Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-8443

A vulnerability was found in code-projects Online Medicine Guide 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument uname leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Online Medicine Guide
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-8442

A vulnerability has been found in code-projects Online Medicine Guide 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /cussignup.php. The manipulation of the argument uname leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Online Medicine Guide
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-8441

A vulnerability, which was classified as critical, was found in code-projects Online Medicine Guide 1.0. Affected is an unknown function of the file /pharsignup.php. The manipulation of the argument phuname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Online Medicine Guide
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-8440

The Team Members plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the first and last name fields in all versions up to, and including, 5.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
spwebguy
Product
Team Members
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8439

A vulnerability, which was classified as critical, has been found in code-projects Wazifa System 1.0. This issue affects some unknown processing of the file /controllers/updatesettings.php. The manipulation of the argument Password leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Wazifa System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-8438

A vulnerability classified as critical was found in code-projects Wazifa System 1.0. This vulnerability affects unknown code of the file /controllers/postpublish.php. The manipulation of the argument post leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Wazifa System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-8437

A vulnerability classified as critical has been found in code-projects Kitchen Treasure 1.0. This affects an unknown part of the file /userregistration.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Kitchen Treasure
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-8436

A vulnerability was found in projectworlds Online Admission System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /viewdoc.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
projectworlds
Product
Online Admission System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-8435

A vulnerability was found in code-projects Online Movie Streaming 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin-control.php. The manipulation of the argument ID leads to missing authorization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Online Movie Streaming
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-8434

A vulnerability was found in code-projects Online Movie Streaming 1.0. It has been classified as critical. Affected is an unknown function of the file /admin.php. The manipulation of the argument ID leads to missing authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Online Movie Streaming
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-8433

A vulnerability was found in code-projects Document Management System 1.0 and classified as critical. This issue affects the function unlink of the file /dell.php. The manipulation of the argument ID leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Document Management System
Provider severity
MEDIUM
Conflicts
1

CVE-2025-8432

Incorrect Default Permissions vulnerability in Centreon Infra Monitoring (MBI modules) allows Embedding Scripts within Scripts by CentreonBI user account on the MBI server This issue affects Infra Monitoring: from 24.10.0 before 24.10.6, from 24.04.0 before 24.04.9, from 23.10.0 before 23.10.15.

PUBLISHED
Vendor
Centreon
Product
Infra Monitoring
Provider severity
HIGH
Conflicts
0

CVE-2025-8431

A vulnerability has been found in PHPGurukul Boat Booking System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/add-boat.php. The manipulation of the argument boatname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
PHPGurukul
Product
Boat Booking System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-8430

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Commands Connectors configuration modules) allows Stored XSS by users with elevated privileges. This issue affects Infra Monitoring: from 24.10.0 before 24.10.13, from 24.04.0 before 24.04.18, from 23.10.0 before 23.10.28.

PUBLISHED
Vendor
Centreon
Product
Infra Monitoring
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8429

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (ACL Action access configuration modules) allows Stored XSS by users with elevated privileges. This issue affects Infra Monitoring: from 24.10.0 before 24.10.13, from 24.04.0 before 24.04.18, from 23.10.0 before 23.10.28.

PUBLISHED
Vendor
Centreon
Product
Infra Monitoring
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8428

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (HTTP Loader widget modules) allows Stored XSS.This issue affects Infra Monitoring: from 24.10.0 before 24.10.13, from 24.04.0 before 24.04.18, from 23.10.0 before 23.10.28.

PUBLISHED
Vendor
Centreon
Product
Infra Monitoring
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8427

The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘auto_play’ parameter in all versions up to, and including, 2.9.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
The Beaver Builder Team
Product
Beaver Builder Plugin (Starter Version)
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8426

Marvell QConvergeConsole compressConfigFiles Directory Traversal Information Disclosure and Denial-of-Service Vulnerability. This vulnerability allows remote attackers to disclose sensitive information or to create a denial-of-service condition on affected installations of Marvell QConvergeConsole. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the compressConfigFiles method. The issue results from the lack of proper validatio

PUBLISHED
Vendor
Marvell
Product
QConvergeConsole
Provider severity
CRITICAL
Conflicts
0

CVE-2025-8425

The My WP Translate plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the ajax_import_strings() function in all versions up to, and including, 1.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration

PUBLISHED
Vendor
mythemeshop
Product
My WP Translate
Provider severity
HIGH
Conflicts
0

CVE-2025-8424

Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway when an attacker can get access to the appliance NSIP, Cluster Management IP or local GSLB Site IP or SNIP with Management Access

PUBLISHED
Vendor
NetScaler, NetScaler
Product
ADC, Gateway
Provider severity
HIGH
Conflicts
1

CVE-2025-8423

The My WP Translate plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mtswpt_remove_plugin() and ajax_update_export_code() functions in all versions up to, and including, 1.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read and delete arbitrary WordPress options which can cause a denial of service.

