Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-7851

An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.

PUBLISHED
Vendor
TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc.
Product
Festa gateways, Omada gateways, Omada Pro gateways
Provider severity
HIGH
Conflicts
1

CVE-2025-7850

A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways.

PUBLISHED
Vendor
TP-Link Systems Inc., TP-Link Systems Inc., TP-Link Systems Inc.
Product
Omada gateways, Omada Pro gateways, Festa gateways
Provider severity
CRITICAL
Conflicts
1

CVE-2025-7849

A memory corruption vulnerability due to improper error handling when a VILinkObj is null exists in NI LabVIEW that may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q1 and prior versions.

PUBLISHED
Vendor
NI
Product
LabVIEW
Provider severity
HIGH
Conflicts
1

CVE-2025-7848

A memory corruption vulnerability due to improper input validation in lvpict.cpp exists in NI LabVIEW that may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q1 and prior versions.

PUBLISHED
Vendor
NI
Product
LabVIEW
Provider severity
HIGH
Conflicts
1

CVE-2025-7847

The AI Engine plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rest_simpleFileUpload() function in versions 2.9.3 and 2.9.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server when the REST API is enabled, which may make remote code execution possible.

PUBLISHED
Vendor
tigroumeow
Product
AI Engine
Provider severity
HIGH
Conflicts
0

CVE-2025-7846

The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the save_fields() function in all versions up to, and including, 16.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

PUBLISHED
Vendor
vanquish
Product
WordPress User Extra Fields
Provider severity
HIGH
Conflicts
0

CVE-2025-7845

The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Advanced Google Maps and Image Hotspot widgets in all versions up to, and including, 1.6.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
jetmonsters
Product
Stratum Widgets for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-7844

Exporting a TPM based RSA key larger than 2048 bits from the TPM could overrun a stack buffer if the default `MAX_RSA_KEY_BITS=2048` is used. If your TPM 2.0 module supports RSA key sizes larger than 2048 bit and your applications supports creating or importing an RSA private or public key larger than 2048 bits and your application calls `wolfTPM2_RsaKey_TpmToWolf` on that key, then a stack buffer could be overrun. If the `MAX_RSA_KEY_BITS` build-time macro is set correctly (RSA bits match what

PUBLISHED
Vendor
wolfSSL Inc.
Product
wolfTPM
Provider severity
LOW
Conflicts
0

CVE-2025-7843

The Auto Save Remote Images (Drafts) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.9 via the fetch_images() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PUBLISHED
Vendor
fernandiez
Product
Auto Save Remote Images (Drafts)
Provider severity
MEDIUM
Conflicts
0

CVE-2025-7842

The Silencesoft RSS Reader plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.6. This is due to missing or incorrect nonce validation on the 'sil_rss_edit_page' page. This makes it possible for unauthenticated attackers to delete RSS feeds via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PUBLISHED
Vendor
silence
Product
Silencesoft RSS Reader
Provider severity
MEDIUM
Conflicts
0

CVE-2025-7841

The Sertifier Certificate & Badge Maker for WordPress – Tutor LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.19. This is due to missing or incorrect nonce validation on the 'sertifier_settings' page. This makes it possible for unauthenticated attackers to update the plugin's api key via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PUBLISHED
Vendor
sertifier
Product
Sertifier Certificate & Badge Maker for WordPress – Tutor LMS
Provider severity
MEDIUM
Conflicts
0

CVE-2025-7840

A vulnerability was found in Campcodes Online Movie Theater Seat Reservation System 1.0. It has been classified as problematic. This affects an unknown part of the file /index.php?page=reserve of the component Reserve Your Seat Page. The manipulation of the argument Firstname/Lastname leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
Campcodes
Product
Online Movie Theater Seat Reservation System
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-7839

The Restore Permanently delete Post or Page Data plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the rp_dpo_dpa_ajax_dp_delete_data() function. This makes it possible for unauthenticated attackers to delete data via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PUBLISHED
Vendor
pokornydavid
Product
Restore Permanently delete Post or Page Data
Provider severity
MEDIUM
Conflicts
0

CVE-2025-7838

A vulnerability has been found in Campcodes Online Movie Theater Seat Reservation System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/manage_seat.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
Campcodes
Product
Online Movie Theater Seat Reservation System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-7837

A vulnerability was found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical. Affected by this issue is the function recvSlaveStaInfo of the component MQTT Service. The manipulation of the argument dest leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
TOTOLINK
Product
T6
Provider severity
HIGH
Conflicts
2

