Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-62897

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Brecht WP Recipe Maker wp-recipe-maker allows Code Injection.This issue affects WP Recipe Maker: from n/a through < 10.1.0.

PUBLISHED
Vendor
Brecht
Product
WP Recipe Maker
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62896

Cross-Site Request Forgery (CSRF) vulnerability in digitaldonkey Multilang Contact Form multilang-contact-form allows Stored XSS.This issue affects Multilang Contact Form: from n/a through <= 1.5.

PUBLISHED
Vendor
digitaldonkey
Product
Multilang Contact Form
Provider severity
HIGH
Conflicts
0

CVE-2025-62895

Insertion of Sensitive Information Into Sent Data vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Retrieve Embedded Sensitive Data.This issue affects Atarim: from n/a through <= 4.2.1.

PUBLISHED
Vendor
Vito Peleg
Product
Atarim
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62894

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in magicoders ACF Recent Posts Widget acf-recent-posts-widget allows Stored XSS.This issue affects ACF Recent Posts Widget: from n/a through <= 5.9.3.

PUBLISHED
Vendor
magicoders
Product
ACF Recent Posts Widget
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62892

Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Sunshine Photo Cart: from n/a through <= 3.5.3.

PUBLISHED
Vendor
sunshinephotocart
Product
Sunshine Photo Cart
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62891

Cross-Site Request Forgery (CSRF) vulnerability in Jory Hogeveen Off-Canvas Sidebars & Menus (Slidebars) off-canvas-sidebars allows Cross Site Request Forgery.This issue affects Off-Canvas Sidebars & Menus (Slidebars): from n/a through <= 0.5.8.5.

PUBLISHED
Vendor
Jory Hogeveen
Product
Off-Canvas Sidebars & Menus (Slidebars)
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62890

Cross-Site Request Forgery (CSRF) vulnerability in Premmerce Premmerce Brands for WooCommerce premmerce-woocommerce-brands allows Cross Site Request Forgery.This issue affects Premmerce Brands for WooCommerce: from n/a through <= 1.2.13.

PUBLISHED
Vendor
Premmerce
Product
Premmerce Brands for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62889

Missing Authorization vulnerability in KingAddons.com King Addons for Elementor king-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects King Addons for Elementor: from n/a through <= 51.1.61.

PUBLISHED
Vendor
KingAddons.com
Product
King Addons for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62888

Missing Authorization vulnerability in Marco Milesi WP Attachments wp-attachments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Attachments: from n/a through <= 5.2.

PUBLISHED
Vendor
Marco Milesi
Product
WP Attachments
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62887

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KingAddons.com King Addons for Elementor king-addons allows DOM-Based XSS.This issue affects King Addons for Elementor: from n/a through <= 51.1.61.

PUBLISHED
Vendor
KingAddons.com
Product
King Addons for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62886

Cross-Site Request Forgery (CSRF) vulnerability in wpdevart Pricing Table builder wpdevart-pricing-table allows Stored XSS.This issue affects Pricing Table builder: from n/a through <= 1.5.3.

PUBLISHED
Vendor
wpdevart
Product
Pricing Table builder
Provider severity
HIGH
Conflicts
0

CVE-2025-62885

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RexTheme WP VR wpvr allows DOM-Based XSS.This issue affects WP VR: from n/a through <= 8.5.48.

PUBLISHED
Vendor
RexTheme
Product
WP VR
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62884

Missing Authorization vulnerability in Elliot Sowersby / RelyWP Coupon Affiliates woo-coupon-usage allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Coupon Affiliates: from n/a through <= 7.2.0.

PUBLISHED
Vendor
Elliot Sowersby / RelyWP
Product
Coupon Affiliates
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62883

Missing Authorization vulnerability in Premmerce Premmerce User Roles premmerce-user-roles allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Premmerce User Roles: from n/a through <= 1.0.13.

PUBLISHED
Vendor
Premmerce
Product
Premmerce User Roles
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62882

Missing Authorization vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Seriously Simple Podcasting: from n/a through <= 3.13.0.

PUBLISHED
Vendor
Craig Hewitt
Product
Seriously Simple Podcasting
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62881

Missing Authorization vulnerability in WP Lab WP-Lister Lite for eBay wp-lister-for-ebay allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP-Lister Lite for eBay: from n/a through <= 3.8.3.

PUBLISHED
Vendor
WP Lab
Product
WP-Lister Lite for eBay
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62880

Cross-Site Request Forgery (CSRF) vulnerability in Kunal Custom 404 Pro custom-404-pro allows Cross Site Request Forgery.This issue affects Custom 404 Pro: from n/a through <= 3.12.0.