PUBLISHED
Vendor
mythemeshop
Product
My WP Translate
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8422

The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.7.6.7 via the send_email() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

PUBLISHED
Vendor
fassionstorage
Product
Propovoice: All-in-One Client Management System
Provider severity
HIGH
Conflicts
0

CVE-2025-8421

An improper default permission vulnerability was reported in Lenovo Dock Manager that, under certain conditions during installation, could allow an authenticated local user to redirect log files with elevated privileges.

PUBLISHED
Vendor
Lenovo
Product
Dock Manager
Provider severity
MEDIUM
Conflicts
1

CVE-2025-8420

Multiple plugins for WordPress by emarket-design with the 'emd-form-builder-lite' package are vulnerable to Remote Code Execution in various versions via the emd_form_builder_lite_pagenum function. This is due to the plugin not properly validating user input before using it as a function name. This makes it possible for unauthenticated attackers to execute code on the server, however, parameters can not be passed to the functions called

PUBLISHED
Vendor
emarket-design, emarket-design, cyberlord92, emarket-design, emarket-design, emarket-design, emarket-design, emarket-design
Product
Campus Directory – Faculty, Staff & Student Directory Plugin for WordPress, Request a Quote Form Plugin – Price Quote Request Management Made Easy, Employee Directory – Staff Directory and Listing, Video Gallery – YouTube Gallery & Responsive Video Playlist, Simple Contact Form Plugin for WordPress – WP Easy Contact, Project Management, Bug and Issue Tracking Plugin – Software Issue Manager, Event RSVP and Simple Event Management Plugin, Customer Support Ticket System & Helpdesk Plugin for WordPress
Provider severity
HIGH
Conflicts
1

CVE-2025-8419

A vulnerability was found in Keycloak-services. Special characters used during e-mail registration may perform SMTP Injection and unexpectedly send short unwanted e-mails. The email is limited to 64 characters (limited local part of the email), so the attack is limited to very shorts emails (subject and little data, the example is 60 chars). This flaw's only direct consequence is an unsolicited email being sent from the Keycloak server. However, this action could be a precursor for more sophisti

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Keycloak, Red Hat, Red Hat
Product
Red Hat build of Keycloak 26.0, Red Hat build of Keycloak 26.2, Red Hat build of Keycloak 26.0, Red Hat build of Keycloak 26.0, Red Hat build of Keycloak 26.2, Red Hat build of Keycloak 26.2, keycloak, Red Hat build of Keycloak 26.0, Red Hat build of Keycloak 26.2
Provider severity
MEDIUM
Conflicts
1

CVE-2025-8418

The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Arbitrary Plugin Installation in all versions up to, and including, 1.1.30. This is due to missing capability checks on the activated_plugin function. This makes it possible for authenticated attackers, with subscriber-level access and above, to install arbitrary plugins on the server which can make remote code execution possible.

PUBLISHED
Vendor
bplugins
Product
bSlider – Create Responsive Image, Post, Product, and Video Sliders
Provider severity
HIGH
Conflicts
0

CVE-2025-8417

The Catalog Importer, Scraper & Crawler plugin for WordPress is vulnerable to PHP code injection in all versions up to, and including, 5.1.4. This is due to reliance on a guessable numeric token (e.g. ?key= 900001705) without proper authentication, combined with the unsafe use of eval() on user-supplied input. This makes it possible for unauthenticated attackers to execute arbitrary PHP code on the server via a forged request granted they can guess or brute-force the numeric key.

PUBLISHED
Vendor
idiatech
Product
Catalog Importer, Scraper & Crawler
Provider severity
HIGH
Conflicts
0

CVE-2025-8416

The Product Filter by WBW plugin for WordPress is vulnerable to SQL Injection via the 'filtersDataBackend' parameter in all versions up to, and including, 2.9.7. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PUBLISHED
Vendor
woobewoo
Product
Product Filter for WooCommerce by WBW
Provider severity
HIGH
Conflicts
0

CVE-2025-8415

A vulnerability was found in the Cryostat HTTP API. Cryostat's HTTP API binds to all network interfaces, allowing possible external visibility and access to the API port if Network Policies are disabled, allowing an unauthenticated, malicious attacker to jeopardize the environment.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Cryostat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Cryostat 4 on RHEL 9, Cryostat 4 on RHEL 9, Cryostat 4 on RHEL 9, Cryostat 4, Cryostat 4 on RHEL 9, Cryostat 4 on RHEL 9, Cryostat 4 on RHEL 9, Cryostat 4 on RHEL 9, Cryostat 4 on RHEL 9, Cryostat 4, Cryostat, Cryostat 4 on RHEL 9, Cryostat 4 on RHEL 9, Cryostat 4, Cryostat 4 on RHEL 9
Provider severity
MEDIUM
Conflicts
1

CVE-2025-8414

Due to improper input validation, a buffer overflow vulnerability is present in Zigbee EZSP Host Applications. If the buffer overflows, stack corruption is possible. In certain conditions, this could lead to arbitrary code execution. Access to a network key is required to exploit this vulnerability.