CVE-2025-7836

A vulnerability has been found in D-Link DIR-816L up to 2.06B01 and classified as critical. Affected by this vulnerability is the function lxmldbc_system of the file /htdocs/cgibin of the component Environment Variable Handler. The manipulation leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

PUBLISHED
Vendor
D-Link
Product
DIR-816L
Provider severity
MEDIUM
Conflicts
2

CVE-2025-7835

The iThoughts Advanced Code Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.10. This is due to missing or incorrect nonce validation on the 'ithoughts_ace_update_options' AJAX action. This makes it possible for unauthenticated attackers to update plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PUBLISHED
Vendor
gerkin
Product
iThoughts Advanced Code Editor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-7834

A vulnerability, which was classified as problematic, was found in PHPGurukul Complaint Management System 2.0. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
PHPGurukul
Product
Complaint Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-7833

A vulnerability, which was classified as critical, has been found in code-projects Church Donation System 1.0. This issue affects some unknown processing of the file /members/giving.php. The manipulation of the argument Amount leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Church Donation System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-7832

A vulnerability classified as critical was found in code-projects Church Donation System 1.0. This vulnerability affects unknown code of the file /members/offering.php. The manipulation of the argument trcode leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Church Donation System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-7831

A vulnerability classified as critical has been found in code-projects Church Donation System 1.0. This affects an unknown part of the file /members/Tithes.php. The manipulation of the argument trcode leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Church Donation System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-7830

A vulnerability was found in code-projects Church Donation System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /reg.php. The manipulation of the argument mobile leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

PUBLISHED
Vendor
code-projects
Product
Church Donation System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-7829

A vulnerability was found in code-projects Church Donation System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /login.php. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Church Donation System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-7828

The WP Filter & Combine RSS Feeds plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the post_listing_page() function in all versions up to, and including, 0.4. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete feeds.

PUBLISHED
Vendor
evigeo
Product
WP Filter & Combine RSS Feeds
Provider severity
MEDIUM
Conflicts
0

CVE-2025-7827

The Ni WooCommerce Customer Product Report plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ni_woocpr_action() function in all versions up to, and including, 1.2.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update plugin settings.

PUBLISHED
Vendor
anzia
Product
Ni WooCommerce Customer Product Report
Provider severity
MEDIUM
Conflicts
0

CVE-2025-7826

The Testimonial plugin for WordPress is vulnerable to SQL Injection via the 'iNICtestimonial' shortcode in all versions up to, and including, 2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PUBLISHED
Vendor
laki_patel
Product
Testimonial
Provider severity
MEDIUM
Conflicts
0

CVE-2025-7825

The Schema Plugin For Divi, Gutenberg & Shortcodes plugin for WordPress is vulnerable to Object Instantiation in all versions up to, and including, 4.3.2 via deserialization of untrusted input via the wpt_schema_breadcrumbs shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a P

PUBLISHED
Vendor
wpt00ls
Product
Schema Plugin For Divi, Gutenberg & Shortcodes
Provider severity
MEDIUM
Conflicts
0

CVE-2025-7824

A vulnerability was found in Jinher OA 1.1. It has been rated as problematic. This issue affects some unknown processing of the file XmlHttp.aspx. The manipulation leads to xml external entity reference. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
Jinher
Product
OA
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-7823

A vulnerability was found in Jinher OA 1.2. It has been declared as problematic. This vulnerability affects unknown code of the file ProjectScheduleDelete.aspx. The manipulation leads to xml external entity reference. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
Jinher
Product
OA
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-7822

The WP Wallcreeper plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the admin_notices hook in all versions up to, and including, 1.6.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to enable and disable caching.

PUBLISHED
Vendor
alexalouit
Product
WP Wallcreeper
Provider severity
MEDIUM
Conflicts
0

CVE-2025-7821

The WC Plus plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pluswc_logo_favicon_logo_base' AJAX action in all versions up to, and including, 1.2.0. This makes it possible for unauthenticated attackers to update the site's favicon logo base.

PUBLISHED
Vendor
wcplus
Product
WC Plus
Provider severity
MEDIUM
Conflicts
0

CVE-2025-7820

The SKT PayPal for WooCommerce plugin for WordPress is vulnerable to Payment Bypass in all versions up to, and including, 1.4. This is due to the plugin only enforcing client side controls instead of server-side controls when processing payments. This makes it possible for unauthenticated attackers to make confirmed purchases without actually paying for them.

PUBLISHED
Vendor
sonalsinha21
Product
SKT PayPal for WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2025-7819

A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /create-pass.php of the component HTTP POST Request Handler. The manipulation of the argument visname leads to cross site scripting. It is possible to initiate the attack remotely.

