Latest CVE Feed
-
7.5
HIGHCVE-2025-9008
A vulnerability was identified in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown processing of the file /admin/sms_setting.php. The manipulation of the argument uname leads to sql injection. The attack may be in... Read more
Affected Products :- Published: Aug. 15, 2025
- Modified: Aug. 15, 2025
-
9.0
HIGHCVE-2025-9007
A vulnerability has been found in Tenda CH22 1.0.0.1. Affected by this issue is the function formeditFileName of the file /goform/editFileName. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed ... Read more
Affected Products :- Published: Aug. 15, 2025
- Modified: Aug. 15, 2025
-
9.0
HIGHCVE-2025-9006
A vulnerability was identified in Tenda CH22 1.0.0.1. Affected by this vulnerability is the function formdelFileName of the file /goform/delFileName. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit has been disc... Read more
Affected Products :- Published: Aug. 15, 2025
- Modified: Aug. 15, 2025
-
6.3
MEDIUMCVE-2025-9005
A vulnerability was determined in mtons mblog up to 3.5.0. Affected is an unknown function of the file /register. The manipulation leads to information exposure through error message. It is possible to launch the attack remotely. The complexity of an atta... Read more
Affected Products :- Published: Aug. 15, 2025
- Modified: Aug. 15, 2025
-
6.3
MEDIUMCVE-2025-9004
A vulnerability was found in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /settings/password. The manipulation leads to improper restriction of excessive authentication attempts. The attack may be initiated remotely. The... Read more
Affected Products :- Published: Aug. 15, 2025
- Modified: Aug. 15, 2025
-
5.1
MEDIUMCVE-2025-9003
A vulnerability has been found in D-Link DIR-818LW 1.04. This vulnerability affects unknown code of the file /bsc_lan.php of the component DHCP Reserved Address Handler. The manipulation of the argument Name leads to cross site scripting. The attack can b... Read more
Affected Products :- Published: Aug. 15, 2025
- Modified: Aug. 15, 2025
-
7.5
HIGHCVE-2025-9002
A vulnerability was identified in Surbowl dormitory-management-php 1.0. This affects an unknown part of the file login.php. The manipulation of the argument Account leads to sql injection. It is possible to initiate the attack remotely. The exploit has be... Read more
Affected Products :- Published: Aug. 15, 2025
- Modified: Aug. 15, 2025
-
5.5
MEDIUMCVE-2025-9001
A vulnerability was determined in LemonOS up to nightly-2024-07-12 on LemonOS. Affected by this issue is the function HTTPGet of the file /Applications/Steal/main.cpp of the component HTTP Client. The manipulation of the argument chunkSize leads to stack-... Read more
Affected Products :- Published: Aug. 15, 2025
- Modified: Aug. 15, 2025
-
6.4
MEDIUMCVE-2025-8867
The Graphina - Elementor Charts and Graphs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple chart widget parameters in version 3.1.3 and below. This is due to insufficient input sanitization and output escaping on user suppli... Read more
Affected Products :- Published: Aug. 15, 2025
- Modified: Aug. 15, 2025
-
4.3
MEDIUMCVE-2025-8680
The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Server-Side Request Forgery in version less than, or equal to, 2.0.0 via the fs_api_request function. This makes it possible for authenticated attackers, with subscriber-lev... Read more
Affected Products :- Published: Aug. 15, 2025
- Modified: Aug. 15, 2025
-
4.3
MEDIUMCVE-2025-8676
The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Sensitive Information Exposure in versions less than, or equal to, 2.0.0 via the get_active_plugins function. This makes it possible for authenticated attackers, with subscr... Read more
Affected Products :- Published: Aug. 15, 2025
- Modified: Aug. 15, 2025
-
8.1
HIGHCVE-2025-8342
The WooCommerce OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass due to insufficient empty value checking in the lwp_ajax_register function in all versions up to, and including, 1.8.47. This makes i... Read more
Affected Products :- Published: Aug. 15, 2025
- Modified: Aug. 15, 2025
-
7.5
HIGHCVE-2025-6025
The Order Tip for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Improper Input Validation in all versions up to, and including, 1.5.4. This is due to lack of server-side validation on the `data-tip` attribute, which makes it possible f... Read more
Affected Products :- Published: Aug. 15, 2025
- Modified: Aug. 15, 2025
-
7.3
HIGHCVE-2025-9000
A vulnerability was found in Mechrevo Control Center GX V2 5.56.51.48. Affected by this vulnerability is an unknown functionality of the component reg File Handler. The manipulation leads to uncontrolled search path. It is possible to launch the attack on... Read more
Affected Products :- Published: Aug. 15, 2025
- Modified: Aug. 15, 2025
-
7.5
HIGHCVE-2025-8993
A vulnerability was found in itsourcecode Online Tour and Travel Management System 1.0. This affects an unknown part of the file /admin/expense_report.php. The manipulation of the argument from_date leads to sql injection. It is possible to initiate the a... Read more
Affected Products :- Published: Aug. 15, 2025
- Modified: Aug. 15, 2025
-
5.3
MEDIUMCVE-2025-8992
A vulnerability has been found in mtons mblog up to 3.5.0. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and ma... Read more
Affected Products :- Published: Aug. 15, 2025
- Modified: Aug. 15, 2025
-
5.3
MEDIUMCVE-2025-8991
A vulnerability was identified in linlinjava litemall up to 1.8.0. Affected by this vulnerability is an unknown functionality of the file /admin/config/express of the component Business Logic Handler. The manipulation of the argument litemall_express_frei... Read more
Affected Products :- Published: Aug. 15, 2025
- Modified: Aug. 15, 2025
-
7.5
HIGHCVE-2025-8990
A vulnerability was determined in code-projects Online Medicine Guide 1.0. Affected is an unknown function of the file /browsemdcn.php. The manipulation of the argument Search leads to sql injection. It is possible to launch the attack remotely. The explo... Read more
Affected Products :- Published: Aug. 15, 2025
- Modified: Aug. 15, 2025
-
7.5
HIGHCVE-2025-8989
A vulnerability was found in SourceCodester COVID 19 Testing Management System 1.0. This issue affects some unknown processing of the file /edit-phlebotomist.php. The manipulation of the argument mobilenumber leads to sql injection. The attack may be init... Read more
Affected Products :- Published: Aug. 15, 2025
- Modified: Aug. 15, 2025
-
9.4
CRITICALCVE-2025-8876
Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1.... Read more
Affected Products :- Actively Exploited
- Published: Aug. 14, 2025
- Modified: Aug. 15, 2025