Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-67946

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in scriptsbundle AdForest adforest allows PHP Local File Inclusion.This issue affects AdForest: from n/a through <= 6.0.11.

PUBLISHED
Vendor
scriptsbundle
Product
AdForest
Provider severity
HIGH
Conflicts
0

CVE-2025-67945

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MailerLite MailerLite – WooCommerce integration woo-mailerlite allows SQL Injection.This issue affects MailerLite – WooCommerce integration: from n/a through <= 3.1.2.

PUBLISHED
Vendor
MailerLite
Product
MailerLite – WooCommerce integration
Provider severity
CRITICAL
Conflicts
0

CVE-2025-67944

Improper Control of Generation of Code ('Code Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Code Injection.This issue affects Nelio AB Testing: from n/a through <= 8.1.8.

PUBLISHED
Vendor
Nelio Software
Product
Nelio AB Testing
Provider severity
CRITICAL
Conflicts
0

CVE-2025-67943

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wphocus My auctions allegro my-auctions-allegro-free-edition allows Reflected XSS.This issue affects My auctions allegro: from n/a through <= 3.6.32.

PUBLISHED
Vendor
wphocus
Product
My auctions allegro
Provider severity
HIGH
Conflicts
0

CVE-2025-67942

Missing Authorization vulnerability in peachpayments Peach Payments Gateway wc-peach-payments-gateway allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Peach Payments Gateway: from n/a through <= 3.3.6.

PUBLISHED
Vendor
peachpayments
Product
Peach Payments Gateway
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67941

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes The Aisle theaisle allows PHP Local File Inclusion.This issue affects The Aisle: from n/a through < 2.9.1.

PUBLISHED
Vendor
Elated-Themes
Product
The Aisle
Provider severity
HIGH
Conflicts
0

CVE-2025-67940

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Powerlift powerlift allows PHP Local File Inclusion.This issue affects Powerlift: from n/a through < 3.2.1.

PUBLISHED
Vendor
Mikado-Themes
Product
Powerlift
Provider severity
HIGH
Conflicts
0

CVE-2025-6794

Marvell QConvergeConsole saveAsText Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the saveAsText method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage thi

PUBLISHED
Vendor
Marvell
Product
QConvergeConsole
Provider severity
CRITICAL
Conflicts
0

CVE-2025-67939

Missing Authorization vulnerability in Tickera Tickera tickera-event-ticketing-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tickera: from n/a through <= 3.5.6.2.

PUBLISHED
Vendor
Tickera
Product
Tickera
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67938

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Biagiotti biagiotti allows PHP Local File Inclusion.This issue affects Biagiotti: from n/a through < 3.5.2.

PUBLISHED
Vendor
Mikado-Themes
Product
Biagiotti
Provider severity
HIGH
Conflicts
0

CVE-2025-67937

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Hendon hendon allows PHP Local File Inclusion.This issue affects Hendon: from n/a through < 1.7.

PUBLISHED
Vendor
Mikado-Themes
Product
Hendon
Provider severity
HIGH
Conflicts
0

CVE-2025-67936

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Curly curly allows PHP Local File Inclusion.This issue affects Curly: from n/a through < 3.3.

PUBLISHED
Vendor
Mikado-Themes
Product
Curly
Provider severity
HIGH
Conflicts
0

CVE-2025-67935

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Optimize optimizewp allows PHP Local File Inclusion.This issue affects Optimize: from n/a through < 2.4.

PUBLISHED
Vendor
Mikado-Themes
Product
Optimize
Provider severity
HIGH
Conflicts
0

CVE-2025-67934

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Wellspring wellspring allows PHP Local File Inclusion.This issue affects Wellspring: from n/a through < 2.8.

PUBLISHED
Vendor
Mikado-Themes
Product
Wellspring
Provider severity
HIGH
Conflicts
0

CVE-2025-67933

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in taskbuilder Taskbuilder taskbuilder allows Reflected XSS.This issue affects Taskbuilder: from n/a through <= 4.0.9.

PUBLISHED
Vendor
taskbuilder
Product
Taskbuilder
Provider severity
HIGH
Conflicts
0

CVE-2025-67932

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in purethemes Listeo Core listeo-core allows Reflected XSS.This issue affects Listeo Core: from n/a through < 2.0.19.

PUBLISHED
Vendor
purethemes
Product
Listeo Core
Provider severity
HIGH
Conflicts
0

CVE-2025-67931

Insertion of Sensitive Information Into Sent Data vulnerability in AITpro BulletProof Security bulletproof-security allows Retrieve Embedded Sensitive Data.This issue affects BulletProof Security: from n/a through <= 6.9.