PUBLISHED
Vendor
PHPGurukul
Product
Apartment Visitors Management System
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-7818

A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /category.php of the component HTTP POST Request Handler. The manipulation of the argument categoryname leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
PHPGurukul
Product
Apartment Visitors Management System
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-7817

A vulnerability has been found in PHPGurukul Apartment Visitors Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /bwdates-reports.php of the component HTTP POST Request Handler. The manipulation of the argument visname leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
PHPGurukul
Product
Apartment Visitors Management System
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-7816

A vulnerability, which was classified as problematic, was found in PHPGurukul Apartment Visitors Management System 1.0. Affected is an unknown function of the file /visitor-detail.php of the component HTTP POST Request Handler. The manipulation of the argument visname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
PHPGurukul
Product
Apartment Visitors Management System
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-7815

A vulnerability, which was classified as problematic, has been found in PHPGurukul Apartment Visitors Management System 1.0. This issue affects some unknown processing of the file /manage-newvisitors.php of the component HTTP POST Request Handler. The manipulation of the argument visname leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

PUBLISHED
Vendor
PHPGurukul
Product
Apartment Visitors Management System
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-7814

A vulnerability classified as critical was found in code-projects Food Ordering Review System 1.0. This vulnerability affects unknown code of the file /pages/signup_function.php. The manipulation of the argument fname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

PUBLISHED
Vendor
code-projects
Product
Food Ordering Review System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-7813

The Events Calendar, Event Booking, Registrations and Event Tickets – Eventin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.37 via the proxy_image function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

PUBLISHED
Vendor
arraytics
Product
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)
Provider severity
HIGH
Conflicts
0

CVE-2025-7812

The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.6. This is due to missing or incorrect nonce validation on the adminExport() function. This makes it possible for unauthenticated attackers to update settings and execute remote code when the Server command execution setting is enabled via a forged request granted they can trick a site administrator into performing an action such as cl

PUBLISHED
Vendor
videowhisper
Product
Video Share VOD – Turnkey Video Site Builder Script
Provider severity
HIGH
Conflicts
0

CVE-2025-7811

The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'data-uuid' attribute in all versions up to, and including, 1.4.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
streamweasels
Product
StreamWeasels YouTube Integration
Provider severity
MEDIUM
Conflicts
0

CVE-2025-7810

The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'data-uuid' attribute in all versions up to, and including, 1.1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
streamweasels
Product
StreamWeasels Kick Integration
Provider severity
MEDIUM
Conflicts
0

CVE-2025-7809

The StreamWeasels Twitch Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'data-uuid' attribute in all versions up to, and including, 1.9.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
streamweasels
Product
StreamWeasels Twitch Integration
Provider severity
MEDIUM
Conflicts
0

CVE-2025-7808

The WP Shopify WordPress plugin before 1.5.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PUBLISHED
Vendor
Unknown
Product
WP Shopify
Provider severity
MEDIUM
Conflicts
0

CVE-2025-7807

A vulnerability, which was classified as critical, has been found in Tenda FH451 1.0.0.9. This issue affects the function fromSafeUrlFilter of the file /goform/SafeUrlFilter. The manipulation of the argument Go/page leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
Tenda
Product
FH451
Provider severity
HIGH
Conflicts
2

CVE-2025-7806

A vulnerability classified as critical was found in Tenda FH451 1.0.0.9. This vulnerability affects the function fromSafeClientFilter of the file /goform/SafeClientFilter. The manipulation of the argument Go/page leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
Tenda
Product
FH451
Provider severity
HIGH
Conflicts
2

CVE-2025-7805

A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. This affects the function fromPptpUserSetting of the file /goform/PPTPUserSetting. The manipulation of the argument delno leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
Tenda
Product
FH451
Provider severity
HIGH
Conflicts
2

CVE-2025-7803

A vulnerability was found in descreekert wx-discuz up to 12bd4745c63ec203cb32119bf77ead4a923bf277. It has been classified as problematic. This affects the function validToken of the file /wx.php. The manipulation of the argument echostr leads to cross site scripting. It is possible to initiate the attack remotely. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available.

PUBLISHED
Vendor
descreekert
Product
wx-discuz
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-7802

A vulnerability was found in PHPGurukul Complaint Management System 2.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/complaint-search.php. The manipulation of the argument Search leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
PHPGurukul
Product
Complaint Management System
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-7801

A vulnerability has been found in BossSoft CRM 6.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /crm/module/HNDCBas_customPrmSearchDtl.jsp. The manipulation of the argument cstid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
BossSoft
Product
CRM
Provider severity
HIGH, MEDIUM
Conflicts
2