PUBLISHED
Vendor
Kunal
Product
Custom 404 Pro
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6288

A vulnerability, which was classified as problematic, has been found in PHPGurukul Bus Pass Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/admin-profile.php of the component Profile Page. The manipulation of the argument profile name leads to cross site scripting. The attack may be launched remotely.

PUBLISHED
Vendor
PHPGurukul
Product
Bus Pass Management System
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-62879

A vulnerability has been identified within the Rancher Backup Operator, resulting in the leakage of S3 tokens (both accessKey and secretKey) into the rancher-backup-operator pod's logs.

PUBLISHED
Vendor
SUSE
Product
Rancher
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62878

A malicious user can manipulate the parameters.pathPattern to create PersistentVolumes in arbitrary locations on the host node, potentially overwriting sensitive files or gaining access to unintended directories.

PUBLISHED
Vendor
SUSE
Product
Rancher
Provider severity
CRITICAL
Conflicts
0

CVE-2025-62877

Projects using the SUSE Virtualization (Harvester) environment may expose the OS default ssh login password  if they are using the 1.5.x or 1.6.x interactive installer to either create a new cluster or add new hosts to an existing cluster. The environment is not affected if the PXE boot mechanism is utilized along with the Harvester configuration setup.

PUBLISHED
Vendor
SUSE
Product
harvester
Provider severity
CRITICAL
Conflicts
0

CVE-2025-62876

A Execution with Unnecessary Privileges vulnerability in lightdm-kde-greeter allows escalation from the service user to root.This issue affects lightdm-kde-greeter. before 6.0.4.

PUBLISHED
Vendor
SUSE
Product
openSUSE
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62875

An Improper Check for Unusual or Exceptional Conditions vulnerability in OpenSMTPD allows local users to crash OpenSMTPD. This issue affects openSUSE Tumbleweed: from ? before 7.8.0p0-1.1.

PUBLISHED
Vendor
SUSE
Product
openSUSE Tumbleweed
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62874

Missing Authorization vulnerability in Alexander AnyComment anycomment allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AnyComment: from n/a through <= 0.3.6.

PUBLISHED
Vendor
Alexander
Product
AnyComment
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62873

Cross-Site Request Forgery (CSRF) vulnerability in Flashyapp WP Flashy Marketing Automation wp-flashy-marketing-automation allows Cross Site Request Forgery.This issue affects WP Flashy Marketing Automation: from n/a through <= 2.0.8.

PUBLISHED
Vendor
Flashyapp
Product
WP Flashy Marketing Automation
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62872

Cross-Site Request Forgery (CSRF) vulnerability in JK Social Photo Fetcher facebook-photo-fetcher allows Cross Site Request Forgery.This issue affects Social Photo Fetcher: from n/a through <= 3.0.4.

PUBLISHED
Vendor
JK
Product
Social Photo Fetcher
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62871

Cross-Site Request Forgery (CSRF) vulnerability in Alex Prokopenko / JustCoded Just TinyMCE Custom Styles just-tinymce-styles allows Cross Site Request Forgery.This issue affects Just TinyMCE Custom Styles: from n/a through <= 1.2.1.

PUBLISHED
Vendor
Alex Prokopenko / JustCoded
Product
Just TinyMCE Custom Styles
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62870

Missing Authorization vulnerability in Eupago Eupago Gateway For Woocommerce eupago-gateway-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Eupago Gateway For Woocommerce: from n/a through <= 4.7.1.

PUBLISHED
Vendor
Eupago
Product
Eupago Gateway For Woocommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6287

A vulnerability classified as problematic was found in PHPGurukul COVID19 Testing Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /test-details.php of the component Take Action. The manipulation of the argument remark leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
PHPGurukul
Product
COVID19 Testing Management System
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-62869

Missing Authorization vulnerability in Gravitec.net - Web Push Notifications Gravitec.net – Web Push Notifications gravitec-net-web-push-notifications allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gravitec.net – Web Push Notifications: from n/a through <= 2.9.17.

PUBLISHED
Vendor
Gravitec.net - Web Push Notifications
Product
Gravitec.net – Web Push Notifications
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62868

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Edge CPT allows PHP Local File Inclusion.This issue affects Edge CPT: from n/a through 1.4.

PUBLISHED
Vendor
Edge-Themes
Product
Edge CPT
Provider severity
HIGH
Conflicts
0

CVE-2025-62867

Missing Authorization vulnerability in ergonet Ergonet Cache ergonet-varnish-cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ergonet Cache: from n/a through <= 1.0.13.

PUBLISHED
Vendor
ergonet
Product
Ergonet Cache
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62866

Cross-Site Request Forgery (CSRF) vulnerability in Valerio Monti Auto Alt Text auto-alt-text allows Cross Site Request Forgery.This issue affects Auto Alt Text: from n/a through <= 2.5.2.

