Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-62774

On Mercku M6a devices through 2.1.0, the authentication system uses predictable session tokens based on timestamps.

PUBLISHED
Vendor
Mercku
Product
M6a
Provider severity
LOW
Conflicts
0

CVE-2025-62773

Mercku M6a devices through 2.1.0 allow TELNET sessions via a router.telnet.enabled.update request by an administrator.

PUBLISHED
Vendor
Mercku
Product
M6a
Provider severity
LOW
Conflicts
0

CVE-2025-62772

On Mercku M6a devices through 2.1.0, session tokens remain valid for at least months in some cases.

PUBLISHED
Vendor
Mercku
Product
M6a
Provider severity
LOW
Conflicts
0

CVE-2025-62771

Mercku M6a devices through 2.1.0 allow password changes via intranet CSRF attacks.

PUBLISHED
Vendor
Mercku
Product
M6a
Provider severity
HIGH
Conflicts
0

CVE-2025-6277

A vulnerability classified as critical has been found in Brilliance Golden Link Secondary System up to 20250609. This affects an unknown part of the file /storagework/custTakeInfoPage.htm. The manipulation of the argument custTradeName leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
Brilliance
Product
Golden Link Secondary System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-62765

General Industrial Controls Lynx+ Gateway is vulnerable to a cleartext transmission vulnerability that could allow an attacker to observe network traffic to obtain sensitive information, including plaintext credentials.

PUBLISHED
Vendor
General Industrial Controls
Product
Lynx+ Gateway
Provider severity
HIGH
Conflicts
1

CVE-2025-62763

Zimbra Collaboration (ZCS) before 10.1.12 allows SSRF because of the configuration of the chat proxy.

PUBLISHED
Vendor
Zimbra
Product
Collaboration
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62762

Cross-Site Request Forgery (CSRF) vulnerability in photoboxone SMTP Mail smtp-mail allows Cross Site Request Forgery.This issue affects SMTP Mail: from n/a through <= 1.3.51.

PUBLISHED
Vendor
photoboxone
Product
SMTP Mail
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62761

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BasePress Knowledge Base documentation & wiki plugin – BasePress basepress allows Stored XSS.This issue affects Knowledge Base documentation & wiki plugin – BasePress: from n/a through <= 2.17.0.1.

PUBLISHED
Vendor
BasePress
Product
Knowledge Base documentation & wiki plugin – BasePress
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62760

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BuddyDev BuddyPress Activity Shortcode bp-activity-shortcode allows Stored XSS.This issue affects BuddyPress Activity Shortcode: from n/a through <= 1.1.8.

PUBLISHED
Vendor
BuddyDev
Product
BuddyPress Activity Shortcode
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6276

A vulnerability was found in Brilliance Golden Link Secondary System up to 20250609. It has been rated as critical. Affected by this issue is some unknown functionality of the file /storagework/rentTakeInfoPage.htm. The manipulation of the argument custTradeName leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
Brilliance
Product
Golden Link Secondary System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-62759

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Tadlock Series series allows Stored XSS.This issue affects Series: from n/a through <= 2.0.1.

PUBLISHED
Vendor
Justin Tadlock
Product
Series
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62758

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Funnelforms Funnelforms Free funnelforms-free allows DOM-Based XSS.This issue affects Funnelforms Free: from n/a through <= 3.8.

PUBLISHED
Vendor
Funnelforms
Product
Funnelforms Free
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62757

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebMan Design | Oliver Juhas WebMan Amplifier webman-amplifier allows DOM-Based XSS.This issue affects WebMan Amplifier: from n/a through <= 1.5.12.

PUBLISHED
Vendor
WebMan Design | Oliver Juhas
Product
WebMan Amplifier
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62756

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lvaudore The Moneytizer the-moneytizer allows DOM-Based XSS.This issue affects The Moneytizer: from n/a through <= 10.0.9.

PUBLISHED
Vendor
lvaudore
Product
The Moneytizer
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62755

Missing Authorization vulnerability in GS Plugins GS Portfolio for Envato gs-envato-portfolio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GS Portfolio for Envato: from n/a through <= 1.4.2.

PUBLISHED
Vendor
GS Plugins
Product
GS Portfolio for Envato
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62754

Missing Authorization vulnerability in Kapil Paul Payment Gateway bKash for WC woo-payment-bkash allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Payment Gateway bKash for WC: from n/a through <= 3.1.0.

PUBLISHED
Vendor
Kapil Paul
Product
Payment Gateway bKash for WC
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62753

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in MadrasThemes MAS Videos masvideos allows PHP Local File Inclusion.This issue affects MAS Videos: from n/a through <= 1.3.4.

PUBLISHED
Vendor
MadrasThemes
Product
MAS Videos
Provider severity
HIGH
Conflicts
0

CVE-2025-62752

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kalender.digital Kalender.digital kalender-digital allows DOM-Based XSS.This issue affects Kalender.digital: from n/a through <= 1.0.13.

PUBLISHED
Vendor
kalender.digital
Product
Kalender.digital
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62751

Missing Authorization vulnerability in extendthemes Vireo vireo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Vireo: from n/a through <= 1.0.24.

