Latest CVE Feed
-
5.4
MEDIUMCVE-2025-49481
Improper Resource Shutdown or Release vulnerability in ASR180x 、ASR190x in router modules allows Resource Leak Exposure. This vulnerability is associated with program files router/phonebook/pbwork-queue.C. This issue affects Falcon_Linux、Kestrel、Lapwing_... Read more
Affected Products :- Published: Jul. 01, 2025
- Modified: Jul. 03, 2025
-
5.4
MEDIUMCVE-2025-49482
Improper Resource Shutdown or Release vulnerability in ASR180x 、ASR190x in tr069 modules allows Resource Leak Exposure. This vulnerability is associated with program files tr069/tr098.c. This issue affects Falcon_Linux、Kestrel、Lapwing_Linux: before v1536... Read more
Affected Products :- Published: Jul. 01, 2025
- Modified: Jul. 03, 2025
-
5.4
MEDIUMCVE-2025-49483
Improper Resource Shutdown or Release vulnerability in ASR180x 、ASR190x in tr069 modules allows Resource Leak Exposure. This vulnerability is associated with program files tr069/tr069_uci.c. This issue affects Falcon_Linux、Kestrel、Lapwing_Linux: before ... Read more
Affected Products :- Published: Jul. 01, 2025
- Modified: Jul. 03, 2025
-
5.4
MEDIUMCVE-2025-46259
Missing Authorization vulnerability in POSIMYTH Innovation The Plus Addons for Elementor Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Plus Addons for Elementor Pro: from n/a before 6.3.7.... Read more
Affected Products : the_plus_addons_for_elementor- Published: Jul. 01, 2025
- Modified: Jul. 03, 2025
-
5.4
MEDIUMCVE-2025-7112
A vulnerability was found in Portabilis i-Educar 2.9.0 and classified as problematic. This issue affects some unknown processing of the file /intranet/educar_funcao_det.php?cod_funcao=COD&ref_cod_instituicao=COD of the component Function Management Module... Read more
Affected Products : i-educar- Published: Jul. 07, 2025
- Modified: Aug. 13, 2025
-
5.4
MEDIUMCVE-2025-7133
A vulnerability classified as problematic has been found in CodeAstro Online Movie Ticket Booking System 1.0. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit h... Read more
Affected Products : online_movie_ticket_booking_system- Published: Jul. 07, 2025
- Modified: Jul. 09, 2025
-
5.4
MEDIUMCVE-2025-7057
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Quiz Extension allows Stored XSS.This issue affects Mediawiki - Quiz Extension: from 1.39.X before 1.39.13, from ... Read more
Affected Products :- Published: Jul. 07, 2025
- Modified: Jul. 08, 2025
-
5.4
MEDIUMCVE-2025-53491
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - FlaggedRevs Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - FlaggedRevs Extension: fro... Read more
Affected Products :- Published: Jul. 07, 2025
- Modified: Jul. 08, 2025
-
5.4
MEDIUMCVE-2025-53497
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - RelatedArticles Extension allows Stored XSS.This issue affects Mediawiki - RelatedArticles Extension: from 1.43.X... Read more
Affected Products :- Published: Jul. 07, 2025
- Modified: Jul. 08, 2025
-
5.4
MEDIUMCVE-2025-7139
A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /panel/edit-customer-detailed.php of the component Update Customer Details Page. The man... Read more
Affected Products : best_salon_management_system- Published: Jul. 07, 2025
- Modified: Jul. 09, 2025
-
5.4
MEDIUMCVE-2025-53478
The CheckUser extension’s Special:Investigate interface is vulnerable to reflected XSS due to improper escaping of certain internationalized system messages rendered on the “IPs and User agents” tab. This issue affects Mediawiki - CheckUser extension:... Read more
Affected Products :- Published: Jul. 07, 2025
- Modified: Jul. 08, 2025
-
5.4
MEDIUMCVE-2025-7140
A vulnerability classified as problematic has been found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the file /panel/edit-staff.php of the component Update Staff Page. The manipulation of the argument Staff Name ... Read more
Affected Products : best_salon_management_system- Published: Jul. 07, 2025
- Modified: Jul. 09, 2025
-
5.4
MEDIUMCVE-2025-7141
A vulnerability classified as problematic was found in SourceCodester Best Salon Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /panel/edit_plan.php of the component Update Staff Page. The manipulation leads ... Read more
Affected Products : best_salon_management_system- Published: Jul. 07, 2025
- Modified: Jul. 09, 2025
-
5.4
MEDIUMCVE-2025-53496
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - MediaSearch Extension allows Stored XSS.This issue affects Mediawiki - MediaSearch Extension: from 1.42.X before ... Read more
Affected Products :- Published: Jul. 07, 2025
- Modified: Jul. 08, 2025
-
5.4
MEDIUMCVE-2025-7142
A vulnerability, which was classified as problematic, has been found in SourceCodester Best Salon Management System 1.0. Affected by this issue is some unknown functionality of the file /panel/search-appointment.php. The manipulation leads to cross site s... Read more
Affected Products : best_salon_management_system- Published: Jul. 07, 2025
- Modified: Jul. 09, 2025
-
5.4
MEDIUMCVE-2025-7143
A vulnerability, which was classified as problematic, was found in SourceCodester Best Salon Management System 1.0. This affects an unknown part of the file /panel/edit-tax.php of the component Update Tax Page. The manipulation of the argument Tax Name le... Read more
Affected Products : best_salon_management_system- Published: Jul. 07, 2025
- Modified: Jul. 09, 2025
-
5.4
MEDIUMCVE-2025-7148
A vulnerability was found in CodeAstro Simple Hospital Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /patient.html of the component POST Parameter Handler. The manipulation leads to c... Read more
Affected Products : simple_hospital_management_system- Published: Jul. 07, 2025
- Modified: Jul. 09, 2025
-
5.4
MEDIUMCVE-2025-7153
A vulnerability classified as problematic was found in CodeAstro Simple Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /doctor.html of the component POST Parameter Handler. The manipulation of the ar... Read more
Affected Products : simple_hospital_management_system- Published: Jul. 08, 2025
- Modified: Jul. 08, 2025
-
5.4
MEDIUMCVE-2025-5570
The AI Engine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the mwai_chatbot shortcode 'id' parameter in all versions up to, and including, 2.8.4 due to insufficient input sanitization and output escaping. This makes it possible fo... Read more
- Published: Jul. 08, 2025
- Modified: Aug. 13, 2025
-
5.4
MEDIUMCVE-2025-4406
The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.4.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack... Read more
Affected Products : wpforo_forum- Published: Jul. 10, 2025
- Modified: Jul. 10, 2025