PUBLISHED
Vendor
AITpro
Product
BulletProof Security
Provider severity
HIGH
Conflicts
0

CVE-2025-67930

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vernon Systems Limited eHive Search ehive-search allows Reflected XSS.This issue affects eHive Search: from n/a through <= 2.5.0.

PUBLISHED
Vendor
Vernon Systems Limited
Product
eHive Search
Provider severity
HIGH
Conflicts
0

CVE-2025-6793

Marvell QConvergeConsole QLogicDownloadImpl Directory Traversal Arbitrary File Deletion and Information Disclosure Vulnerability. This vulnerability allows remote attackers to delete arbitrary files and disclose sensitive information on affected installations of Marvell QConvergeConsole. Authentication is not required to exploit this vulnerability. The specific flaw exists within the QLogicDownloadImpl class. The issue results from the lack of proper validation of a user-supplied path prior to

PUBLISHED
Vendor
Marvell
Product
QConvergeConsole
Provider severity
CRITICAL
Conflicts
0

CVE-2025-67929

Missing Authorization vulnerability in templateinvaders TI WooCommerce Wishlist ti-woocommerce-wishlist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TI WooCommerce Wishlist: from n/a through <= 2.10.0.

PUBLISHED
Vendor
templateinvaders
Product
TI WooCommerce Wishlist
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67928

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in themesuite Automotive Listings automotive allows Blind SQL Injection.This issue affects Automotive Listings: from n/a through <= 18.6.

PUBLISHED
Vendor
themesuite
Product
Automotive Listings
Provider severity
CRITICAL
Conflicts
0

CVE-2025-67927

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spencer Haws Link Whisper Free link-whisper allows Reflected XSS.This issue affects Link Whisper Free: from n/a through <= 0.8.8.

PUBLISHED
Vendor
Spencer Haws
Product
Link Whisper Free
Provider severity
HIGH
Conflicts
0

CVE-2025-67926

Missing Authorization vulnerability in Shahjahan Jewel Fluent Support fluent-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Support: from n/a through <= 1.10.4.

PUBLISHED
Vendor
Shahjahan Jewel
Product
Fluent Support
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67925

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in zozothemes Corpkit corpkit allows PHP Local File Inclusion.This issue affects Corpkit: from n/a through <= 2.0.

PUBLISHED
Vendor
zozothemes
Product
Corpkit
Provider severity
HIGH
Conflicts
0

CVE-2025-67924

Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Corpkit corpkit allows Upload a Web Shell to a Web Server.This issue affects Corpkit: from n/a through <= 2.0.

PUBLISHED
Vendor
zozothemes
Product
Corpkit
Provider severity
CRITICAL
Conflicts
0

CVE-2025-67923

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine jet-engine allows Reflected XSS.This issue affects JetEngine: from n/a through <= 3.7.7.

PUBLISHED
Vendor
Crocoblock
Product
JetEngine
Provider severity
HIGH
Conflicts
0

CVE-2025-67922

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Reflected XSS.This issue affects Grand Restaurant: from n/a through < 7.0.9.

PUBLISHED
Vendor
ThemeGoods
Product
Grand Restaurant
Provider severity
HIGH
Conflicts
0

CVE-2025-67921

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VanKarWai Lobo lobo allows Blind SQL Injection.This issue affects Lobo: from n/a through < 2.8.6.

PUBLISHED
Vendor
VanKarWai
Product
Lobo
Provider severity
HIGH
Conflicts
0

CVE-2025-67920

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Neo Ocular neoocular allows PHP Local File Inclusion.This issue affects Neo Ocular: from n/a through < 1.2.

PUBLISHED
Vendor
Elated-Themes
Product
Neo Ocular
Provider severity
HIGH
Conflicts
0

CVE-2025-6792

The One to one user Chat by WPGuppy plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /wp-json/guppylite/v2/channel-authorize rest endpoint in all versions up to, and including, 1.1.4. This makes it possible for unauthenticated attackers to intercept and view private chat messages between users.

PUBLISHED
Vendor
amentotechpvtltd
Product
One to one user Chat by WPGuppy
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67919

Authorization Bypass Through User-Controlled Key vulnerability in WofficeIO Woffice Core woffice-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Woffice Core: from n/a through <= 5.4.30.

PUBLISHED
Vendor
WofficeIO
Product
Woffice Core
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67918

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WofficeIO Woffice woffice allows Reflected XSS.This issue affects Woffice: from n/a through <= 5.4.30.

PUBLISHED
Vendor
WofficeIO
Product
Woffice
Provider severity
HIGH
Conflicts
0

CVE-2025-67917

Missing Authorization vulnerability in shinetheme Traveler traveler allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Traveler: from n/a through <= 3.2.6.

PUBLISHED
Vendor
shinetheme
Product
Traveler
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67916

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Astoundify Jobify jobify allows Reflected XSS.This issue affects Jobify: from n/a through <= 4.3.0.

