Latest CVE Feed
-
8.7
HIGHCVE-2025-41374
A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /... Read more
Affected Products :- Published: Aug. 01, 2025
- Modified: Aug. 04, 2025
-
8.7
HIGHCVE-2025-41373
A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /... Read more
Affected Products :- Published: Aug. 01, 2025
- Modified: Aug. 04, 2025
-
8.7
HIGHCVE-2025-41372
A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /... Read more
Affected Products :- Published: Aug. 01, 2025
- Modified: Aug. 04, 2025
-
9.3
CRITICALCVE-2025-41371
A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /... Read more
Affected Products :- Published: Aug. 01, 2025
- Modified: Aug. 04, 2025
-
9.3
CRITICALCVE-2025-41370
A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /... Read more
Affected Products :- Published: Aug. 01, 2025
- Modified: Aug. 04, 2025
-
6.4
MEDIUMCVE-2025-6228
The Sina Extension for Elementor (Header Builder, Footer Builter, Theme Builder, Slider, Gallery, Form, Modal, Data Table Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `Sina Posts`,... Read more
Affected Products :- Published: Aug. 01, 2025
- Modified: Aug. 04, 2025
-
6.4
MEDIUMCVE-2025-4684
The BlockSpare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites – Post Grids, Sliders, Carousels, Counters, Page Builder & Starter Site Imports, No Coding Needed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HT... Read more
Affected Products : blockspare- Published: Aug. 01, 2025
- Modified: Aug. 04, 2025
-
9.8
CRITICALCVE-2025-8443
A vulnerability was found in code-projects Online Medicine Guide 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument uname leads to sql injection. The attack may be ... Read more
Affected Products : online_medicine_guide- Published: Aug. 01, 2025
- Modified: Aug. 05, 2025
-
6.7
MEDIUMCVE-2025-6398
A null pointer dereference vulnerability exists in the IOMap64.sys driver of ASUS AI Suite 3. The vulnerability can be triggered by a specially crafted input, which may lead to a system crash (BSOD). Refer to the ' Security Update for for AI Suite 3 ' s... Read more
Affected Products :- Published: Aug. 01, 2025
- Modified: Aug. 04, 2025
-
9.8
CRITICALCVE-2025-8442
A vulnerability has been found in code-projects Online Medicine Guide 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /cussignup.php. The manipulation of the argument uname leads to sql injection. The... Read more
Affected Products : online_medicine_guide- Published: Aug. 01, 2025
- Modified: Aug. 05, 2025
-
9.8
CRITICALCVE-2025-8441
A vulnerability, which was classified as critical, was found in code-projects Online Medicine Guide 1.0. Affected is an unknown function of the file /pharsignup.php. The manipulation of the argument phuname leads to sql injection. It is possible to launch... Read more
Affected Products : online_medicine_guide- Published: Aug. 01, 2025
- Modified: Aug. 05, 2025
-
9.8
CRITICALCVE-2025-8439
A vulnerability, which was classified as critical, has been found in code-projects Wazifa System 1.0. This issue affects some unknown processing of the file /controllers/updatesettings.php. The manipulation of the argument Password leads to sql injection.... Read more
Affected Products : wazifa_system- Published: Aug. 01, 2025
- Modified: Aug. 05, 2025
-
9.8
CRITICALCVE-2025-8438
A vulnerability classified as critical was found in code-projects Wazifa System 1.0. This vulnerability affects unknown code of the file /controllers/postpublish.php. The manipulation of the argument post leads to sql injection. The attack can be initiate... Read more
Affected Products : wazifa_system- Published: Aug. 01, 2025
- Modified: Aug. 05, 2025
-
9.8
CRITICALCVE-2025-8437
A vulnerability classified as critical has been found in code-projects Kitchen Treasure 1.0. This affects an unknown part of the file /userregistration.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the atta... Read more
Affected Products : kitchen_treasure- Published: Aug. 01, 2025
- Modified: Aug. 05, 2025
-
6.4
MEDIUMCVE-2025-7646
The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom script parameter in all versions up to, and including, 6.3.10 even when ... Read more
Affected Products : the_plus_addons_for_elementor- Published: Aug. 01, 2025
- Modified: Aug. 04, 2025
-
9.8
CRITICALCVE-2025-8454
It was discovered that uscan, a tool to scan/watch upstream sources for new releases of software, included in devscripts (a collection of scripts to make the life of a Debian Package maintainer easier), skips OpenPGP verification if the upstream source is... Read more
Affected Products : devscripts- Published: Aug. 01, 2025
- Modified: Aug. 06, 2025
-
9.8
CRITICALCVE-2025-8436
A vulnerability was found in projectworlds Online Admission System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /viewdoc.php. The manipulation of the argument ID leads to sql injection. The attack ma... Read more
Affected Products : online_admission_system- Published: Aug. 01, 2025
- Modified: Aug. 06, 2025
-
5.8
MEDIUMCVE-2025-5921
The SureForms WordPress plugin before 1.7.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against both authenticated and unauthenticated users.... Read more
Affected Products : sureforms- Published: Aug. 01, 2025
- Modified: Aug. 06, 2025
-
5.3
MEDIUMCVE-2025-54939
LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak.... Read more
Affected Products : lsquic- Published: Aug. 01, 2025
- Modified: Aug. 20, 2025
-
5.1
MEDIUMCVE-2025-31716
In bootloader, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed.... Read more
Affected Products :- Published: Aug. 01, 2025
- Modified: Aug. 04, 2025