Latest CVE Feed
-
9.8
CRITICALCVE-2025-8185
A vulnerability was found in 1000 Projects ABC Courier Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /getbyid.php. The manipulation of the argument ID leads to sql injection. It is possible to launc... Read more
Affected Products : abc_courier_management_system- Published: Jul. 26, 2025
- Modified: Aug. 07, 2025
-
9.8
CRITICALCVE-2025-8184
A vulnerability was found in D-Link DIR-513 up to 1.10 and classified as critical. This issue affects the function formSetWanL2TPcallback of the file /goform/formSetWanL2TPtriggers of the component HTTP POST Request Handler. The manipulation leads to stac... Read more
- Published: Jul. 26, 2025
- Modified: Jul. 31, 2025
-
7.4
HIGHCVE-2025-8182
A vulnerability has been found in Tenda AC18 15.03.05.19 and classified as problematic. This vulnerability affects unknown code of the file /etc_ro/smb.conf of the component Samba. The manipulation leads to weak password requirements. The attack can be in... Read more
- Published: Jul. 26, 2025
- Modified: Aug. 01, 2025
-
7.5
HIGHCVE-2025-6991
The kallyas theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.21.0 via the 'TH_LatestPosts4` widget. This makes it possible for authenticated attackers, with Contributor-level access and above, to include an... Read more
Affected Products :- Published: Jul. 26, 2025
- Modified: Jul. 29, 2025
-
8.1
HIGHCVE-2025-6989
The Kallyas theme for WordPress is vulnerable to arbitrary folder deletion due to insufficient file path validation in the delete_font() function in all versions up to, and including, 4.21.0. This makes it possible for authenticated attackers, with Contri... Read more
Affected Products :- Published: Jul. 26, 2025
- Modified: Jul. 29, 2025
-
6.4
MEDIUMCVE-2025-5529
The Educenter theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Circle Counter Block in all versions up to, and including, 1.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated at... Read more
Affected Products :- Published: Jul. 26, 2025
- Modified: Jul. 29, 2025
-
8.6
HIGHCVE-2025-8181
A vulnerability, which was classified as critical, was found in TOTOLINK N600R and X2000R 1.0.0.1. This affects an unknown part of the file vsftpd.conf of the component FTP Service. The manipulation leads to least privilege violation. It is possible to in... Read more
- Published: Jul. 26, 2025
- Modified: Jul. 29, 2025
-
9.0
HIGHCVE-2025-8180
A vulnerability, which was classified as critical, has been found in Tenda CH22 1.0.0.1. Affected by this issue is the function formdeleteUserName of the file /goform/deleteUserName. The manipulation of the argument old_account leads to buffer overflow. T... Read more
- Published: Jul. 26, 2025
- Modified: Aug. 05, 2025
-
5.3
MEDIUMCVE-2025-8097
The WoodMart theme for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 8.2.6. This is due to insufficient validation of the qty parameter in the woodmart_update_cart_item function. This makes it possible for unau... Read more
Affected Products : woodmart- Published: Jul. 26, 2025
- Modified: Jul. 29, 2025
-
6.4
MEDIUMCVE-2025-7501
The Wonder Slider Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image title and description DOM in all versions up to, and including, 14.4 due to insufficient input sanitization and output escaping. This makes it possible for ... Read more
Affected Products : wonder_slider_lite- Published: Jul. 26, 2025
- Modified: Jul. 29, 2025
-
6.4
MEDIUMCVE-2025-6987
The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2025.5 due to insufficient input sanitization and output escaping on user supplied att... Read more
Affected Products : advanced_iframe- Published: Jul. 26, 2025
- Modified: Jul. 29, 2025
-
7.5
HIGHCVE-2025-8198
The MinimogWP – The High Converting eCommerce WordPress Theme theme for WordPress is vulnerable to price manipulation in all versions up to, and including, 3.9.0. This is due to an insufficient check on quantity values when changing quantities in the cart... Read more
Affected Products :- Published: Jul. 26, 2025
- Modified: Jul. 29, 2025
-
9.8
CRITICALCVE-2025-8179
A vulnerability classified as critical was found in PHPGurukul Local Services Search Engine Management System 2.1. Affected by this vulnerability is an unknown functionality of the file /admin/changeimage.php. The manipulation of the argument editid leads... Read more
Affected Products : local_services_search_engine_management_system- Published: Jul. 26, 2025
- Modified: Jul. 30, 2025
-
9.0
HIGHCVE-2025-8178
A vulnerability classified as critical has been found in Tenda AC10 16.03.10.13. Affected is an unknown function of the file /goform/RequestsProcessLaid. The manipulation of the argument device1D leads to heap-based buffer overflow. It is possible to laun... Read more
- Published: Jul. 26, 2025
- Modified: Aug. 01, 2025
-
9.8
CRITICALCVE-2025-6895
The Melapress Login Security plugin for WordPress is vulnerable to Authentication Bypass due to missing authorization within the get_valid_user_based_on_token() function in versions 2.1.0 to 2.1.1. This makes it possible for unauthenticated attackers who ... Read more
Affected Products : melapress_login_security- Published: Jul. 26, 2025
- Modified: Jul. 29, 2025
-
5.3
MEDIUMCVE-2025-8177
A vulnerability was found in LibTIFF up to 4.7.0. It has been rated as critical. This issue affects the function setrow of the file tools/thumbnail.c. The manipulation leads to buffer overflow. An attack has to be approached locally. The patch is named e8... Read more
Affected Products : libtiff- Published: Jul. 26, 2025
- Modified: Jul. 29, 2025
-
5.3
MEDIUMCVE-2025-8176
A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as critical. This vulnerability affects the function get_histogram of the file tools/tiffmedian.c. The manipulation leads to use after free. The attack needs to be approached locally. ... Read more
Affected Products : libtiff- Published: Jul. 26, 2025
- Modified: Jul. 29, 2025
-
4.3
MEDIUMCVE-2025-8103
The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.7. This is due to missing nonce validation in the handle_feedback_submission() function. This makes it possible for u... Read more
Affected Products : wpematico_rss_feed_fetcher- Published: Jul. 26, 2025
- Modified: Jul. 29, 2025
-
9.1
CRITICALCVE-2025-54416
tj-actions/branch-names is a Github actions repository that contains workflows to retrieve branch or tag names with support for all events. In versions 8.2.1 and below, a critical vulnerability has been identified in the tj-actions/branch-names' GitHub Ac... Read more
Affected Products : branch-names- Published: Jul. 26, 2025
- Modified: Jul. 29, 2025
-
9.1
CRITICALCVE-2025-54415
dag-factory is a library for Apache Airflow® to construct DAGs declaratively via configuration files. In versions 0.23.0a8 and below, a high-severity vulnerability has been identified in the cicd.yml workflow within the astronomer/dag-factory GitHub repos... Read more
Affected Products :- Published: Jul. 26, 2025
- Modified: Jul. 29, 2025