PUBLISHED
Vendor
extendthemes
Product
Vireo
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62750

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Filipe Seabra WooCommerce Parcelas woocommerce-parcelas allows DOM-Based XSS.This issue affects WooCommerce Parcelas: from n/a through <= 1.3.5.

PUBLISHED
Vendor
Filipe Seabra
Product
WooCommerce Parcelas
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6275

A vulnerability was found in WebAssembly wabt up to 1.0.37. It has been declared as problematic. Affected by this vulnerability is the function GetFuncOffset of the file src/interp/binary-reader-interp.cc. The manipulation leads to use after free. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. A similar issue reported during the same timeframe was disputed by the code maintainer because it might not affect "real world wasm pro

PUBLISHED
Vendor
WebAssembly
Product
wabt
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-62749

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bainternet User Specific Content user-specific-content allows DOM-Based XSS.This issue affects User Specific Content: from n/a through <= 1.0.6.

PUBLISHED
Vendor
Bainternet
Product
User Specific Content
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62748

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Genetech Products Web and WooCommerce Addons for WPBakery Builder vc-addons-by-bit14 allows DOM-Based XSS.This issue affects Web and WooCommerce Addons for WPBakery Builder: from n/a through <= 1.5.

PUBLISHED
Vendor
Genetech Products
Product
Web and WooCommerce Addons for WPBakery Builder
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62747

Missing Authorization vulnerability in Aum Watcharapon Featured Image Generator featured-image-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Featured Image Generator: from n/a through <= 1.3.4.

PUBLISHED
Vendor
Aum Watcharapon
Product
Featured Image Generator
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62746

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeFlavors Featured Video for WordPress – VideographyWP videographywp allows Stored XSS.This issue affects Featured Video for WordPress – VideographyWP: from n/a through <= 1.0.18.

PUBLISHED
Vendor
CodeFlavors
Product
Featured Video for WordPress – VideographyWP
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62745

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Team Showcase allows Stored XSS. This issue affects Team Showcase: from n/a through 1.22.28.

PUBLISHED
Vendor
PickPlugins
Product
Team Showcase
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62744

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chris Steman Page Title Splitter page-title-splitter allows Stored XSS.This issue affects Page Title Splitter: from n/a through <= 2.5.9.

PUBLISHED
Vendor
Chris Steman
Product
Page Title Splitter
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62743

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zookatron MyBookTable Bookstore mybooktable allows Stored XSS.This issue affects MyBookTable Bookstore: from n/a through <= 3.6.0.

PUBLISHED
Vendor
zookatron
Product
MyBookTable Bookstore
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62742

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Curator.io Curator.io curatorio allows Stored XSS.This issue affects Curator.io: from n/a through <= 1.9.5.

PUBLISHED
Vendor
Curator.io
Product
Curator.io
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62741

Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft Pool Services pool-services allows Server Side Request Forgery.This issue affects Pool Services: from n/a through <= 3.3.

PUBLISHED
Vendor
SmartDataSoft
Product
Pool Services
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62740

Missing Authorization vulnerability in Mario Peshev WP-CRM System wp-crm-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP-CRM System: from n/a through <= 3.4.6.

PUBLISHED
Vendor
Mario Peshev
Product
WP-CRM System
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6274

A vulnerability was found in WebAssembly wabt up to 1.0.37. It has been classified as problematic. Affected is the function OnDataCount of the file src/interp/binary-reader-interp.cc. The manipulation leads to resource consumption. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. A similar issue reported during the same timeframe was disputed by the code maintainer because it might not affect "real world wasm programs". Therefore, this entry might

PUBLISHED
Vendor
WebAssembly
Product
wabt
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-62739

Cross-Site Request Forgery (CSRF) vulnerability in SaifuMak Add Custom Codes add-custom-codes allows Cross Site Request Forgery.This issue affects Add Custom Codes: from n/a through <= 4.80.

PUBLISHED
Vendor
SaifuMak
Product
Add Custom Codes
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62738

Missing Authorization vulnerability in mmattax Formstack Online Forms formstack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Formstack Online Forms: from n/a through <= 2.0.2.

PUBLISHED
Vendor
mmattax
Product
Formstack Online Forms
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62737

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in opicron Image Cleanup image-cleanup allows Retrieve Embedded Sensitive Data.This issue affects Image Cleanup: from n/a through <= 1.9.2.

PUBLISHED
Vendor
opicron
Product
Image Cleanup
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62736

Missing Authorization vulnerability in opicron Image Cleanup image-cleanup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Cleanup: from n/a through <= 1.9.2.

PUBLISHED
Vendor
opicron
Product
Image Cleanup
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62735

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Joel User Spam Remover user-spam-remover allows Retrieve Embedded Sensitive Data.This issue affects User Spam Remover: from n/a through <= 1.1.

PUBLISHED
Vendor
Joel
Product
User Spam Remover
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62734

Cross-Site Request Forgery (CSRF) vulnerability in M.Code Media Library Downloader media-library-downloader allows Cross Site Request Forgery.This issue affects Media Library Downloader: from n/a through <= 1.4.0.