PUBLISHED
Vendor
silabs.com, silabs.com
Product
Gecko SDK, Simplicity SDK
Provider severity
CRITICAL
Conflicts
1

CVE-2025-8413

The Listeo theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `soundcloud` shortcode in version less than, or equal to, 2.0.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
purethemes
Product
Listeo - Directory & Listings With Booking - WordPress Theme
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8412

A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in SUSE Virtual Machine Driver Pack allows an attacker with the ability to modify the registry to affect the integrity of the driver. We're not aware of a feasible way to exploit this currently. This issue affects Virtual Machine Driver Pack: before e7a602ec232756ead019bdf19d6d3b9d010cc94b.

PUBLISHED
Vendor
SUSE
Product
Virtual Machine Driver Pack
Provider severity
LOW
Conflicts
0

CVE-2025-8411

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dokuzsoft Technology E-Commerce Web Design Product allows XSS Through HTTP Headers. This issue affects E-Commerce Web Design Product: before 11.08.2025.

PUBLISHED
Vendor
Dokuzsoft Technology
Product
E-Commerce Web Design Product
Provider severity
HIGH
Conflicts
0

CVE-2025-8410

Use After Free vulnerability in RTI Connext Professional (Security Plugins) allows File Manipulation.This issue affects Connext Professional: from 7.5.0 before 7.6.0.

PUBLISHED
Vendor
RTI
Product
Connext Professional
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8409

A vulnerability has been found in code-projects Vehicle Management 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /filter.php. The manipulation of the argument from leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Vehicle Management
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-8408

A vulnerability, which was classified as critical, was found in code-projects Vehicle Management 1.0. Affected is an unknown function of the file /filter1.php. The manipulation of the argument vehicle leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Vehicle Management
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-8407

A vulnerability, which was classified as critical, has been found in code-projects Vehicle Management 1.0. This issue affects some unknown processing of the file /filter2.php. The manipulation of the argument from leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Vehicle Management
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-8406

ZenML version 0.83.1 is affected by a path traversal vulnerability in the `PathMaterializer` class. The `load` function uses `is_path_within_directory` to validate files during `data.tar.gz` extraction, which fails to effectively detect symbolic and hard links. This vulnerability can lead to arbitrary file writes, potentially resulting in arbitrary command execution if critical files are overwritten.

PUBLISHED
Vendor
zenml-io
Product
zenml-io/zenml
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8405

GitLab has remediated a security issue in GitLab CE/EE affecting all versions from 17.1 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to perform unauthorized actions on behalf of other users by injecting malicious HTML into vulnerability code flow displays.

PUBLISHED
Vendor
GitLab
Product
GitLab
Provider severity
HIGH
Conflicts
0

CVE-2025-8404

Stack buffer overflow vulnerability exists in the Supermicro BMC Shared library. An authenticated attacker with access to the BMC exploit stack buffer via a crafted  header and achieve arbitrary code execution of the BMC’s firmware operating system.

PUBLISHED
Vendor
SMCI
Product
MBD-X13SEDW-F
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8402

Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to validate import data which allows a system admin to crash the server via the bulk import feature.

PUBLISHED
Vendor
Mattermost
Product
Mattermost
Provider severity
MEDIUM
Conflicts
1

CVE-2025-8401

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.1 via the 'get_post_data' function. This makes it possible for authenticated attackers, with Author-level access and above, to extract sensitive data including the content of private, password-protected, and draft posts and pages.

PUBLISHED
Vendor
devitemsllc
Product
HT Mega Addons for Elementor – Elementor Widgets & Template Builder
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8400

The Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
aumsrini
Product
Image Gallery
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8399

The Mmm Unity Loader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘attributes’ parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
mmanifesto
Product
Mmm Unity Loader
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8398

The azurecurve BBCode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'url' shortcode in all versions up to, and including, 2.0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
azurecurve
Product
azurecurve BBCode
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8397

The Save as PDF Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's restpackpdfbutton shortcode in all versions up to, and including, 1.9.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
restpack
Product
Save as PDF Button
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8396

Insufficiently specific bounds checking on authorization header could lead to denial of service in the Temporal server on all platforms due to excessive memory allocation.This issue affects all platforms and versions of OSS Server prior to 1.26.3, 1.27.3, and 1.28.1 (i.e., fixed in 1.26.3, 1.27.3, and 1.28.1 and later). Temporal Cloud services are not impacted.

PUBLISHED
Vendor
Temporal
Product
OSS Server
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8394

The Productive Style plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's display_productive_breadcrumb shortcode in all versions up to, and including, 1.1.23 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
productiveminds
Product
Productive Style – Optimisations & Content Publishing Support
Provider severity
MEDIUM
Conflicts
0

CVE-2025-8393

A TLS vulnerability exists in the phone application used to manage a connected device. The phone application accepts self-signed certificates when establishing TLS communication which may result in man-in-the-middle attacks on untrusted networks. Captured communications may include user credentials and sensitive session tokens.

PUBLISHED
Vendor
Dreame Technology, Dreame Technology, Dreame Technology
Product
Dreamehome Android app, MOVAhome iOS app, Dreamehome iOS app
Provider severity
HIGH
Conflicts
2

CVE-2025-8392

The Mitfahrgelegenheit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘date’ parameter in all versions up to, and including, 1.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
bessermitfahren
Product
Mitfahrgelegenheit
Provider severity
MEDIUM
Conflicts
0