Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-64377

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CridioStudio ListingPro listingpro allows PHP Local File Inclusion.This issue affects ListingPro: from n/a through < 2.9.10.

PUBLISHED
Vendor
CridioStudio
Product
ListingPro
Provider severity
HIGH
Conflicts
0

CVE-2025-64376

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CridioStudio ListingPro listingpro allows Reflected XSS.This issue affects ListingPro: from n/a through < 2.9.10.

PUBLISHED
Vendor
CridioStudio
Product
ListingPro
Provider severity
HIGH
Conflicts
0

CVE-2025-64375

Missing Authorization vulnerability in Mahmudul Hasan Arif WP Social Ninja wp-social-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Social Ninja: from n/a through <= 3.20.1.

PUBLISHED
Vendor
Mahmudul Hasan Arif
Product
WP Social Ninja
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64374

Unrestricted Upload of File with Dangerous Type vulnerability in StylemixThemes Motors motors allows Using Malicious Files.This issue affects Motors: from n/a through <= 5.6.81.

PUBLISHED
Vendor
StylemixThemes
Product
Motors
Provider severity
CRITICAL
Conflicts
0

CVE-2025-64373

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in shinetheme Traveler traveler allows PHP Local File Inclusion.This issue affects Traveler: from n/a through < 3.2.6.

PUBLISHED
Vendor
shinetheme
Product
Traveler
Provider severity
HIGH
Conflicts
0

CVE-2025-64372

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shinetheme Traveler traveler allows Reflected XSS.This issue affects Traveler: from n/a through < 3.2.6.

PUBLISHED
Vendor
shinetheme
Product
Traveler
Provider severity
HIGH
Conflicts
0

CVE-2025-64371

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler traveler allows Blind SQL Injection.This issue affects Traveler: from n/a through < 3.2.6.

PUBLISHED
Vendor
shinetheme
Product
Traveler
Provider severity
HIGH
Conflicts
0

CVE-2025-64370

Missing Authorization vulnerability in YOP YOP Poll yop-poll allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YOP Poll: from n/a through <= 6.5.38.

PUBLISHED
Vendor
YOP
Product
YOP Poll
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6437

The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via the ‘oid’ parameter in all versions up to, and including, 4.89 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PUBLISHED
Vendor
scripteo
Product
Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager
Provider severity
HIGH
Conflicts
0

CVE-2025-64369

Missing Authorization vulnerability in codepeople Contact Form Email contact-form-to-email allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form Email: from n/a through <= 1.3.58.

PUBLISHED
Vendor
codepeople
Product
Contact Form Email
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64368

Cross-Site Request Forgery (CSRF) vulnerability in Mikado-Themes Bard bardwp allows Cross Site Request Forgery.This issue affects Bard: from n/a through <= 1.6.

PUBLISHED
Vendor
Mikado-Themes
Product
Bard
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64367

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Adrian Tobey Groundhogg groundhogg allows Stored XSS.This issue affects Groundhogg: from n/a through <= 4.2.6.

PUBLISHED
Vendor
Adrian Tobey
Product
Groundhogg
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64366

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Blind SQL Injection.This issue affects MasterStudy LMS: from n/a through <= 3.6.27.

PUBLISHED
Vendor
Stylemix
Product
MasterStudy LMS
Provider severity
HIGH
Conflicts
0

CVE-2025-64365

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in colabrio Ohio Extra ohio-extra allows DOM-Based XSS.This issue affects Ohio Extra: from n/a through <= 3.6.0.

PUBLISHED
Vendor
colabrio
Product
Ohio Extra
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64364

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Masterstudy masterstudy allows PHP Local File Inclusion.This issue affects Masterstudy: from n/a through < 4.8.126.

PUBLISHED
Vendor
StylemixThemes
Product
Masterstudy
Provider severity
HIGH
Conflicts
0

CVE-2025-64363

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SeventhQueen Kleo kleo allows PHP Local File Inclusion.This issue affects Kleo: from n/a through < 5.5.0.

PUBLISHED
Vendor
SeventhQueen
Product
Kleo
Provider severity
HIGH
Conflicts
0

CVE-2025-64362

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SeventhQueen K Elements k-elements allows DOM-Based XSS.This issue affects K Elements: from n/a through < 5.5.0.

