Latest CVE Feed
-
6.8
MEDIUMCVE-2025-8641
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication is not required to exploit this vulner... Read more
- Published: Aug. 06, 2025
- Modified: Aug. 07, 2025
-
6.8
MEDIUMCVE-2025-8640
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication is not required to exploit this vulner... Read more
- Published: Aug. 06, 2025
- Modified: Aug. 07, 2025
-
6.8
MEDIUMCVE-2025-8639
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected Kenwood DMX958XR devices. Authentication is not required to exploit this vulnerability. The spe... Read more
- Published: Aug. 06, 2025
- Modified: Aug. 07, 2025
-
6.8
MEDIUMCVE-2025-8638
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication is not required to exploit this vulner... Read more
- Published: Aug. 06, 2025
- Modified: Aug. 07, 2025
-
6.8
MEDIUMCVE-2025-8637
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication is not required to exploit this vulner... Read more
- Published: Aug. 06, 2025
- Modified: Aug. 07, 2025
-
6.8
MEDIUMCVE-2025-8636
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication is not required to exploit this vulner... Read more
- Published: Aug. 06, 2025
- Modified: Aug. 07, 2025
-
6.8
MEDIUMCVE-2025-8635
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication is not required to exploit this vulner... Read more
- Published: Aug. 06, 2025
- Modified: Aug. 07, 2025
-
6.8
MEDIUMCVE-2025-8634
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication is not required to exploit this vulner... Read more
- Published: Aug. 06, 2025
- Modified: Aug. 07, 2025
-
6.8
MEDIUMCVE-2025-8633
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication is not required to exploit this vulner... Read more
- Published: Aug. 06, 2025
- Modified: Aug. 07, 2025
-
6.8
MEDIUMCVE-2025-8632
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication is not required to exploit this vulner... Read more
- Published: Aug. 06, 2025
- Modified: Aug. 07, 2025
-
6.8
MEDIUMCVE-2025-8631
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication is not required to exploit this vulner... Read more
- Published: Aug. 06, 2025
- Modified: Aug. 07, 2025
-
6.8
MEDIUMCVE-2025-8630
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication is not required to exploit this vulner... Read more
- Published: Aug. 06, 2025
- Modified: Aug. 07, 2025
-
6.8
MEDIUMCVE-2025-8629
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication is not required to exploit this vulner... Read more
- Published: Aug. 06, 2025
- Modified: Aug. 07, 2025
-
6.8
MEDIUMCVE-2025-8628
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication is not required to exploit this vulner... Read more
- Published: Aug. 06, 2025
- Modified: Aug. 07, 2025
-
6.4
MEDIUMCVE-2025-7502
The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several shortcodes in all versions up to, and including, 8.5 due to insufficient input sanitization and output escaping on user supplied attribut... Read more
Affected Products : page_builder- Published: Aug. 06, 2025
- Modified: Aug. 06, 2025
-
7.5
HIGHCVE-2025-7036
The CleverReach® WP plugin for WordPress is vulnerable to time-based SQL Injection via the ‘title’ parameter in all versions up to, and including, 1.5.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the... Read more
Affected Products :- Published: Aug. 06, 2025
- Modified: Aug. 06, 2025
-
6.5
MEDIUMCVE-2025-6986
The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to SQL Injection via the 'search' parameter in all versions up to, and including, 6.4.8 due to insufficient escaping on the user supplied parameter and lack o... Read more
Affected Products : filebird- Published: Aug. 06, 2025
- Modified: Aug. 06, 2025
-
6.4
MEDIUMCVE-2025-6690
The WP Tournament Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘field’ parameter in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping. This makes it possible for a... Read more
Affected Products :- Published: Aug. 06, 2025
- Modified: Aug. 06, 2025
-
6.4
MEDIUMCVE-2025-6259
The esri-map-view plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's esri-map-view shortcode in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping on user supplied attributes... Read more
Affected Products :- Published: Aug. 06, 2025
- Modified: Aug. 06, 2025
-
6.4
MEDIUMCVE-2025-6256
The Flex Guten plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘thumbnailHoverEffect’ parameter in all versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping. This makes it possible for au... Read more
Affected Products :- Published: Aug. 06, 2025
- Modified: Aug. 06, 2025