PUBLISHED
Vendor
Astoundify
Product
Jobify
Provider severity
HIGH
Conflicts
0

CVE-2025-67915

Authentication Bypass Using an Alternate Path or Channel vulnerability in Arraytics Timetics timetics allows Authentication Abuse.This issue affects Timetics: from n/a through <= 1.0.46.

PUBLISHED
Vendor
Arraytics
Product
Timetics
Provider severity
HIGH
Conflicts
0

CVE-2025-67914

Path Traversal: '.../...//' vulnerability in beeteam368 VidMov vidmov allows Path Traversal.This issue affects VidMov: from n/a through <= 2.3.8.

PUBLISHED
Vendor
beeteam368
Product
VidMov
Provider severity
HIGH
Conflicts
0

CVE-2025-67913

Missing Authorization vulnerability in Aruba.it Dev Aruba HiSpeed Cache aruba-hispeed-cache allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Aruba HiSpeed Cache: from n/a through < 3.0.3.

PUBLISHED
Vendor
Aruba.it Dev
Product
Aruba HiSpeed Cache
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67912

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Premio Stars Testimonials stars-testimonials-with-slider-and-masonry-grid allows Stored XSS.This issue affects Stars Testimonials: from n/a through <= 3.3.4.

PUBLISHED
Vendor
Premio
Product
Stars Testimonials
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67911

Deserialization of Untrusted Data vulnerability in Tribulant Software Newsletters newsletters-lite allows Object Injection.This issue affects Newsletters: from n/a through <= 4.11.

PUBLISHED
Vendor
Tribulant Software
Product
Newsletters
Provider severity
CRITICAL
Conflicts
0

CVE-2025-67910

Unrestricted Upload of File with Dangerous Type vulnerability in contentstudio Contentstudio contentstudio allows Upload a Web Shell to a Web Server.This issue affects Contentstudio: from n/a through <= 1.3.7.

PUBLISHED
Vendor
contentstudio
Product
Contentstudio
Provider severity
CRITICAL
Conflicts
0

CVE-2025-6791

In the monitoring event logs page, it is possible to alter the http request to insert a reflect payload in the DB. Caused by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon web (Monitoring event logs modules) allows SQL Injection.This issue affects web: 24.10.0, 24.04.0, 23.10.0.

PUBLISHED
Vendor
Centreon
Product
web
Provider severity
HIGH
Conflicts
0

CVE-2025-67909

Authorization Bypass Through User-Controlled Key vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Membership For WooCommerce: from n/a through <= 3.0.3.

PUBLISHED
Vendor
WP Swings
Product
Membership For WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2025-67906

In MISP before 2.5.28, app/View/Elements/Workflows/executionPath.ctp allows XSS in the workflow execution path.

PUBLISHED
Vendor
MISP
Product
MISP
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67905

Malwarebytes AdwCleaner before v.8.7.0 runs as Administrator and performs an insecure log file delete operation in which the target location is user-controllable, allowing a non-admin user to escalate privileges to SYSTEM via a symbolic link, a related issue to CVE-2023-28892. To exploit this, an attacker must create a file in a given folder path and intercept the application log file deletion flow.

PUBLISHED
Vendor
n/a
Product
n/a
Provider severity
HIGH
Conflicts
1

CVE-2025-67903

Northern.tech Mender Client 5 before 5.0.4 allows a Cryptographic signature verification bypass.

PUBLISHED
Vendor
n/a
Product
n/a
Provider severity
MEDIUM
Conflicts
1

CVE-2025-67901

openrsync through 0.5.0, as used in OpenBSD through 7.8 and on other platforms, allows a client to cause a server SIGSEGV by specifying a length of zero for block data, because the relationship between p->rem and p->len is not checked.

PUBLISHED
Vendor
kristapsdz
Product
openrsync
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67900

NXLog Agent before 6.11 can load a file specified by the OPENSSL_CONF environment variable.

PUBLISHED
Vendor
NXLog
Product
NXLog Agent
Provider severity
HIGH
Conflicts
0

CVE-2025-6790

The Quiz and Survey Master (QSM) WordPress plugin before 10.2.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

PUBLISHED
Vendor
Unknown
Product
Quiz and Survey Master (QSM)
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67899

uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by ParseMustBeSegmentNzNc with large input containing many commas.

PUBLISHED
Vendor
uriparser project
Product
uriparser
Provider severity
LOW
Conflicts
0

CVE-2025-67898

MJML through 4.18.0 allows mj-include directory traversal to test file existence and (in the type="css" case) read files. NOTE: this issue exists because of an incomplete fix for CVE-2020-12827.

PUBLISHED
Vendor
MJML
Product
MJML
Provider severity
MEDIUM
Conflicts
0