PUBLISHED
Vendor
M.Code
Product
Media Library Downloader
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62733

Cross-Site Request Forgery (CSRF) vulnerability in ProteusThemes Custom Sidebars by ProteusThemes custom-sidebars-by-proteusthemes allows Cross Site Request Forgery.This issue affects Custom Sidebars by ProteusThemes: from n/a through <= 1.0.3.

PUBLISHED
Vendor
ProteusThemes
Product
Custom Sidebars by ProteusThemes
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62731

SOPlanning is vulnerable to Stored XSS in /feries endpoint. Malicious attacker with access to public holidays feature is able to inject arbitrary HTML and JS into website, which will be rendered/executed when opening multiple pages. By default only administrators and users with special privileges are able to access this endpoint. This issue was fixed in version 1.55.

PUBLISHED
Vendor
SOPlanning
Product
SOPlanning
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62730

SOPlanning is vulnerable to Privilege Escalation in user management tab. Users with user_manage_team role are allowed to modify permissions of users. However, they are able to assign administrative permissions to any user including themselves. This allow a malicious authenticated attacker with this role to escalate to admin privileges. This issue affects both Bulk Update functionality and regular edition of user's right and privileges. This issue was fixed in version 1.55.

PUBLISHED
Vendor
SOPlanning
Product
SOPlanning
Provider severity
HIGH
Conflicts
0

CVE-2025-62729

SOPlanning is vulnerable to Stored XSS in /status endpoint. Malicious attacker with an account can inject arbitrary HTML and JS into website, which will be rendered/executed when opening multiple pages. This issue was fixed in version 1.55.

PUBLISHED
Vendor
SOPlanning
Product
SOPlanning
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62728

SQL injection vulnerability in Hive Metastore Server (HMS) when processing delete column statistics requests via the Thrift APIs. The vulnerability is only exploitable by trusted/authorized users/applications that are allowed to call directly the Thrift APIs. In most real-world deployments, HMS is accessible to only a handful of applications (e.g., Hiveserver2) thus the vulnerability is not exploitable. Moreover, the vulnerable code cannot be reached when metastore.try.direct.sql property is set

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Hive
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62727

Starlette is a lightweight ASGI framework/toolkit. Starting in version 0.39.0 and prior to version 0.49.1 , an unauthenticated attacker can send a crafted HTTP Range header that triggers quadratic-time processing in Starlette's FileResponse Range parsing/merging logic. This enables CPU exhaustion per request, causing denial‑of‑service for endpoints serving files (e.g., StaticFiles or any use of FileResponse). This vulnerability is fixed in 0.49.1.

PUBLISHED
Vendor
Kludex
Product
starlette
Provider severity
HIGH
Conflicts
0

CVE-2025-62726

n8n is an open source workflow automation platform. Prior to 1.113.0, a remote code execution vulnerability exists in the Git Node component available in both Cloud and Self-Hosted versions of n8n. When a malicious actor clones a remote repository containing a pre-commit hook, the subsequent use of the Commit operation in the Git Node can inadvertently trigger the hook’s execution. This allows attackers to execute arbitrary code within the n8n environment, potentially compromising the system and

PUBLISHED
Vendor
n8n-io
Product
n8n
Provider severity
HIGH
Conflicts
0

CVE-2025-62725

Docker Compose trusts the path information embedded in remote OCI compose artifacts. When a layer includes the annotations com.docker.compose.extends or com.docker.compose.envfile, Compose joins the attacker‑supplied value from com.docker.compose.file/com.docker.compose.envfile with its local cache directory and writes the file there. This affects any platform or workflow that resolves remote OCI compose artifacts, Docker Desktop, standalone Compose binaries on Linux, CI/CD runners, cloud dev en

PUBLISHED
Vendor
docker
Product
compose
Provider severity
HIGH
Conflicts
0

CVE-2025-62724

Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, users can craft a "Time of Check to Time of Use" (TOCTOU) attack when downloading zip files to access files outside of the OOD_ALLOWLIST. This vulnerability impacts sites that use the file browser allowlists in all current versions of OOD. However, files accessed are still protected by the UNIX permissions. Open OnDemand versions 4.0.8 and 3.1.16 have been patched for this vulnerability.

PUBLISHED
Vendor
OSC
Product
ondemand
Provider severity
MEDIUM
Conflicts
1

CVE-2025-62723

FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.23.2, any authenticated user can create sessions and have them collect QoS messages. When not sent to a client, these are then not released upon (eventual) session expiration. Version 1.23.2 fixes the issue.

PUBLISHED
Vendor
halfgaar
Product
FlashMQ
Provider severity
MEDIUM
Conflicts
0

CVE-2025-62722

LinkAce is a self-hosted archive to collect website links. In versions 2.3.1 and below, the social media sharing functionality contains a Stored Cross-Site Scripting (XSS) vulnerability that allows any authenticated user to inject arbitrary JavaScript by creating a link with malicious HTML in the title field. When a user views the link details page and the shareable links are rendered, the malicious JavaScript executes in their browser. This vulnerability affects multiple sharing services and ca

PUBLISHED
Vendor
Kovah
Product
LinkAce
Provider severity
HIGH
Conflicts
0