, DCP-T525W, DCP-L5652DN, DCP-J1800N, MFC-T920DW, MFC-J5740DW, MFC-L6702DW, DCP-7190DN, HL-L2475DW, DCP-L2550DW, MFC-L3735CDN, MFC-L2900DWXL
Provider severity
MEDIUM
Conflicts
1

CVE-2025-8451

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘data-gallery-items’ parameter in all versions up to, and including, 6.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
wpdevteam
Product
Essential Addons for Elementor – Popular Elementor Templates & Widgets
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8450

Improper Access Control issue in the Workflow component of Fortra's FileCatalyst allows unauthenticated users to upload arbitrary files via the order forms page.

PUBLISHED
Vendor
Fortra
Product
FileCatalyst
Provider severity
HIGH
Conflicts
1

CVE-2025-8449

CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause a denial of service when an authenticated user sends a specially crafted request to a specific endpoint from within the BMS network.

PUBLISHED
Vendor
Schnieder Electric, Schneider Electric, Schneider Eelctric
Product
EcoStruxure Building Operation Enterprise Server, EcoStruxure Enterprise Server, EcoStruxure Building Operation Workstation
Provider severity
MEDIUM
Conflicts
1

CVE-2025-8448

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause unauthorized access to sensitive credential data when an attacker is able to capture local SMB traffic between a valid user within the BMS network and the vulnerable products.

PUBLISHED
Vendor
Schneider Eelctric, Schneider Electric, Schneider Eelctric
Product
EcoStruxure Building Operation Enterprise Server, EcoStruxure Enterprise Server, EcoStruxure Building Operation Workstation
Provider severity
LOW
Conflicts
1

CVE-2025-8447

An improper access control vulnerability was identified in GitHub Enterprise Server that allowed users with access to any repository to retrieve limited code content from another repository by creating a diff between the repositories. To exploit this vulnerability, an attacker needed to know the name of a private repository along with its branches, tags, or commit SHAs that they could use to trigger compare/diff functionality and retrieve limited code without proper authorization. This vulnerabi

PUBLISHED
Vendor
GitHub
Product
Enterprise Server
Provider severity
HIGH
Conflicts
0

CVE-2025-8446

The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized limited plugin install due to a missing capability check on the 'blaze_demo_importer_install_plugin' function in all versions up to, and including, 1.0.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate a limited number of specific plugins. The News Kit Elementor Addons plugin and a BlazeThemes theme must be installed and activated in order to exploit th

PUBLISHED
Vendor
blazethemes
Product
Blaze Demo Importer
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8445

The Countdown Timer for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'countdown_label' Parameter in all versions up to, and including, 1.3.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
shaikhaezaz80
Product
Countdown Timer for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8444

The Animation Addons for Elementor – GSAP Powered Elementor Addons & Website Templates plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the multiple parameters in all versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
wealcoder
Product
Animation Addons for Elementor – GSAP Motion Elementor Addons & Website Templates
Provider severity
MEDIUM
Conflicts
0