Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-69001

Improper Control of Generation of Code ('Code Injection') vulnerability in Shahjahan Jewel FluentForm fluentform allows Code Injection.This issue affects FluentForm: from n/a through <= 6.1.11.

PUBLISHED
Vendor
Shahjahan Jewel
Product
FluentForm
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6900

A vulnerability has been found in code-projects Library System 1.0 and classified as critical. This vulnerability affects unknown code of the file /add-book.php. The manipulation of the argument image leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Library System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-68999

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons allows Blind SQL Injection.This issue affects Happy Addons for Elementor: from n/a through <= 3.20.4.

PUBLISHED
Vendor
HappyMonster
Product
Happy Addons for Elementor
Provider severity
HIGH
Conflicts
0

CVE-2025-68998

Cross-Site Request Forgery (CSRF) vulnerability in Heateor Support Heateor Social Login heateor-social-login allows Cross Site Request Forgery.This issue affects Heateor Social Login: from n/a through <= 1.1.39.

PUBLISHED
Vendor
Heateor Support
Product
Heateor Social Login
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68997

Authorization Bypass Through User-Controlled Key vulnerability in AdvancedCoding wpDiscuz wpdiscuz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpDiscuz: from n/a through <= 7.6.43.

PUBLISHED
Vendor
AdvancedCoding
Product
wpDiscuz
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68996

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WebCodingPlace Responsive Posts Carousel Pro responsive-posts-carousel-pro allows PHP Local File Inclusion.This issue affects Responsive Posts Carousel Pro: from n/a through <= 15.1.

PUBLISHED
Vendor
WebCodingPlace
Product
Responsive Posts Carousel Pro
Provider severity
HIGH
Conflicts
0

CVE-2025-68995

Missing Authorization vulnerability in Premio My Sticky Elements mystickyelements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects My Sticky Elements: from n/a through <= 2.3.3.

PUBLISHED
Vendor
Premio
Product
My Sticky Elements
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68994

Missing Authorization vulnerability in XforWooCommerce Product Loops for WooCommerce product-loops allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Loops for WooCommerce: from n/a through <= 2.1.2.

PUBLISHED
Vendor
XforWooCommerce
Product
Product Loops for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68993

Missing Authorization vulnerability in XforWooCommerce Share, Print and PDF Products for WooCommerce share-print-pdf-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Share, Print and PDF Products for WooCommerce: from n/a through <= 3.1.2.

PUBLISHED
Vendor
XforWooCommerce
Product
Share, Print and PDF Products for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68992

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xenioushk BWL Knowledge Base Manager bwl-kb-manager allows Stored XSS.This issue affects BWL Knowledge Base Manager: from n/a through <= 1.6.3.

PUBLISHED
Vendor
xenioushk
Product
BWL Knowledge Base Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68991

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xenioushk BWL Pro Voting Manager bwl-pro-voting-manager allows DOM-Based XSS.This issue affects BWL Pro Voting Manager: from n/a through <= 1.4.9.

PUBLISHED
Vendor
xenioushk
Product
BWL Pro Voting Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68990

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in xenioushk BWL Pro Voting Manager bwl-pro-voting-manager allows Blind SQL Injection.This issue affects BWL Pro Voting Manager: from n/a through <= 1.4.9.

PUBLISHED
Vendor
xenioushk
Product
BWL Pro Voting Manager
Provider severity
HIGH
Conflicts
0

CVE-2025-6899

A vulnerability, which was classified as critical, was found in D-Link DI-7300G+ and DI-8200G 17.12.20A1/19.12.25A1. This affects an unknown part of the file msp_info.htm. The manipulation of the argument flag/cmd/iface leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
D-Link, D-Link
Product
DI-8200G, DI-7300G+
Provider severity
MEDIUM
Conflicts
3

CVE-2025-68989

Insertion of Sensitive Information Into Sent Data vulnerability in Renzo Johnson contact-form-7-mailchimp-extension contact-form-7-mailchimp-extension allows Retrieve Embedded Sensitive Data.This issue affects contact-form-7-mailchimp-extension: from n/a through <= 0.9.68.

