Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-69333

Missing Authorization vulnerability in Crocoblock JetEngine jet-engine allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetEngine: from n/a through <= 3.8.1.1.

PUBLISHED
Vendor
Crocoblock
Product
JetEngine
Provider severity
MEDIUM
Conflicts
0

CVE-2025-69332

Subscriber Broken Access Control in Bookify <= 1.1.1 versions.

PUBLISHED
Vendor
myCred
Product
Bookify
Provider severity
MEDIUM
Conflicts
0

CVE-2025-69331

Missing Authorization vulnerability in Jeroen Schmit Theater for WordPress theatre allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Theater for WordPress: from n/a through <= 0.19.

PUBLISHED
Vendor
Jeroen Schmit
Product
Theater for WordPress
Provider severity
MEDIUM
Conflicts
0

CVE-2025-69330

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jthemes Prestige prestige allows Reflected XSS.This issue affects Prestige: from n/a through < 1.4.1.

PUBLISHED
Vendor
Jthemes
Product
Prestige
Provider severity
HIGH
Conflicts
0

CVE-2025-69329

Deserialization of Untrusted Data vulnerability in Jthemes Prestige prestige allows Object Injection.This issue affects Prestige: from n/a through < 1.4.1.

PUBLISHED
Vendor
Jthemes
Product
Prestige
Provider severity
CRITICAL
Conflicts
0

CVE-2025-69328

Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Object Injection.This issue affects Booking and Rental Manager: from n/a through <= 2.5.9.

PUBLISHED
Vendor
magepeopleteam
Product
Booking and Rental Manager
Provider severity
HIGH
Conflicts
0

CVE-2025-69327

Missing Authorization vulnerability in magepeopleteam Car Rental Manager car-rental-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Car Rental Manager: from n/a through <= 1.0.9.

PUBLISHED
Vendor
magepeopleteam
Product
Car Rental Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2025-69326

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basix NEX-Forms nex-forms-express-wp-form-builder allows Reflected XSS.This issue affects NEX-Forms: from n/a through <= 9.1.7.

PUBLISHED
Vendor
Basix
Product
NEX-Forms
Provider severity
HIGH
Conflicts
0

CVE-2025-69325

Path Traversal: '.../...//' vulnerability in primersoftware Primer MyData for Woocommerce primer-mydata allows Path Traversal.This issue affects Primer MyData for Woocommerce: from n/a through <= 4.2.8.

PUBLISHED
Vendor
primersoftware
Product
Primer MyData for Woocommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2025-69324

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basix NEX-Forms nex-forms-express-wp-form-builder allows Stored XSS.This issue affects NEX-Forms: from n/a through <= 9.1.7.

PUBLISHED
Vendor
Basix
Product
NEX-Forms
Provider severity
HIGH
Conflicts
0

CVE-2025-69323

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs Slimstat Analytics wp-slimstat allows Reflected XSS.This issue affects Slimstat Analytics: from n/a through <= 5.3.2.

PUBLISHED
Vendor
VeronaLabs
Product
Slimstat Analytics
Provider severity
HIGH
Conflicts
0

CVE-2025-69322

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes PeakShops peakshops allows PHP Local File Inclusion.This issue affects PeakShops: from n/a through < 1.5.9.

PUBLISHED
Vendor
fuelthemes
Product
PeakShops
Provider severity
HIGH
Conflicts
0

CVE-2025-69321

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Spa grandspa allows Reflected XSS.This issue affects Grand Spa: from n/a through <= 3.5.5.

PUBLISHED
Vendor
ThemeGoods
Product
Grand Spa
Provider severity
HIGH
Conflicts
0

CVE-2025-69320

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Magazine grandmagazine allows Reflected XSS.This issue affects Grand Magazine: from n/a through <= 3.5.7.

PUBLISHED
Vendor
ThemeGoods
Product
Grand Magazine
Provider severity
HIGH
Conflicts
0

CVE-2025-6932

A vulnerability, which was classified as problematic, was found in D-Link DCS-7517 up to 2.02.0. This affects the function g_F_n_GenPassForQlync of the file /bin/httpd of the component Qlync Password Generation Handler. The manipulation leads to use of hard-coded password. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. This vulnerability only affe

PUBLISHED
Vendor
D-Link
Product
DCS-7517
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-69319

Improper Control of Generation of Code ('Code Injection') vulnerability in Beaver Builder Beaver Builder beaver-builder-lite-version allows Code Injection.This issue affects Beaver Builder: from n/a through <= 2.9.4.1.

PUBLISHED
Vendor
Beaver Builder
Product
Beaver Builder
Provider severity
HIGH
Conflicts
0

CVE-2025-69318

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hossni Mubarak JobWP jobwp allows Stored XSS.This issue affects JobWP: from n/a through <= 2.4.5.

PUBLISHED
Vendor
Hossni Mubarak
Product
JobWP
Provider severity
HIGH
Conflicts
0

CVE-2025-69317

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in scriptsbundle CarSpot carspot allows Reflected XSS.This issue affects CarSpot: from n/a through < 2.4.6.

