Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-7750

A vulnerability, which was classified as critical, was found in code-projects Online Appointment Booking System 1.0. Affected is an unknown function of the file /admin/adddoctorclinic.php. The manipulation of the argument clinic leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Online Appointment Booking System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-7749

A vulnerability, which was classified as critical, has been found in code-projects Online Appointment Booking System 1.0. This issue affects some unknown processing of the file /admin/getmanagerregion.php. The manipulation of the argument city leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Online Appointment Booking System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-7748

A vulnerability classified as problematic was found in ZCMS 3.6.0. This vulnerability affects unknown code of the component Create Article Page. The manipulation of the argument Title leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
n/a
Product
ZCMS
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-7747

A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. This affects the function fromWizardHandle of the file /goform/WizardHandle of the component POST Request Handler. The manipulation of the argument PPW leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
Tenda
Product
FH451
Provider severity
HIGH
Conflicts
2

CVE-2025-7746

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause an unvalidated data injected by a malicious user potentially leading to modify or read data in a victim’s browser.

PUBLISHED
Vendor
Schneider Electric, Schneider Electric, Schneider Electric, Schneider Electric, Schneider Electric, Schneider Electric, Schneider Electric, Schneider Electric
Product
ATS490 Altivar Soft Starter, ATV930/950/955/960/980/9A0/9B0/9L0/991/992/993 Altivar Process Drives, VW3A3720 & VW3A3721 Altivar Process Communication Modules, ATV6000 Medium Voltage Altivar Process Drives, ATV630/650/660/680/6A0/6B0/6L0 Altivar Process Drives, ILC992 InterLink Converter, ATV340E Altivar Machine Drives, VW3A3530D: ATVdPAC module
Provider severity
MEDIUM
Conflicts
1

CVE-2025-7745

Buffer Over-read vulnerability in ABB AC500 V2.This issue affects AC500 V2: through 2.5.2.

PUBLISHED
Vendor
ABB
Product
AC500 V2
Provider severity
MEDIUM
Conflicts
1

CVE-2025-7744

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dolusoft Omaspot allows SQL Injection. This issue affects Omaspot: before 12.09.2025.

PUBLISHED
Vendor
Dolusoft
Product
Omaspot
Provider severity
CRITICAL
Conflicts
0

CVE-2025-7743

Cleartext Transmission of Sensitive Information vulnerability in Dolusoft Omaspot allows Interception, Privilege Escalation. This issue affects Omaspot: before 12.09.2025.

PUBLISHED
Vendor
Dolusoft
Product
Omaspot
Provider severity
CRITICAL
Conflicts
0

CVE-2025-7742

An authentication vulnerability exists in the LG Innotek camera model LNV5110R firmware that allows a malicious actor to upload an HTTP POST request to the devices non-volatile storage. This action may result in remote code execution that allows an attacker to run arbitrary commands on the target device at the administrator privilege level.

PUBLISHED
Vendor
LG Innotek
Product
Camera Model LNV5110R
Provider severity
HIGH
Conflicts
0

CVE-2025-7741

Hardcoded Password Vulnerability have been found in CENTUM. Affected products contain a hardcoded password for the user account (PROG) used for CENTUM Authentication Mode within the system. Under the following conditions, there is a risk that an attacker could log in as the PROG user. The default permission for the PROG users is S1 permission (equivalent to OFFUSER). Therefore, for properly permission-controlled targets of operation and monitoring, even if an attacker user in as the PROG user,

PUBLISHED
Vendor
Yokogawa Electric Corporation
Product
CENTUM VP
Provider severity
LOW
Conflicts
0

CVE-2025-7740

Default credentials vulnerability exists in SuprOS product. If exploited, this could allow an authenticated local attacker to use an admin account created during product deployment.