PUBLISHED
Vendor
SeventhQueen
Product
K Elements
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64361

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StylemixThemes Consulting Elementor Widgets consulting-elementor-widgets allows DOM-Based XSS.This issue affects Consulting Elementor Widgets: from n/a through <= 1.4.2.

PUBLISHED
Vendor
StylemixThemes
Product
Consulting Elementor Widgets
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64360

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Consulting Elementor Widgets consulting-elementor-widgets allows PHP Local File Inclusion.This issue affects Consulting Elementor Widgets: from n/a through <= 1.4.2.

PUBLISHED
Vendor
StylemixThemes
Product
Consulting Elementor Widgets
Provider severity
HIGH
Conflicts
0

CVE-2025-6436

Memory safety bugs present in Firefox 139 and Thunderbird 139. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 140 and Thunderbird 140.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Firefox, Thunderbird
Provider severity
HIGH
Conflicts
1

CVE-2025-64359

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Consulting consulting allows PHP Local File Inclusion.This issue affects Consulting: from n/a through < 6.7.5.

PUBLISHED
Vendor
StylemixThemes
Product
Consulting
Provider severity
HIGH
Conflicts
0

CVE-2025-64358

Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce wt-smart-coupons-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart Coupons for WooCommerce: from n/a through <= 2.2.3.

PUBLISHED
Vendor
WebToffee
Product
Smart Coupons for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64357

Cross-Site Request Forgery (CSRF) vulnerability in Younes JFR. Advanced Database Cleaner advanced-database-cleaner allows Cross Site Request Forgery.This issue affects Advanced Database Cleaner: from n/a through <= 3.1.6.

PUBLISHED
Vendor
Younes JFR.
Product
Advanced Database Cleaner
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64356

Missing Authorization vulnerability in f1logic Insert PHP Code Snippet insert-php-code-snippet allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Insert PHP Code Snippet: from n/a through <= 1.4.3.

PUBLISHED
Vendor
f1logic
Product
Insert PHP Code Snippet
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64355

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElements For Elementor jet-elements allows DOM-Based XSS.This issue affects JetElements For Elementor: from n/a through <= 2.7.12.

PUBLISHED
Vendor
Crocoblock
Product
JetElements For Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64354

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matias Ventura Gutenberg gutenberg allows Stored XSS.This issue affects Gutenberg: from n/a through <= 21.8.2.

PUBLISHED
Vendor
Matias Ventura
Product
Gutenberg
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64353

Deserialization of Untrusted Data vulnerability in Chouby Polylang polylang allows Object Injection.This issue affects Polylang: from n/a through <= 3.7.3.

PUBLISHED
Vendor
Chouby
Product
Polylang
Provider severity
HIGH
Conflicts
0

CVE-2025-64352

Missing Authorization vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Addons for Elementor: from n/a through <= 6.2.4.

PUBLISHED
Vendor
WPDeveloper
Product
Essential Addons for Elementor
Provider severity
LOW
Conflicts
0

CVE-2025-64351

Insertion of Sensitive Information Into Sent Data vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows Retrieve Embedded Sensitive Data.This issue affects Rank Math SEO: from n/a through <= 1.0.252.1.

PUBLISHED
Vendor
Rank Math SEO
Product
Rank Math SEO
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64350

Missing Authorization vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rank Math SEO: from n/a through <= 1.0.252.1.

PUBLISHED
Vendor
Rank Math SEO
Product
Rank Math SEO
Provider severity
LOW
Conflicts
0

CVE-2025-6435

If a user saved a response from the Network tab in Devtools using the Save As context menu option, that file may not have been saved with the `.download` file extension. This could have led to the user inadvertently running a malicious executable. This vulnerability was fixed in Firefox 140 and Thunderbird 140.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Thunderbird, Firefox
Provider severity
HIGH
Conflicts
1

CVE-2025-64349

ELOG allows an authenticated user to modify another user's profile. An attacker can edit a target user's email address, then request a password reset, and take control of the target account. By default, ELOG is not configured to allow self-registration.