PUBLISHED
Vendor
scriptsbundle
Product
CarSpot
Provider severity
HIGH
Conflicts
0

CVE-2025-69316

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 TableOn posts-table-filterable allows Reflected XSS.This issue affects TableOn: from n/a through <= 1.0.4.2.

PUBLISHED
Vendor
RealMag777
Product
TableOn
Provider severity
HIGH
Conflicts
0

CVE-2025-69315

Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.9.15.

PUBLISHED
Vendor
NSquared
Product
Simply Schedule Appointments
Provider severity
MEDIUM
Conflicts
0

CVE-2025-69314

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes Werkstatt werkstatt allows PHP Local File Inclusion.This issue affects Werkstatt: from n/a through < 4.8.3.

PUBLISHED
Vendor
fuelthemes
Product
Werkstatt
Provider severity
HIGH
Conflicts
0

CVE-2025-69313

Missing Authorization vulnerability in WPXPO PostX ultimate-post allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PostX: from n/a through <= 5.0.3.

PUBLISHED
Vendor
WPXPO
Product
PostX
Provider severity
HIGH
Conflicts
0

CVE-2025-69312

Unrestricted Upload of File with Dangerous Type vulnerability in Xpro Xpro Elementor Addons xpro-elementor-addons allows Upload a Web Shell to a Web Server.This issue affects Xpro Elementor Addons: from n/a through <= 1.4.19.1.

PUBLISHED
Vendor
Xpro
Product
Xpro Elementor Addons
Provider severity
CRITICAL
Conflicts
0

CVE-2025-69311

Missing Authorization vulnerability in Broadstreet Broadstreet Ads broadstreet allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Broadstreet Ads: from n/a through <= 1.52.1.

PUBLISHED
Vendor
Broadstreet
Product
Broadstreet Ads
Provider severity
HIGH
Conflicts
0

CVE-2025-69310

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Woodly Core woodly-core allows Blind SQL Injection.This issue affects Woodly Core: from n/a through <= 1.4.

PUBLISHED
Vendor
TeconceTheme
Product
Woodly Core
Provider severity
CRITICAL
Conflicts
0

CVE-2025-6931

A vulnerability classified as problematic was found in D-Link DCS-6517 and DCS-7517 up to 2.02.0. Affected by this vulnerability is the function generate_pass_from_mac of the file /bin/httpd of the component Root Password Generation Handler. The manipulation leads to insufficient entropy. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. This vulnerability only a

PUBLISHED
Vendor
D-Link, D-Link
Product
DCS-6517, DCS-7517
Provider severity
LOW, MEDIUM
Conflicts
3

CVE-2025-69309

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Saasplate Core saasplate-core allows Blind SQL Injection.This issue affects Saasplate Core: from n/a through <= 1.2.8.

PUBLISHED
Vendor
TeconceTheme
Product
Saasplate Core
Provider severity
CRITICAL
Conflicts
0

CVE-2025-69308

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Nestbyte Core nestbyte-core allows Blind SQL Injection.This issue affects Nestbyte Core: from n/a through <= 1.2.

PUBLISHED
Vendor
TeconceTheme
Product
Nestbyte Core
Provider severity
CRITICAL
Conflicts
0

CVE-2025-69307

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Medinik Core medinik-core allows Blind SQL Injection.This issue affects Medinik Core: from n/a through <= 1.3.6.

PUBLISHED
Vendor
TeconceTheme
Product
Medinik Core
Provider severity
CRITICAL
Conflicts
0

CVE-2025-69306

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Electio Core electio-core allows Blind SQL Injection.This issue affects Electio Core: from n/a through <= 1.4.

PUBLISHED
Vendor
TeconceTheme
Product
Electio Core
Provider severity
CRITICAL
Conflicts
0

CVE-2025-69305

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Crete Core crete-core allows Blind SQL Injection.This issue affects Crete Core: from n/a through <= 1.4.3.

PUBLISHED
Vendor
TeconceTheme
Product
Crete Core
Provider severity
CRITICAL
Conflicts
0

CVE-2025-69304

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Allmart allmart-core allows Blind SQL Injection.This issue affects Allmart: from n/a through <= 1.1.

PUBLISHED
Vendor
TeconceTheme
Product
Allmart
Provider severity
CRITICAL
Conflicts
0

CVE-2025-69303

Missing Authorization vulnerability in modeltheme ModelTheme Framework modeltheme-framework allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ModelTheme Framework: from n/a through < 2.0.0.

PUBLISHED
Vendor
modeltheme
Product
ModelTheme Framework
Provider severity
HIGH
Conflicts
0

CVE-2025-69302

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes DesignThemes Core Features designthemes-core-features allows Reflected XSS.This issue affects DesignThemes Core Features: from n/a through <= 2.3.

PUBLISHED
Vendor
designthemes
Product
DesignThemes Core Features
Provider severity
HIGH
Conflicts
0

CVE-2025-69301

Deserialization of Untrusted Data vulnerability in ThemeGoods PhotoMe photome allows Object Injection.This issue affects PhotoMe: from n/a through <= 5.6.11.

