Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-6609

A vulnerability was found in SourceCodester Best Salon Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /panel/bwdates-reports-details.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
SourceCodester
Product
Best Salon Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-66089

Missing Authorization vulnerability in WebToffee Product Feed for WooCommerce webtoffee-product-feed allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Feed for WooCommerce: from n/a through <= 2.3.1.

PUBLISHED
Vendor
WebToffee
Product
Product Feed for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66088

Missing Authorization vulnerability in Property Hive PropertyHive propertyhive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PropertyHive: from n/a through <= 2.1.12.

PUBLISHED
Vendor
Property Hive
Product
PropertyHive
Provider severity
HIGH
Conflicts
0

CVE-2025-66087

Missing Authorization vulnerability in Property Hive PropertyHive propertyhive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PropertyHive: from n/a through <= 2.1.12.

PUBLISHED
Vendor
Property Hive
Product
PropertyHive
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66086

Missing Authorization vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SMS Alert Order Notifications: from n/a through <= 3.8.8.

PUBLISHED
Vendor
Cozy Vision
Product
SMS Alert Order Notifications
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66085

Missing Authorization vulnerability in tychesoftwares Arconix Shortcodes arconix-shortcodes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Arconix Shortcodes: from n/a through <= 2.1.18.

PUBLISHED
Vendor
tychesoftwares
Product
Arconix Shortcodes
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66084

Missing Authorization vulnerability in Shahjahan Jewel FluentCommunity fluent-community allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FluentCommunity: from n/a through <= 2.0.0.

PUBLISHED
Vendor
Shahjahan Jewel
Product
FluentCommunity
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66083

Missing Authorization vulnerability in magepeopleteam WpEvently mage-eventpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpEvently: from n/a through <= 5.0.4.

PUBLISHED
Vendor
magepeopleteam
Product
WpEvently
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66082

Missing Authorization vulnerability in magepeopleteam WpEvently mage-eventpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpEvently: from n/a through <= 5.0.4.

PUBLISHED
Vendor
magepeopleteam
Product
WpEvently
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66081

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Head Meta Data head-meta-data allows Stored XSS.This issue affects Head Meta Data: from n/a through <= 20250327.

PUBLISHED
Vendor
Jeff Starr
Product
Head Meta Data
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66080

Missing Authorization vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent gdpr-cookie-consent allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through <= 4.0.3.

PUBLISHED
Vendor
WP Legal Pages
Product
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6608

A vulnerability has been found in SourceCodester Best Salon Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /panel/edit-services.php. The manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
SourceCodester
Product
Best Salon Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-66079

Missing Authorization vulnerability in Jegstudio Gutenverse Form gutenverse-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gutenverse Form: from n/a through <= 2.2.0.

PUBLISHED
Vendor
Jegstudio
Product
Gutenverse Form
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66078

Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters Hotel Booking Lite motopress-hotel-booking-lite allows Remote Code Inclusion.This issue affects Hotel Booking Lite: from n/a through <= 5.2.3.

PUBLISHED
Vendor
jetmonsters
Product
Hotel Booking Lite
Provider severity
CRITICAL
Conflicts
0

CVE-2025-66077

Missing Authorization vulnerability in wpWax Legal Pages legal-pages allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Legal Pages: from n/a through <= 1.4.6.

PUBLISHED
Vendor
wpWax
Product
Legal Pages
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66076

Unauthenticated Broken Access Control in Woostify Sites Library <= 1.6.2 versions.

PUBLISHED
Vendor
dylan ngo
Product
Woostify Sites Library
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66075

Missing Authorization vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent gdpr-cookie-consent allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through <= 4.0.3.

PUBLISHED
Vendor
WP Legal Pages
Product
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66074

Unrestricted Upload of File with Dangerous Type vulnerability in Cozmoslabs WP Webhooks wp-webhooks allows Path Traversal.This issue affects WP Webhooks: from n/a through <= 3.3.8.

PUBLISHED
Vendor
Cozmoslabs
Product
WP Webhooks
Provider severity
CRITICAL
Conflicts
0

CVE-2025-66073

Deserialization of Untrusted Data vulnerability in Cozmoslabs WP Webhooks wp-webhooks allows Object Injection.This issue affects WP Webhooks: from n/a through <= 3.3.8.