PUBLISHED
Vendor
Hitachi Energy
Product
SuprOS
Provider severity
HIGH
Conflicts
0

CVE-2025-7739

An issue has been discovered in GitLab CE/EE affecting all versions from 18.2 before 18.2.2 that, under certain conditions, could have allowed authenticated users to achieve stored cross-site scripting by injecting malicious HTML content in scoped label descriptions.

PUBLISHED
Vendor
GitLab
Product
GitLab
Provider severity
HIGH
Conflicts
0

CVE-2025-7738

A flaw was found in Ansible Automation Platform (AAP) where the Gateway API returns the client secret for certain GitHub Enterprise authenticators in clear text. This vulnerability affects administrators or auditors accessing authenticator configurations. While access is limited to privileged users, the clear text exposure of sensitive credentials increases the risk of accidental leaks or misuse.

PUBLISHED
Vendor
Ansible, Red Hat, Red Hat
Product
django-ansible-base, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat Ansible Automation Platform 2.5 for RHEL 8
Provider severity
MEDIUM
Conflicts
1

CVE-2025-7737

DoS Vulnerability in 10G iSCSI Interface of Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Storage Platform E990, E1090, E1090H: before DKCMAIN Ver.93-07-21-80/00-05, CHB(iSCSI) Ver.88-01-02-04, before DKCMAIN Ver.93-07-01-80/00-07, CHB(iSCSI) Ver.88-01-02-04, before DKCMAIN Ver.93-06-82-80/00-06, CHB(iSCSI) Ver.88-01-02-04, before DKCMAIN Ver.93-06-63-80/00-04, CHB(iSCSI) Ver.88-01-02-04; Hitachi Virtual Storage Platform E390, E590, E790, E390H, E590H, E790H: before DKC

PUBLISHED
Vendor
Hitachi, Hitachi, Hitachi, Hitachi, Hitachi, Hitachi
Product
Hitachi Virtual Storage Platform E390, E590, E790, E390H, E590H, E790H, Hitachi Virtual Storage Platform E990, E1090, E1090H, Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform VX7, G1000, G1500, F1500, Hitachi Virtual Storage Platform G100, G200, G400, G600, G800, F400, F600, F800, Hitachi Virtual Storage Platform VX8, 5100, 5500, 5100H, 5500H, 5200, 5600, 5200H, 5600H
Provider severity
HIGH
Conflicts
1

CVE-2025-7736

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.9 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to bypass access control restrictions and view GitLab Pages content intended only for project members by authenticating through OAuth providers.

PUBLISHED
Vendor
GitLab
Product
GitLab
Provider severity
LOW
Conflicts
0

CVE-2025-7735

The Hospital Information System developed by UNIMAX has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.

PUBLISHED
Vendor
UNIMAX
Product
Hospital Information System
Provider severity
HIGH
Conflicts
1

CVE-2025-7734

An issue has been discovered in GitLab CE/EE affecting all versions from 14.2 before 18.0.6, 18.1 before 18.1.4 and 18.2 before 18.2.2 that, under certain conditions, could have allowed a successful attacker to execute actions on behalf of users by injecting malicious content.

PUBLISHED
Vendor
GitLab
Product
GitLab
Provider severity
HIGH
Conflicts
0

CVE-2025-7733

The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 7.7 via the 'cs_update_application_status_callback' due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Candidate-level access and above, to send a site-generated email with injected HTML to any user.

PUBLISHED
Vendor
n/a
Product
WP JobHunt
Provider severity
MEDIUM
Conflicts
0

CVE-2025-7732

The Lazy Load for Videos plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its lazy‑loading handlers in all versions up to, and including, 2.18.7 due to insufficient input sanitization and output escaping. The plugin’s JavaScript registration handlers read the client‑supplied 'data-video-title' and 'href' attributes, decode HTML entities by default, and pass them directly into DOM sinks without any escaping or validation. This makes it possible for authenticated attackers, wi

PUBLISHED
Vendor
kevinweber
Product
Lazy Load for Videos
Provider severity
MEDIUM
Conflicts
0

CVE-2025-7731

Cleartext Transmission of Sensitive Information vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU module allows a remote unauthenticated attacker to obtain credential information by intercepting SLMP communication messages, and read or write the device values of the product and stop the operations of programs by using the obtained credential information.