PUBLISHED
Vendor
ELOG
Product
ELOG
Provider severity
HIGH
Conflicts
1

CVE-2025-64348

ELOG allows an authenticated user to modify or overwrite the configuration file, resulting in denial of service. If the execute facility is specifically enabled with the "-x" command line flag, attackers could execute OS commands on the host machine. By default, ELOG is not configured to allow shell commands or self-registration.

PUBLISHED
Vendor
ELOG
Product
ELOG
Provider severity
CRITICAL, HIGH
Conflicts
1

CVE-2025-64347

Apollo Router Core is a configurable Rust graph router written to run a federated supergraph using Apollo Federation 2. Versions 1.61.12-rc.0 and below and 2.8.1-rc.0 allow unauthorized access to protected data through schema elements with access control directives (@authenticated, @requiresScopes, and @policy) that were renamed via @link imports. Router did not enforce renamed access control directives on schema elements (e.g. fields and types), allowing queries to bypass those element-level ac

PUBLISHED
Vendor
apollographql
Product
router
Provider severity
HIGH
Conflicts
0

CVE-2025-64346

archives is a Go library for extracting archives (tar, zip, etc.). Version 1.0.0 does not prevent a malicious user to feed a specially crafted archive to the library causing RCE, modification of files or other malignancies in the context of whatever the user is running this library as, through the program that imports it. Severity depends on user permissions, environment and how arbitrary archives are passed. This issue is fixed in version 1.0.1.

PUBLISHED
Vendor
jaredallard
Product
archives
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64345

Wasmtime is a runtime for WebAssembly. Prior to version 38.0.4, 37.0.3, 36.0.3, and 24.0.5, Wasmtime's Rust embedder API contains an unsound interaction where a WebAssembly shared linear memory could be viewed as a type which provides safe access to the host (Rust) to the contents of the linear memory. This is not sound for shared linear memories, which could be modified in parallel, and this could lead to a data race in the host. Patch releases have been issued for all supported versions of Was

PUBLISHED
Vendor
bytecodealliance
Product
wasmtime
Provider severity
LOW
Conflicts
0

CVE-2025-64344

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, working with large buffers in Lua scripts can lead to a stack overflow. Users of Lua rules and output scripts may be affected when working with large buffers. This includes a rule passing a large buffer to a Lua script. This issue has been patched in versions 7.0.13 and 8.0.2. A workaround for this issue involves disabling Lua

PUBLISHED
Vendor
OISF
Product
suricata
Provider severity
HIGH
Conflicts
0

CVE-2025-64343

(conda) Constructor is a tool that enables users to create installers for conda package collections. In versions 3.12.2 and below, the installation directory inherits permissions from its parent directory. Outside of restricted directories, the permissions are very permissive and often allow write access by authenticated users. Any logged in user can make modifications during the installation for both single-user and all-user installations. This constitutes a local attack vector if the installa

PUBLISHED
Vendor
conda
Product
constructor
Provider severity
HIGH
Conflicts
0

CVE-2025-64342

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. When the ESP32 is in advertising mode, if it receives a connection request containing an invalid Access Address (AA) of 0x00000000 or 0xFFFFFFFF, advertising may stop unexpectedly. In this case, the controller may incorrectly report a connection event to the host, which can cause the application layer to assume that the device has successfully established a connection. This issue has been fixed in versions 5.5.2, 5.4.3, 5.3

PUBLISHED
Vendor
espressif
Product
esp-idf
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64340

FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, server names containing shell metacharacters (e.g., &) can cause command injection on Windows when passed to fastmcp install claude-code or fastmcp install gemini-cli. These install paths use subprocess.run() with a list argument, but on Windows the target CLIs often resolve to .cmd wrappers that are executed through cmd.exe, which interprets metacharacters in the flattened command string. This issue has bee

PUBLISHED
Vendor
jlowin
Product
fastmcp
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6434

The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an attacker to trick a user into granting an exception and loading a webpage over HTTP. This vulnerability was fixed in Firefox 140 and Thunderbird 140.