PUBLISHED
Vendor
ThemeGoods
Product
PhotoMe
Provider severity
CRITICAL
Conflicts
0

CVE-2025-69300

Missing Authorization vulnerability in Leap13 Premium Addons for Elementor premium-addons-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Premium Addons for Elementor: from n/a through <= 4.11.63.

PUBLISHED
Vendor
Leap13
Product
Premium Addons for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6930

A vulnerability classified as critical has been found in PHPGurukul Zoo Management System 2.1. Affected is an unknown function of the file /admin/manage-foreigners-ticket.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
PHPGurukul
Product
Zoo Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-69299

Server-Side Request Forgery (SSRF) vulnerability in Laborator Oxygen oxygen allows Server Side Request Forgery.This issue affects Oxygen: from n/a through <= 6.0.8.

PUBLISHED
Vendor
Laborator
Product
Oxygen
Provider severity
HIGH
Conflicts
0

CVE-2025-69298

Missing Authorization vulnerability in GhostPool Gauge gauge allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gauge: from n/a through <= 6.56.4.

PUBLISHED
Vendor
GhostPool
Product
Gauge
Provider severity
HIGH
Conflicts
0

CVE-2025-69297

Missing Authorization vulnerability in GhostPool Aardvark Plugin aardvark-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Aardvark Plugin: from n/a through <= 2.19.

PUBLISHED
Vendor
GhostPool
Product
Aardvark Plugin
Provider severity
HIGH
Conflicts
0

CVE-2025-69296

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhostPool Aardvark aardvark allows Reflected XSS.This issue affects Aardvark: from n/a through <= 4.6.3.

PUBLISHED
Vendor
GhostPool
Product
Aardvark
Provider severity
HIGH
Conflicts
0

CVE-2025-69295

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Coven Core coven-core allows Blind SQL Injection.This issue affects Coven Core: from n/a through <= 1.3.

PUBLISHED
Vendor
TeconceTheme
Product
Coven Core
Provider severity
CRITICAL
Conflicts
0

CVE-2025-69294

Deserialization of Untrusted Data vulnerability in fuelthemes PeakShops peakshops allows Object Injection.This issue affects PeakShops: from n/a through <= 1.5.9.

PUBLISHED
Vendor
fuelthemes
Product
PeakShops
Provider severity
HIGH
Conflicts
0

CVE-2025-69293

Incorrect Privilege Assignment vulnerability in e-plugins Final User final-user allows Privilege Escalation.This issue affects Final User: from n/a through <= 1.2.5.

PUBLISHED
Vendor
e-plugins
Product
Final User
Provider severity
HIGH
Conflicts
0

CVE-2025-69292

Incorrect Privilege Assignment vulnerability in e-plugins WP Membership wp-membership allows Privilege Escalation.This issue affects WP Membership: from n/a through <= 1.6.4.

PUBLISHED
Vendor
e-plugins
Product
WP Membership
Provider severity
HIGH
Conflicts
0

CVE-2025-6929

A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been rated as critical. This issue affects some unknown processing of the file /admin/view-normal-ticket.php. The manipulation of the argument viewid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
PHPGurukul
Product
Zoo Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-69289

Discourse is an open source discussion platform. A privilege escalation vulnerability in versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 allows a non-admin moderator to bypass email-change restrictions, allowing a takeover of non-staff accounts. This issue is patched in versions 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0. As a workaround, ensure moderators are trusted or enable the "require_change_email_confirmation" setting.

PUBLISHED
Vendor
discourse
Product
discourse
Provider severity
MEDIUM
Conflicts
0

CVE-2025-69288

Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user to modify the timeEntryRule in the database. The value is then passed to a NodeVM value to execute as code. Without sanitization, it leads to a Remote Code Execution. Version 0.99.49 fixes the issue.

PUBLISHED
Vendor
kromitgmbh
Product
titra
Provider severity
CRITICAL
Conflicts
0

CVE-2025-69287

The BSV Blockchain SDK is a unified TypeScript SDK for developing scalable apps on the BSV Blockchain. Prior to version 2.0.0, a cryptographic vulnerability in the TypeScript SDK's BRC-104 authentication implementation caused incorrect signature data preparation, resulting in signature incompatibility between SDK implementations and potential authentication bypass scenarios. The vulnerability was located in the `Peer.ts` file of the TypeScript SDK, specifically in the `processInitialRequest` and

PUBLISHED
Vendor
bsv-blockchain
Product
ts-sdk
Provider severity
MEDIUM
Conflicts
0

CVE-2025-69286

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.22.0, the use of an insecure key generation algorithm in the API key and beta (assistant/agent share auth) token generation process allows these tokens to be mutually derivable. Specifically, both tokens are generated using the same `URLSafeTimedSerializer` with predictable inputs, enabling an unauthorized user who obtains the shared assistant/agent URL to derive the personal API key. This grants them f

PUBLISHED
Vendor
infiniflow
Product
ragflow
Provider severity
HIGH
Conflicts
0