PUBLISHED
Vendor
Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation, Mitsubishi Electric Corporation
Product
MELSEC iQ-F Series FX5S-80MT/ES, MELSEC iQ-F Series FX5UC-96MT/D, MELSEC iQ-F Series FX5UJ-60MR/ES, MELSEC iQ-F Series FX5UJ-40MR/ES, MELSEC iQ-F Series FX5UC-32MT/D, MELSEC iQ-F Series FX5U-64MR/DS, MELSEC iQ-F Series FX5U-64MT/DS, MELSEC iQ-F Series FX5UJ-40MR/DS, MELSEC iQ-F Series FX5S-60MT/ESS, MELSEC iQ-F Series FX5UJ-40MT/DSS, MELSEC iQ-F Series FX5UJ-24MT/DSS, MELSEC iQ-F Series FX5UJ-24MT/ESS, MELSEC iQ-F Series FX5U-32MR/ES, MELSEC iQ-F Series FX5UJ-24MR/DS, MELSEC iQ-F Series FX5S-80MT/DS, MELSEC iQ-F Series FX5UJ-24MT/ES-A, MELSEC iQ-F Series FX5UC-32MR/DS-TS, MELSEC iQ-F Series FX5UJ-40MT/ESS, MELSEC iQ-F Series FX5S-80MR/DS, MELSEC iQ-F Series FX5UJ-24MR/ES, MELSEC iQ-F Series FX5U-32MT/DSS, MELSEC iQ-F Series FX5U-32MT/DS, MELSEC iQ-F Series FX5U-80MT/ES, MELSEC iQ-F Series FX5UJ-60MT/ES-A, MELSEC iQ-F Series FX5UJ-60MT/DSS, MELSEC iQ-F Series FX5S-30MT/ES, MELSEC iQ-F Series FX5U-80MT/DSS, MELSEC iQ-F Series FX5S-80MT/ESS, MELSEC iQ-F Series FX5UJ-60MT/DS, MELSEC iQ-F Series FX5UC-64MT/D, MELSEC iQ-F Series FX5UJ-60MR/ES-A, MELSEC iQ-F Series FX5UJ-40MR/ES-A, MELSEC iQ-F Series FX5U-32MR/DS, MELSEC iQ-F Series FX5S-40MT/ES, MELSEC iQ-F Series FX5S-40MT/DSS, MELSEC iQ-F Series FX5S-60MR/ES, MELSEC iQ-F Series FX5U-64MT/DSS, MELSEC iQ-F Series FX5UJ-60MR/DS, MELSEC iQ-F Series FX5UJ-40MT/DS, MELSEC iQ-F Series FX5S-30MR/DS, MELSEC iQ-F Series FX5S-40MT/ESS, MELSEC iQ-F Series FX5U-32MT/ES, MELSEC iQ-F Series FX5UC-32MT/DSS-TS, MELSEC iQ-F Series FX5S-40MR/ES, MELSEC iQ-F Series FX5S-40MT/DS, MELSEC iQ-F Series FX5UJ-60MT/ESS, MELSEC iQ-F Series FX5U-64MT/ESS, MELSEC iQ-F Series FX5S-60MT/DS, MELSEC iQ-F Series FX5UJ-24MR/ES-A, MELSEC iQ-F Series FX5U-80MT/DS, MELSEC iQ-F Series FX5U-32MT/ESS, MELSEC iQ-F Series FX5U-80MR/DS, MELSEC iQ-F Series FX5UJ-24MT/DS, MELSEC iQ-F Series FX5S-60MT/ES, MELSEC iQ-F Series FX5UJ-40MT/ES, MELSEC iQ-F Series FX5S-40MR/DS, MELSEC iQ-F Series FX5UJ-60MT/ES, MELSEC iQ-F Series FX5UC-32MT/DS-TS, MELSEC iQ-F Series FX5S-80MT/DSS, MELSEC iQ-F Series FX5S-30MR/ES, MELSEC iQ-F Series FX5U-64MR/ES, MELSEC iQ-F Series FX5U-64MT/ES, MELSEC iQ-F Series FX5S-60MT/DSS, MELSEC iQ-F Series FX5UC-32MT/DSS, MELSEC iQ-F Series FX5UC-96MT/DSS, MELSEC iQ-F Series FX5S-80MR/ES, MELSEC iQ-F Series FX5UC-64MT/DSS, MELSEC iQ-F Series FX5S-30MT/ESS, MELSEC iQ-F Series FX5UJ-40MT/ES-A, MELSEC iQ-F Series FX5S-60MR/DS, MELSEC iQ-F Series FX5S-30MT/DSS, MELSEC iQ-F Series FX5UJ-24MT/ES, MELSEC iQ-F Series FX5S-30MT/DS, MELSEC iQ-F Series FX5U-80MR/ES, MELSEC iQ-F Series FX5U-80MT/ESS
Provider severity
HIGH
Conflicts
1

