Latest CVE Feed
-
4.8
MEDIUMCVE-2025-50582
StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Course module.... Read more
Affected Products :- Published: Jul. 18, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-27209
The V8 release used in Node.js v24.0.0 has changed how string hashes are computed using rapidhash. This implementation re-introduces the HashDoS vulnerability as an attacker who can control the strings to be hashed can generate many hash collisions - an a... Read more
Affected Products : node.js- Published: Jul. 18, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Denial of Service
-
6.4
MEDIUMCVE-2025-7653
The EPay.bg Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'epay' shortcode in all versions up to, and including, 0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This... Read more
Affected Products :- Published: Jul. 19, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-7655
The Live Stream Badger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'livestream' shortcode in all versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping on user supplied attrib... Read more
Affected Products :- Published: Jul. 19, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cross-Site Scripting
-
9.4
CRITICALCVE-2025-29757
An incorrect authorisation check in the the 'plant transfer' function of the Growatt cloud service allowed a malicous attacker with a valid account to transfer any plant into his/her account.... Read more
Affected Products :- Published: Jul. 19, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2025-6720
The Vchasno Kasa plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the clear_all_log() function in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to clear l... Read more
Affected Products :- Published: Jul. 19, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2012-10019
The Front End Editor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload.php file in versions before 2.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the aff... Read more
Affected Products :- Published: Jul. 19, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2015-10134
The Simple Backup plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.7.10. via the download_backup_file function. This is due to a lack of capability checks and file type validation. This makes it possible fo... Read more
Affected Products :- Published: Jul. 19, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2015-10135
The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajaxUpload function in versions before 1.3.9.6. This makes it possible for unauthenticated attackers to upload arbitrary file... Read more
Affected Products :- Published: Jul. 19, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2015-10136
The GI-Media Library plugin for WordPress is vulnerable to Directory Traversal in versions before 3.0 via the 'fileid' parameter. This allows unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive info... Read more
Affected Products :- Published: Jul. 19, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2016-15043
The WP Mobile Detector plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in resize.php file in versions up to, and including, 3.5. This makes it possible for unauthenticated attackers to upload arbitrary file... Read more
Affected Products :- Published: Jul. 19, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2015-10139
The WPLMS theme for WordPress is vulnerable to Privilege Escalation in versions 1.5.2 to 1.8.4.1 via the 'wp_ajax_import_data' AJAX action. This makes it possible for authenticated attackers to change otherwise restricted settings and potentially create a... Read more
Affected Products :- Published: Jul. 19, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-7836
A vulnerability has been found in D-Link DIR-816L up to 2.06B01 and classified as critical. Affected by this vulnerability is the function lxmldbc_system of the file /htdocs/cgibin of the component Environment Variable Handler. The manipulation leads to c... Read more
Affected Products :- Published: Jul. 19, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Injection
-
3.1
LOWCVE-2025-7882
A vulnerability was found in Mercusys MW301R 1.0.2 Build 190726 Rel.59423n. It has been rated as problematic. This issue affects some unknown processing of the component Login. The manipulation leads to improper restriction of excessive authentication att... Read more
Affected Products :- Published: Jul. 20, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authentication
-
8.5
HIGHCVE-2025-7883
A vulnerability classified as critical has been found in Eluktronics Control Center 5.23.51.41. Affected is an unknown function of the file \AiStoneService\MyControlCenter\Command of the component Powershell Script Handler. The manipulation leads to comma... Read more
Affected Products :- Published: Jul. 20, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Injection
-
4.8
MEDIUMCVE-2025-7884
A vulnerability classified as problematic was found in Eluktronics Control Center 5.23.51.41. Affected by this vulnerability is an unknown functionality of the component REG File Handler. The manipulation leads to insufficient verification of data authent... Read more
Affected Products :- Published: Jul. 20, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2025-7886
A vulnerability, which was classified as critical, was found in pmTicket Project-Management-Software up to 2ef379da2075f4761a2c9029cf91d073474e7486. This affects the function getUserLanguage of the file classes/class.database.php. The manipulation of the ... Read more
Affected Products :- Published: Jul. 20, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2025-7887
A vulnerability has been found in Zavy86 WikiDocs up to 1.0.78 and classified as problematic. This vulnerability affects unknown code of the file template.inc.php. The manipulation of the argument path leads to cross site scripting. The attack can be init... Read more
Affected Products :- Published: Jul. 20, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2025-7890
A vulnerability was found in Dunamu StockPlus App up to 7.62.10 on Android. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.dunamu.stockplus. The manipula... Read more
Affected Products :- Published: Jul. 20, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Misconfiguration
-
5.3
MEDIUMCVE-2025-7891
A vulnerability was found in InstantBits Web Video Cast App up to 5.12.4 on Android. It has been rated as problematic. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.instantbits.cast.webvideo. The... Read more
Affected Products :- Published: Jul. 20, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Misconfiguration