PUBLISHED
Vendor
Valerio Monti
Product
Auto Alt Text
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62865

Missing Authorization vulnerability in Evan Herman Post Cloner post-cloner allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Cloner: from n/a through <= 1.0.0.

PUBLISHED
Vendor
Evan Herman
Product
Post Cloner
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62864

Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.5.1 allow an incorrectly formed SMC call to UEFI-MM MMCommunicate service that could result in an out-of-bounds write within the UEFI-MM Secure Partition context.

PUBLISHED
Vendor
n/a
Product
n/a
Provider severity
CRITICAL
Conflicts
1

CVE-2025-62863

Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.5.1 allow an incorrectly formed SMC call to UEFI-MM PCIe driver that could result in an out-of-bounds write within PCIe driver’s S-EL0 address space.

PUBLISHED
Vendor
n/a
Product
n/a
Provider severity
CRITICAL
Conflicts
1

CVE-2025-62862

Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.5.1 allow an incorrectly formed SMC call to UEFI-MM Boot Error Record Table driver that could result in (1) an out-of-bounds read which leaks Secure-EL0 information to a process running in Non-Secure state or (2) an out-of-bounds write which corrupts Secure or Non-Secure memory, limited to memory mapped to UEFI-MM Secure Partition by the Secure Partition Manager.

PUBLISHED
Vendor
n/a
Product
n/a
Provider severity
MEDIUM
Conflicts
1

CVE-2025-6286

A vulnerability classified as problematic has been found in PHPGurukul COVID19 Testing Management System 2021. Affected is an unknown function of the file /search-report-result.php. The manipulation of the argument q leads to open redirect. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
PHPGurukul
Product
COVID19 Testing Management System
Provider severity
LOW, MEDIUM
Conflicts
1

CVE-2025-62858

A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build 20260214 and later QuTS hero h5.2.9.3410 build 20260214 and later QuTS hero h5.3.4.3500 build 20260520 and later QuTS hero h6.0.0.3397 build 20260206 and later

PUBLISHED
Vendor
QNAP Systems Inc., QNAP Systems Inc.
Product
QTS, QuTS hero
Provider severity
MEDIUM
Conflicts
1

CVE-2025-62857

A cross-site scripting (XSS) vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following version: QuMagie 2.8.1 and later

PUBLISHED
Vendor
QNAP Systems Inc.
Product
QuMagie
Provider severity
LOW
Conflicts
0

CVE-2025-62856

A path traversal vulnerability has been reported to affect File Station 5. If a local attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5190 and later

PUBLISHED
Vendor
QNAP Systems Inc.
Product
File Station 5
Provider severity
LOW
Conflicts
0

CVE-2025-62855

A path traversal vulnerability has been reported to affect File Station 5. If a local attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5190 and later

PUBLISHED
Vendor
QNAP Systems Inc.
Product
File Station 5
Provider severity
LOW
Conflicts
0

CVE-2025-62854

An uncontrolled resource consumption vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5190 and later

PUBLISHED
Vendor
QNAP Systems Inc.
Product
File Station 5
Provider severity
LOW
Conflicts
0

CVE-2025-62853

A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5166 and later

PUBLISHED
Vendor
QNAP Systems Inc.
Product
File Station 5
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62852

A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: QTS 5.2.8.3332 build 20251128 and later

PUBLISHED
Vendor
QNAP Systems Inc.
Product
QTS
Provider severity
LOW
Conflicts
0

CVE-2025-62851

A path traversal vulnerability has been reported to affect License Center. If a local attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: License Center 1.9.56 and later

PUBLISHED
Vendor
QNAP Systems Inc.
Product
License Center
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62850

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QuTS hero h5.2.9.3410 build 20260214 and later QuTS hero h5.3.4.3500 build 20260520 and later QuTS hero h6.0.0.3459 build 20260409 and later

PUBLISHED
Vendor
QNAP Systems Inc.
Product
QuTS hero
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6285

A vulnerability was found in PHPGurukul COVID19 Testing Management System 2021. It has been rated as problematic. This issue affects some unknown processing of the file /search-report-result.php. The manipulation of the argument q leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
PHPGurukul
Product
COVID19 Testing Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-62849

An SQL injection vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3297 build 20251024 and later QuTS hero h5.2.7.3297 build 20251024 and later QuTS hero h5.3.1.3292 build 20251024 and later

PUBLISHED
Vendor
QNAP Systems Inc., QNAP Systems Inc.
Product
QuTS hero, QTS
Provider severity
MEDIUM
Conflicts
1

CVE-2025-62848

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3297 build 20251024 and later QuTS hero h5.2.7.3297 build 20251024 and later QuTS hero h5.3.1.3292 build 20251024 and later

PUBLISHED
Vendor
QNAP Systems Inc., QNAP Systems Inc.
Product
QTS, QuTS hero
Provider severity
HIGH
Conflicts
1