PUBLISHED
Vendor
Renzo Johnson
Product
contact-form-7-mailchimp-extension
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68988

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in o2oe E-Invoice App Malaysia einvoiceapp-malaysia allows Retrieve Embedded Sensitive Data.This issue affects E-Invoice App Malaysia: from n/a through <= 1.3.0.

PUBLISHED
Vendor
o2oe
Product
E-Invoice App Malaysia
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68987

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Cinerama cinerama allows PHP Local File Inclusion.This issue affects Cinerama: from n/a through <= 2.9.

PUBLISHED
Vendor
Edge-Themes
Product
Cinerama
Provider severity
HIGH
Conflicts
0

CVE-2025-68986

Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Miion miion allows Upload a Web Shell to a Web Server.This issue affects Miion: from n/a through <= 1.2.7.

PUBLISHED
Vendor
zozothemes
Product
Miion
Provider severity
CRITICAL
Conflicts
0

CVE-2025-68985

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Aora aora allows PHP Local File Inclusion.This issue affects Aora: from n/a through <= 1.3.15.

PUBLISHED
Vendor
thembay
Product
Aora
Provider severity
HIGH
Conflicts
0

CVE-2025-68984

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Puca puca allows PHP Local File Inclusion.This issue affects Puca: from n/a through <= 2.6.39.

PUBLISHED
Vendor
thembay
Product
Puca
Provider severity
HIGH
Conflicts
0

CVE-2025-68983

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Greenmart greenmart allows PHP Local File Inclusion.This issue affects Greenmart: from n/a through <= 4.2.11.

PUBLISHED
Vendor
thembay
Product
Greenmart
Provider severity
HIGH
Conflicts
0

CVE-2025-68982

Missing Authorization vulnerability in designthemes DesignThemes LMS Addon designthemes-lms-addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DesignThemes LMS Addon: from n/a through <= 2.6.

PUBLISHED
Vendor
designthemes
Product
DesignThemes LMS Addon
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68981

Missing Authorization vulnerability in designthemes HomeFix Elementor Portfolio homefix-ele-portfolio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HomeFix Elementor Portfolio: from n/a through <= 1.0.1.

PUBLISHED
Vendor
designthemes
Product
HomeFix Elementor Portfolio
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68980

Missing Authorization vulnerability in designthemes WeDesignTech Portfolio wedesigntech-portfolio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WeDesignTech Portfolio: from n/a through <= 1.0.2.

PUBLISHED
Vendor
designthemes
Product
WeDesignTech Portfolio
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6898

A vulnerability, which was classified as critical, has been found in D-Link DI-7300G+ 19.12.25A1. Affected by this issue is some unknown functionality of the file in proxy_client.asp. The manipulation of the argument proxy_srv/proxy_lanport/proxy_lanip/proxy_srvport leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
D-Link
Product
DI-7300G+
Provider severity
MEDIUM
Conflicts
2

CVE-2025-68979

Authorization Bypass Through User-Controlled Key vulnerability in SimpleCalendar Google Calendar Events google-calendar-events allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Google Calendar Events: from n/a through <= 3.5.9.

PUBLISHED
Vendor
SimpleCalendar
Product
Google Calendar Events
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68978

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes DesignThemes Core designthemes-core allows DOM-Based XSS.This issue affects DesignThemes Core: from n/a through <= 1.6.

PUBLISHED
Vendor
designthemes
Product
DesignThemes Core
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68977

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes DesignThemes Portfolio Addon designthemes-portfolio-addon allows DOM-Based XSS.This issue affects DesignThemes Portfolio Addon: from n/a through <= 1.5.

PUBLISHED
Vendor
designthemes
Product
DesignThemes Portfolio Addon
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68976

Missing Authorization vulnerability in Eagle-Themes Eagle Booking eagle-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Eagle Booking: from n/a through <= 1.3.4.3.

PUBLISHED
Vendor
Eagle-Themes
Product
Eagle Booking
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68975

Authorization Bypass Through User-Controlled Key vulnerability in Eagle-Themes Eagle Booking eagle-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Eagle Booking: from n/a through <= 1.3.4.3.

PUBLISHED
Vendor
Eagle-Themes
Product
Eagle Booking
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68974

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in miniOrange WordPress Social Login and Register miniorange-login-openid allows PHP Local File Inclusion.This issue affects WordPress Social Login and Register: from n/a through <= 7.7.0.

