Latest CVE Feed
-
6.8
MEDIUMCVE-2025-8637
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication is not required to exploit this vulner... Read more
- Published: Aug. 06, 2025
- Modified: Aug. 07, 2025
-
6.8
MEDIUMCVE-2025-8636
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication is not required to exploit this vulner... Read more
- Published: Aug. 06, 2025
- Modified: Aug. 07, 2025
-
6.8
MEDIUMCVE-2025-8635
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication is not required to exploit this vulner... Read more
- Published: Aug. 06, 2025
- Modified: Aug. 07, 2025
-
6.8
MEDIUMCVE-2025-8634
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication is not required to exploit this vulner... Read more
- Published: Aug. 06, 2025
- Modified: Aug. 07, 2025
-
6.8
MEDIUMCVE-2025-8633
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication is not required to exploit this vulner... Read more
- Published: Aug. 06, 2025
- Modified: Aug. 07, 2025
-
6.8
MEDIUMCVE-2025-8632
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication is not required to exploit this vulner... Read more
- Published: Aug. 06, 2025
- Modified: Aug. 07, 2025
-
6.8
MEDIUMCVE-2025-8631
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication is not required to exploit this vulner... Read more
- Published: Aug. 06, 2025
- Modified: Aug. 07, 2025
-
6.8
MEDIUMCVE-2025-8630
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication is not required to exploit this vulner... Read more
- Published: Aug. 06, 2025
- Modified: Aug. 07, 2025
-
6.8
MEDIUMCVE-2025-8629
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication is not required to exploit this vulner... Read more
- Published: Aug. 06, 2025
- Modified: Aug. 07, 2025
-
6.8
MEDIUMCVE-2025-8628
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication is not required to exploit this vulner... Read more
- Published: Aug. 06, 2025
- Modified: Aug. 07, 2025
-
6.4
MEDIUMCVE-2025-7502
The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several shortcodes in all versions up to, and including, 8.5 due to insufficient input sanitization and output escaping on user supplied attribut... Read more
Affected Products : page_builder- Published: Aug. 06, 2025
- Modified: Aug. 06, 2025
-
7.5
HIGHCVE-2025-7036
The CleverReach® WP plugin for WordPress is vulnerable to time-based SQL Injection via the ‘title’ parameter in all versions up to, and including, 1.5.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the... Read more
Affected Products :- Published: Aug. 06, 2025
- Modified: Aug. 06, 2025
-
6.5
MEDIUMCVE-2025-6986
The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to SQL Injection via the 'search' parameter in all versions up to, and including, 6.4.8 due to insufficient escaping on the user supplied parameter and lack o... Read more
Affected Products : filebird- Published: Aug. 06, 2025
- Modified: Aug. 06, 2025
-
6.4
MEDIUMCVE-2025-6690
The WP Tournament Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘field’ parameter in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping. This makes it possible for a... Read more
Affected Products :- Published: Aug. 06, 2025
- Modified: Aug. 06, 2025
-
6.4
MEDIUMCVE-2025-6259
The esri-map-view plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's esri-map-view shortcode in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping on user supplied attributes... Read more
Affected Products :- Published: Aug. 06, 2025
- Modified: Aug. 06, 2025
-
6.4
MEDIUMCVE-2025-6256
The Flex Guten plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘thumbnailHoverEffect’ parameter in all versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping. This makes it possible for au... Read more
Affected Products :- Published: Aug. 06, 2025
- Modified: Aug. 06, 2025
-
6.5
MEDIUMCVE-2025-54623
Out-of-bounds read vulnerability in the devicemanager module. Impact: Successful exploitation of this vulnerability may affect availability.... Read more
Affected Products : harmonyos- Published: Aug. 06, 2025
- Modified: Aug. 20, 2025
-
8.3
HIGHCVE-2025-54622
Binding authentication bypass vulnerability in the devicemanager module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
Affected Products : harmonyos- Published: Aug. 06, 2025
- Modified: Aug. 20, 2025
-
5.3
MEDIUMCVE-2025-54621
Iterator failure issue in the WantAgent module. Impact: Successful exploitation of this vulnerability may cause memory release failures.... Read more
Affected Products : harmonyos- Published: Aug. 06, 2025
- Modified: Aug. 06, 2025
-
5.5
MEDIUMCVE-2025-54620
Deserialization vulnerability of untrusted data in the ability module. Impact: Successful exploitation of this vulnerability may affect availability.... Read more
Affected Products : harmonyos- Published: Aug. 06, 2025
- Modified: Aug. 20, 2025