CVE-2025-7730

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘percentage’ parameter in all versions up to, and including, 5.4.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
boldthemes
Product
Bold Page Builder
Provider severity
MEDIUM
Conflicts
0

CVE-2025-7729

A vulnerability classified as problematic was found in Scada-LTS up to 2.7.8.1. Affected by this vulnerability is an unknown functionality of the file usersProfiles.shtm. The manipulation of the argument Username leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this issue and confirmed that it will be fixed in the upcoming release 2.8.0.

PUBLISHED
Vendor
n/a
Product
Scada-LTS
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-7728

A vulnerability classified as problematic has been found in Scada-LTS up to 2.7.8.1. Affected is an unknown function of the file users.shtm. The manipulation of the argument Username leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this issue and confirmed that it will be fixed in the upcoming release 2.8.0.

PUBLISHED
Vendor
n/a
Product
Scada-LTS
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-7727

The Gutenverse plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Animated Text and Fun Fact blocks in all versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
jegstudio
Product
Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem
Provider severity
MEDIUM
Conflicts
0

CVE-2025-7726

The The7 theme for WordPress is vulnerable to Stored Cross-Site Scripting via its lightbox rendering code in all versions up to, and including, 12.6.0 due to insufficient input sanitization and output escaping. The theme’s JavaScript reads user-supplied 'title' and 'data-dt-img-description' attributes directly via jQuery.attr(), concatenates them into an HTML string, and inserts that string into the DOM using methods such as jQuery.html() without escaping or filtering. This makes it possible for

PUBLISHED
Vendor
Dream-Theme
Product
The7 — Website and eCommerce Builder for WordPress
Provider severity
MEDIUM
Conflicts
0

CVE-2025-7725

The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the comment feature in all versions up to, and including, 26.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected pa

PUBLISHED
Vendor
contest-gallery
Product
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe
Provider severity
HIGH
Conflicts
0

CVE-2025-7724

An unauthenticated OS command injection vulnerability exists in VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2.This issue affects VIGI NVR1104H-4P V1: before 1.1.5 Build 250518; VIGI NVR2016H-16MP V2: before 1.3.1 Build 250407.

PUBLISHED
Vendor
TP-Link Systems Inc., TP-Link Systems Inc.
Product
VIGI NVR2016H-16MP V2, VIGI NVR1104H-4P V1
Provider severity
HIGH
Conflicts
1

CVE-2025-7723

A command injection vulnerability exists that can be exploited after authentication in VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2.This issue affects VIGI NVR1104H-4P V1: before 1.1.5 Build 250518; VIGI NVR2016H-16MP V2: before 1.3.1 Build 250407.

