Latest CVE Feed
-
8.1
HIGHCVE-2025-48905
Wasm exception capture vulnerability in the arkweb v8 module Impact: Successful exploitation of this vulnerability may cause the failure to capture specific Wasm exception types.... Read more
Affected Products : harmonyos- Published: Jun. 06, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Denial of Service
-
6.2
MEDIUMCVE-2025-48904
Vulnerability that cards can call unauthorized APIs in the FRS process Impact: Successful exploitation of this vulnerability may affect availability.... Read more
Affected Products : harmonyos- Published: Jun. 06, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Authorization
-
7.8
HIGHCVE-2025-48903
Permission bypass vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect availability.... Read more
Affected Products : harmonyos- Published: Jun. 06, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Authorization
-
6.6
MEDIUMCVE-2025-48902
Vulnerability of uncontrolled system resource applications in the setting module Impact: Successful exploitation of this vulnerability may affect availability.... Read more
- Published: Jun. 06, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Denial of Service
-
5.4
MEDIUMCVE-2025-2935
The Anti-Spam: Spam Protection | Block Spam Users, Comments, Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2024.7. This is due to missing or incorrect nonce validation in the 'ss_option_maint.... Read more
Affected Products : stop_spammers- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.0
MEDIUMCVE-2024-58114
Resource allocation control failure vulnerability in the ArkUI framework Impact: Successful exploitation of this vulnerability may affect availability.... Read more
Affected Products : harmonyos- Published: Jun. 06, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Denial of Service
-
5.4
MEDIUMCVE-2025-5726
A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /script/academic/division-system of the component Division System Page. Th... Read more
- Published: Jun. 06, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-5725
A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /script/academic/grading-system of the component Grading System P... Read more
- Published: Jun. 06, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-5724
A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file /script/academic/subjects of the component Subjects Page. The manipulation of the argument... Read more
- Published: Jun. 06, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-1778
The Art Theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'arttheme_theme_option_restore' AJAX function in all versions up to, and including, 3.12.2.3. This makes it possible for authenticated attackers, wit... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Authorization
-
6.4
MEDIUMCVE-2025-1777
The BM Content Builder plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the 'ux_cb_page_options_save' function in all versions up to, and including, 3.16.2.1. This makes it possible for authenticated... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2023-2921
The Short URL WordPress plugin through 1.6.8 does not properly sanitise and escape a parameter before using it in SQL statement, leading to a SQL injection exploitable by users with relatively low privilege on the site, like subscribers.... Read more
Affected Products : short_url- Published: Jun. 06, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Injection
-
4.8
MEDIUMCVE-2025-5723
A vulnerability was found in SourceCodester Student Result Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /script/academic/classes of the component Classes Page. The manipulation of the argument... Read more
- Published: Jun. 06, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-5722
A vulnerability has been found in SourceCodester Student Result Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /script/academic/terms of the component Add Academic Term. The manipulation of the arg... Read more
- Published: Jun. 06, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Cross-Site Scripting
-
5.1
MEDIUMCVE-2025-36513
Cross-site request forgery vulnerability exists in surveillance cameras provided by i-PRO Co., Ltd.. If a user views a crafted page while logged in to the affected product, unintended operations may be performed.... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.3
MEDIUMCVE-2025-5733
The Modern Events Calendar Lite plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 7.21.9. This is due improper or insufficient validation of the id property when exporting calendars. This makes it possible fo... Read more
Affected Products : modern_events_calendar_lite- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Information Disclosure
-
5.4
MEDIUMCVE-2025-5721
A vulnerability, which was classified as problematic, was found in SourceCodester Student Result Management System 1.0. This affects an unknown part of the file /script/academic/core/update_profile of the component Profile Setting Page. The manipulation l... Read more
- Published: Jun. 06, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Cross-Site Scripting
-
5.1
MEDIUMCVE-2025-5719
The wallet has an authentication bypass vulnerability that allows access to specific pages.... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-5716
A vulnerability classified as critical has been found in SourceCodester Open Source Clinic Management System 1.0. Affected is an unknown function of the file /login.php. The manipulation of the argument email leads to sql injection. It is possible to laun... Read more
Affected Products : open_source_clinic_management_system- Published: Jun. 06, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Injection
-
3.8
LOWCVE-2025-5715
A vulnerability was found in Signal App 7.41.4 on Android. It has been declared as problematic. This vulnerability affects unknown code of the component Biometric Authentication Handler. The manipulation leads to missing critical step in authentication. I... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Authentication