PUBLISHED
Vendor
miniOrange
Product
WordPress Social Login and Register
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68973

In GnuPG before 2.4.9, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. (For ExtendedLTS, 2.2.51 and later are fixed versions.)

PUBLISHED
Vendor
GnuPG
Product
GnuPG
Provider severity
HIGH
Conflicts
0

CVE-2025-68972

In GnuPG through 2.4.8, if a signed message has \f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an "invalid armor" message is printed during verification). This is related to use of \f as a marker to denote truncation of a long plaintext line.

PUBLISHED
Vendor
GnuPG
Product
GnuPG
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68971

In Forgejo through 13.0.3, the attachment component allows a denial of service by uploading a multi-gigabyte file attachment (e.g., to be associated with an issue or a release).

PUBLISHED
Vendor
n/a
Product
n/a
Provider severity
MEDIUM
Conflicts
1

CVE-2025-68970

Permission verification bypass vulnerability in the media library module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

PUBLISHED
Vendor
Huawei, Huawei
Product
EMUI, HarmonyOS
Provider severity
MEDIUM
Conflicts
1

CVE-2025-6897

A vulnerability classified as critical was found in D-Link DI-7300G+ 19.12.25A1. Affected by this vulnerability is an unknown functionality of the file httpd_debug.asp. The manipulation of the argument Time leads to os command injection. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
D-Link
Product
DI-7300G+
Provider severity
MEDIUM
Conflicts
2

CVE-2025-68969

Multi-thread race condition vulnerability in the thermal management module. Impact: Successful exploitation of this vulnerability may affect availability.

PUBLISHED
Vendor
Huawei
Product
HarmonyOS
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68968

Double free vulnerability in the multi-mode input module. Impact: Successful exploitation of this vulnerability may affect the input function.

PUBLISHED
Vendor
Huawei
Product
HarmonyOS
Provider severity
HIGH
Conflicts
0

CVE-2025-68967

Vulnerability of improper permission control in the print module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

PUBLISHED
Vendor
Huawei
Product
HarmonyOS
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68966

Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

PUBLISHED
Vendor
Huawei
Product
HarmonyOS
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68965

Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

PUBLISHED
Vendor
Huawei
Product
HarmonyOS
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68964

Data verification vulnerability in the HiView module. Impact: Successful exploitation of this vulnerability may affect availability.

PUBLISHED
Vendor
Huawei
Product
HarmonyOS
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68963

Man-in-the-middle attack vulnerability in the Clone module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

PUBLISHED
Vendor
Huawei, Huawei
Product
HarmonyOS, EMUI
Provider severity
MEDIUM
Conflicts
1

CVE-2025-68962

Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulnerability may affect availability.

PUBLISHED
Vendor
Huawei
Product
HarmonyOS
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68961

Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulnerability may affect availability.

PUBLISHED
Vendor
Huawei
Product
HarmonyOS
Provider severity
MEDIUM
Conflicts
0

CVE-2025-68960

Multi-thread race condition vulnerability in the video framework module. Impact: Successful exploitation of this vulnerability may affect availability.

PUBLISHED
Vendor
Huawei
Product
HarmonyOS
Provider severity
HIGH
Conflicts
0

CVE-2025-6896

A vulnerability classified as critical has been found in D-Link DI-7300G+ 19.12.25A1. Affected is an unknown function of the file wget_test.asp. The manipulation of the argument url leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
D-Link
Product
DI-7300G+
Provider severity
MEDIUM
Conflicts
2

CVE-2025-68959

Permission verification bypass vulnerability in the media library module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

PUBLISHED
Vendor
Huawei, Huawei
Product
EMUI, HarmonyOS
Provider severity
MEDIUM
Conflicts
1

CVE-2025-68958

Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerability may affect availability.

PUBLISHED
Vendor
Huawei
Product
HarmonyOS
Provider severity
HIGH
Conflicts
0

CVE-2025-68957

Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerability may affect availability.

PUBLISHED
Vendor
Huawei
Product
HarmonyOS
Provider severity
HIGH
Conflicts
0

CVE-2025-68956

Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerability may affect availability.

PUBLISHED
Vendor
Huawei
Product
HarmonyOS
Provider severity
HIGH
Conflicts
0