PUBLISHED
Vendor
TP-Link Systems Inc., TP-Link Systems Inc.
Product
VIGI NVR2016H-16MP V2, VIGI NVR1104H-4P V1
Provider severity
HIGH
Conflicts
1

CVE-2025-7722

The Social Streams plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.1. This is due to the plugin not properly validating a user's identity prior to updating their user meta information in the update_user_meta() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change their user type to that of an administrator.

PUBLISHED
Vendor
steverio
Product
Social Streams
Provider severity
HIGH
Conflicts
0

CVE-2025-7721

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.7.3 via the task parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded

PUBLISHED
Vendor
beardev
Product
JoomSport – for Sports: Team & League, Football, Hockey & more
Provider severity
CRITICAL
Conflicts
0

CVE-2025-7719

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GE Vernova Smallworld on Windows, Linux allows File Manipulation.This issue affects Smallworld: 5.3.5. and previous versions.

PUBLISHED
Vendor
GE Vernova
Product
Smallworld
Provider severity
MEDIUM
Conflicts
0

CVE-2025-7718

The Resideo Plugin for Resideo - Real Estate WordPress Theme plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.5.4. This is due to the plugin not properly validating a user's identity prior to updating their details like email. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's pa

PUBLISHED
Vendor
pixel_prime
Product
Resideo Plugin for Resideo - Real Estate WordPress Theme
Provider severity
HIGH
Conflicts
0

CVE-2025-7717

Missing Authorization vulnerability in Drupal File Download allows Forceful Browsing.This issue affects File Download: from 0.0.0 before 1.9.0, from 2.0.0 before 2.0.1.

PUBLISHED
Vendor
Drupal
Product
File Download
Provider severity
HIGH
Conflicts
0

CVE-2025-7716

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Real-time SEO for Drupal allows Cross-Site Scripting (XSS).This issue affects Real-time SEO for Drupal: from 2.0.0 before 2.2.0.

PUBLISHED
Vendor
Drupal
Product
Real-time SEO for Drupal
Provider severity
MEDIUM
Conflicts
0

CVE-2025-7715

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Block Attributes allows Cross-Site Scripting (XSS).This issue affects Block Attributes: from 0.0.0 before 1.1.0, from 2.0.0 before 2.0.1.

PUBLISHED
Vendor
Drupal
Product
Block Attributes
Provider severity
MEDIUM
Conflicts
0

CVE-2025-7714

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Global Interactive Design Media Software Inc. Content Management System (CMS) allows Command Line Execution through SQL Injection. This issue affects Content Management System (CMS): through 21072025.

PUBLISHED
Vendor
Global Interactive Design Media Software Inc.
Product
Content Management System (CMS)
Provider severity
HIGH
Conflicts
0

CVE-2025-7713

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Global Interactive Design Media Software Inc. Content Management System (CMS) allows XSS Through HTTP Headers. This issue affects Content Management System (CMS): through 21072025.

PUBLISHED
Vendor
Global Interactive Design Media Software Inc.
Product
Content Management System (CMS)
Provider severity
HIGH
Conflicts
0

CVE-2025-7712

The Madara - Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the wp_manga_delete_zip() function in all versions up to, and including, 2.2.3. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

PUBLISHED
Vendor
MangaBooth
Product
Madara - Core
Provider severity
CRITICAL
Conflicts
0

CVE-2025-7711

The The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes.

PUBLISHED
Vendor
techlabpro1
Product
Classified Listing – AI-Powered Classified ads & Business Directory Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2025-7710

The Brave Conversion Engine (PRO) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 0.7.7. This is due to the plugin not properly restricting a claimed identity while authenticating with Facebook. This makes it possible for unauthenticated attackers to log in as other users, including administrators.