PUBLISHED
Vendor
Mozilla, Mozilla
Product
Firefox, Thunderbird
Provider severity
MEDIUM
Conflicts
1

CVE-2025-64339

ClipBucket v5 is an open source video sharing platform. In versions 5.5.2-#146 and below, the Manage Playlists feature is vulnerable to stored Cross-site Scripting (XSS),specifically in the Playlist Name field. An authenticated low-privileged user can create a playlist with a malicious name containing HTML/JavaScript code, which is rendered unescaped on playlist detail and listing pages. This results in arbitrary JavaScript execution in every viewer’s browser, including administrators. This issu

PUBLISHED
Vendor
MacWarrior
Product
clipbucket-v5
Provider severity
HIGH
Conflicts
0

CVE-2025-64338

ClipBucket v5 is an open source video sharing platform. In versions 5.5.2 - #156 and below, an authenticated regular user can create a photo collection whose Collection Name contains HTML/JavaScript payloads, which making ClipBucket’s Manage Photos feature vulnerable to Stored XSS. The payload is rendered unsafely in the Admin → Manage Photos interface, causing it to execute in the administrator’s browser, therefore allowing an attacker to target administrators and perform actions with elevated

PUBLISHED
Vendor
MacWarrior
Product
clipbucket-v5
Provider severity
MEDIUM
Conflicts
1

CVE-2025-64336

ClipBucket v5 is an open source video sharing platform. In versions 5.5.2-#146 and below, the Manage Photos feature is vulnerable to stored Cross-site Scripting (XSS). An authenticated regular user can upload a photo with a malicious Photo Title containing HTML/JavaScript code. While the payload does not execute in the user-facing photo gallery or detail pages, it is rendered unsafely in the Admin → Manage Photos section, resulting in JavaScript execution in the administrator’s browser. This iss

PUBLISHED
Vendor
MacWarrior
Product
clipbucket-v5
Provider severity
HIGH
Conflicts
1

CVE-2025-64335

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, a NULL dereference can occur when the entropy keyword is used in conjunction with base64_data. This issue has been patched in version 8.0.2. A workaround involves disabling rules that use entropy in conjunction with base64_data.

PUBLISHED
Vendor
OISF
Product
suricata
Provider severity
HIGH
Conflicts
0

CVE-2025-64334

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, compressed HTTP data can lead to unbounded memory growth during decompression. This issue has been patched in version 8.0.2. A workaround involves disabling LZMA decompression or limiting response-body-limit size.

PUBLISHED
Vendor
OISF
Product
suricata
Provider severity
HIGH
Conflicts
0

CVE-2025-64333

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, a large HTTP content type, when logged can cause a stack overflow crashing Suricata. This issue has been patched in versions 7.0.13 and 8.0.2. A workaround for this issue involves limiting stream.reassembly.depth to less then half the stack size. Increasing the process stack size makes it less likely the bug will trigger.

PUBLISHED
Vendor
OISF
Product
suricata
Provider severity
HIGH
Conflicts
0

CVE-2025-64332

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, a stack overflow that causes Suricata to crash can occur if SWF decompression is enabled. This issue has been patched in versions 7.0.13 and 8.0.2. A workaround for this issue involves disabling SWF decompression (swf-decompression in suricata.yaml), it is disabled by default; set decompress-depth to lower than half your stack

PUBLISHED
Vendor
OISF
Product
suricata
Provider severity
HIGH
Conflicts
0

CVE-2025-64331

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, a stack overflow can occur on large HTTP file transfers if the user has increased the HTTP response body limit and enabled the logging of printable http bodies. This issue has been patched in versions 7.0.13 and 8.0.2. A workaround for this issue involves using default HTTP response body limits and/or disabling http-body-printa

PUBLISHED
Vendor
OISF
Product
suricata
Provider severity
HIGH
Conflicts
0

CVE-2025-64330

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, a single byte read heap overflow when logging the verdict in eve.alert and eve.drop records can lead to crashes. This requires the per packet alert queue to be filled with alerts and then followed by a pass rule. This issue has been patched in versions 7.0.13 and 8.0.2. To reduce the likelihood of this issue occurring, the aler

PUBLISHED
Vendor
OISF
Product
suricata
Provider severity
HIGH
Conflicts
0