PUBLISHED
Vendor
Cozmoslabs
Product
WP Webhooks
Provider severity
HIGH
Conflicts
0

CVE-2025-66072

Missing Authorization vulnerability in Stiofan UsersWP userswp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UsersWP: from n/a through <= 1.2.47.

PUBLISHED
Vendor
Stiofan
Product
UsersWP
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66071

Missing Authorization vulnerability in tychesoftwares Custom Order Numbers for WooCommerce custom-order-numbers-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Custom Order Numbers for WooCommerce: from n/a through <= 1.11.0.

PUBLISHED
Vendor
tychesoftwares
Product
Custom Order Numbers for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66070

Missing Authorization vulnerability in Tomdever wpForo Forum wpforo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpForo Forum: from n/a through <= 2.4.10.

PUBLISHED
Vendor
Tomdever
Product
wpForo Forum
Provider severity
HIGH
Conflicts
0

CVE-2025-6607

A vulnerability, which was classified as critical, was found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the file /panel/stock.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
SourceCodester
Product
Best Salon Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-66069

Missing Authorization vulnerability in Themeisle PPOM for WooCommerce woocommerce-product-addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PPOM for WooCommerce: from n/a through <= 33.0.16.

PUBLISHED
Vendor
Themeisle
Product
PPOM for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66068

Missing Authorization vulnerability in InstaWP InstaWP Connect instawp-connect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects InstaWP Connect: from n/a through <= 0.1.1.9.

PUBLISHED
Vendor
InstaWP
Product
InstaWP Connect
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66067

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aman Funnel Builder by FunnelKit funnel-builder allows DOM-Based XSS.This issue affects Funnel Builder by FunnelKit: from n/a through <= 3.13.1.2.

PUBLISHED
Vendor
Aman
Product
Funnel Builder by FunnelKit
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66066

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EnvoThemes Envo Extra envo-extra allows Stored XSS.This issue affects Envo Extra: from n/a through <= 1.9.11.

PUBLISHED
Vendor
EnvoThemes
Product
Envo Extra
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66065

Missing Authorization vulnerability in Jegstudio Gutenverse gutenverse allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gutenverse: from n/a through <= 3.2.1.

PUBLISHED
Vendor
Jegstudio
Product
Gutenverse
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66064

Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Giveaways and Contests by RafflePress rafflepress allows Cross Site Request Forgery.This issue affects Giveaways and Contests by RafflePress: from n/a through <= 1.12.20.

PUBLISHED
Vendor
Syed Balkhi
Product
Giveaways and Contests by RafflePress
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66063

Missing Authorization vulnerability in jgwhite33 WP Google Review Slider wp-google-places-review-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Google Review Slider: from n/a through <= 17.4.

PUBLISHED
Vendor
jgwhite33
Product
WP Google Review Slider
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66062

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Frank Goossens WP YouTube Lyte wp-youtube-lyte allows Phishing.This issue affects WP YouTube Lyte: from n/a through <= 1.7.28.

PUBLISHED
Vendor
Frank Goossens
Product
WP YouTube Lyte
Provider severity
LOW
Conflicts
0

CVE-2025-66061

Cross-Site Request Forgery (CSRF) vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Cross Site Request Forgery.This issue affects Seriously Simple Podcasting: from n/a through <= 3.13.0.

PUBLISHED
Vendor
Craig Hewitt
Product
Seriously Simple Podcasting
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66060

Missing Authorization vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Seriously Simple Podcasting: from n/a through <= 3.13.0.

PUBLISHED
Vendor
Craig Hewitt
Product
Seriously Simple Podcasting
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6606

A vulnerability, which was classified as critical, has been found in SourceCodester Best Salon Management System 1.0. This issue affects some unknown processing of the file /panel/add-services.php. The manipulation of the argument Type leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
SourceCodester
Product
Best Salon Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-66059

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Retrieve Embedded Sensitive Data.This issue affects Seriously Simple Podcasting: from n/a through <= 3.13.0.

PUBLISHED
Vendor
Craig Hewitt
Product
Seriously Simple Podcasting
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66058

Missing Authorization vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.3.17.

PUBLISHED
Vendor
PickPlugins
Product
Post Grid and Gutenberg Blocks
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66057

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in boldthemes Bold Page Builder bold-page-builder allows DOM-Based XSS.This issue affects Bold Page Builder: from n/a through <= 5.5.2.