PUBLISHED
Vendor
Brave
Product
Brave Conversion Engine (PRO)
Provider severity
CRITICAL
Conflicts
0

CVE-2025-7709

An integer overflow exists in the FTS5 https://sqlite.org/fts5.html  extension. It occurs when the size of an array of tombstone pointers is calculated and truncated into a 32-bit integer. A pointer to partially controlled data can then be written out of bounds.

PUBLISHED
Vendor
SQLite
Product
FTS5
Provider severity
MEDIUM
Conflicts
0

CVE-2025-7708

Insertion of Sensitive Information Into Sent Data vulnerability in Atlas Educational Software Industry Ltd. Co. K12net allows Communication Channel Manipulation. This issue affects k12net: through 09022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Atlas Educational Software Industry Ltd. Co.
Product
k12net
Provider severity
MEDIUM
Conflicts
0

CVE-2025-7707

The llama_index library version 0.12.33 sets the NLTK data directory to a subdirectory of the codebase by default, which is world-writable in multi-user environments. This configuration allows local users to overwrite, delete, or corrupt NLTK data files, leading to potential denial of service, data tampering, or privilege escalation. The vulnerability arises from the use of a shared cache directory instead of a user-specific one, making it susceptible to local data tampering and denial of servic

PUBLISHED
Vendor
run-llama
Product
run-llama/llama_index
Provider severity
HIGH
Conflicts
0

CVE-2025-7706

Missing Authentication for Critical Function vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows Remote Code Inclusion. This issue affects Liderahenk: from 3.0.0 to 3.3.1 before 3.5.0.

PUBLISHED
Vendor
TUBITAK BILGEM Software Technologies Research Institute
Product
Liderahenk
Provider severity
MEDIUM
Conflicts
0

CVE-2025-7705

: Active Debug Code vulnerability in ABB Switch Actuator 4 DU-83330, ABB Switch actuator, door/light 4 DU -83330-500.This issue affects Switch Actuator 4 DU-83330: All Versions; Switch actuator, door/light 4 DU -83330-500: All Versions.

PUBLISHED
Vendor
ABB, ABB
Product
Switch Actuator 4 DU-83330, Switch actuator, door/light 4 DU -83330-500
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-7704

Supermicro BMC Insyde SMASH shell program has a stacked-based overflow vulnerability

PUBLISHED
Vendor
SMCI
Product
SYS-111C-NR
Provider severity
MEDIUM
Conflicts
0

CVE-2025-7703

Authentication vulnerability in the mobile application(tech.palm.id)may lead to the risk of information leakage.

PUBLISHED
Vendor
TECNO
Product
tech.palm.id
Provider severity
LOW
Conflicts
0

CVE-2025-7702

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Pusula Communication Information Internet Industry and Trade Ltd. Co. Manageable Email Sending System allows Exploiting Trust in Client. This issue affects Manageable Email Sending System: from <=2025.06 before 2025.08.06.

PUBLISHED
Vendor
Pusula Communication Information Internet Industry and Trade Ltd. Co.
Product
Manageable Email Sending System
Provider severity
MEDIUM
Conflicts
0

CVE-2025-7700

A flaw was found in FFmpeg’s ALS audio decoder, where it does not properly check for memory allocation failures. This can cause the application to crash when processing certain malformed audio files. While it does not lead to data theft or system control, it can be used to disrupt services and cause a denial of service.

PUBLISHED
Vendor
Not asserted
Product
Not asserted
Provider severity
MEDIUM
Conflicts
0

CVE-2025-7699

An improper access control vulnerability was found in the EZ Sync Manager of ADM, which allows authenticated users to copy arbitrary files from the server file system into their own EZSync folder. The vulnerability is due to a lack of authorization checks on the file parameter of the HTTP request. Attackers can exploit this flaw to access files outside their authorized scope, provided the file has readable permissions for other users on the underlying OS. This can lead to unauthorized exposure

PUBLISHED
Vendor
ASUSTOR
Product
ADM
Provider severity
HIGH
Conflicts
0