PUBLISHED
Vendor
boldthemes
Product
Bold Page Builder
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66056

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Uncanny Owl Uncanny Automator uncanny-automator allows Retrieve Embedded Sensitive Data.This issue affects Uncanny Automator: from n/a through < 6.10.0.

PUBLISHED
Vendor
Uncanny Owl
Product
Uncanny Automator
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66055

Deserialization of Untrusted Data vulnerability in Icegram Email Subscribers & Newsletters email-subscribers allows Object Injection.This issue affects Email Subscribers & Newsletters: from n/a through <= 5.9.10.

PUBLISHED
Vendor
Icegram
Product
Email Subscribers & Newsletters
Provider severity
HIGH
Conflicts
0

CVE-2025-66054

Missing Authorization vulnerability in ThimPress LearnPress learnpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LearnPress: from n/a through <= 4.2.9.4.

PUBLISHED
Vendor
ThimPress
Product
LearnPress
Provider severity
HIGH
Conflicts
0

CVE-2025-66053

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kriesi Enfold enfold allows Stored XSS.This issue affects Enfold: from n/a through <= 7.1.2.

PUBLISHED
Vendor
Kriesi
Product
Enfold
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66052

Vivotek IP7137 camera with firmware version 0200a is vulnerable to command injection. Parameter "system_ntpIt" used by "/cgi-bin/admin/setparam.cgi" endpoint is not sanitized properly, allowing a user with administrative privileges to perform an attack. Due to CVE-2025-66050, administrative access is not protected by default,  The vendor has not replied to the CNA Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released.

PUBLISHED
Vendor
Vivotek
Product
IP7137
Provider severity
HIGH
Conflicts
0

CVE-2025-66051

Vivotek IP7137 camera with firmware version 0200a is vulnerable to path traversal. It is possible for an authenticated attacker to access resources beyond webroot directory using a direct HTTP request. Due to CVE-2025-66050, a password for administration panel is not set by default. The vendor has not replied to the CNA. Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released.

PUBLISHED
Vendor
Vivotek
Product
IP7137
Provider severity
MEDIUM
Conflicts
0

CVE-2025-66050

Vivotek IP7137 camera with firmware version 0200a by default dos not require to provide any password when logging in as an administrator. While it is possible to set up such a password, a user is not informed about such a need. The vendor has not replied to the CNA. Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released.

PUBLISHED
Vendor
Vivotek
Product
IP7137
Provider severity
CRITICAL
Conflicts
0

CVE-2025-6605

A vulnerability classified as critical was found in SourceCodester Best Salon Management System 1.0. This vulnerability affects unknown code of the file /panel/edit-staff.php. The manipulation of the argument editid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
SourceCodester
Product
Best Salon Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-66049

Vivotek IP7137 camera with firmware version 0200a is vulnerable to an information disclosure issue where live camera footage can be accessed through the RTSP protocol on port 8554 without requiring authentication. This allows unauthorized users with network access to view the camera's feed, potentially compromising user privacy and security.  The vendor has not replied to the CNA. Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to b

PUBLISHED
Vendor
Vivotek
Product
IP7137
Provider severity
HIGH
Conflicts
0

CVE-2025-66048

Several stack-based buffer overflow vulnerabilities exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.1. A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger these vulnerabilities.When Tag is 133

PUBLISHED
Vendor
The Biosig Project
Product
libbiosig
Provider severity
CRITICAL
Conflicts
0

CVE-2025-66047

Several stack-based buffer overflow vulnerabilities exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.1. A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger these vulnerabilities.When Tag is 131

PUBLISHED
Vendor
The Biosig Project
Product
libbiosig
Provider severity
CRITICAL
Conflicts
0

CVE-2025-66046

Several stack-based buffer overflow vulnerabilities exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.1. A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger these vulnerabilities.When Tag is 67

PUBLISHED
Vendor
The Biosig Project
Product
libbiosig
Provider severity
CRITICAL
Conflicts
0

CVE-2025-66045

Several stack-based buffer overflow vulnerabilities exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.1. A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger these vulnerabilities.When Tag is 65

PUBLISHED
Vendor
The Biosig Project
Product
libbiosig
Provider severity
CRITICAL
Conflicts
0