5.3
CVE-2025-15237 - Quanta Computer๏ฝQOCA aim AI Medical Cloud Platform - Path Traversal
QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Path Traversal vulnerability, allowing authenticated remote attackers to read folder names under the specified path by exploiting an Absolute Path Traversal vulnerability.
5.3
CVE-2025-15236 - Quanta Computer๏ฝQOCA aim AI Medical Cloud Platform - Path Traversal
QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Path Traversal vulnerability, allowing authenticated remote attackers to read folder names under the specified path by exploiting an Absolute Path Traversal vulnerability.
5.1
CVE-2026-0580 - SourceCodester API Key Manager App Import Key cross site scripting
A vulnerability was found in SourceCodester API Key Manager App 1.0. Affected by this vulnerability is an unknown functionality of the component Import Key Handler. Performing a manipulation results in cross site scripting. The attack can be initiated remotely.
7.1
CVE-2025-15235 - Quanta Computer๏ฝQOCA aim AI Medical Cloud Platform - Missing Authorization
QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Missing Authorization vulnerability, allowing authenticated remote attackers to modify specific network packet parameters, enabling certain system functions to access other users' files.
8.7
CVE-2025-15462 - UTT ่ฟๅ 520W ConfigAdvideo strcpy buffer overflow
A vulnerability has been found in UTT ่ฟๅ 520W 1.7.7-180627. This issue affects the function strcpy of the file /goform/ConfigAdvideo. The manipulation of the argument timestart leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public โฆ
8.7
CVE-2025-15461 - UTT ่ฟๅ 520W formTaskEdit strcpy buffer overflow
A flaw has been found in UTT ่ฟๅ 520W 1.7.7-180627. This vulnerability affects the function strcpy of the file /goform/formTaskEdit. Executing a manipulation of the argument selDateType can lead to buffer overflow. The attack can be executed remotely. The exploit has been published and may be used. โฆ
8.7
CVE-2025-15460 - UTT ่ฟๅ 520W formPptpClientConfig strcpy buffer overflow
A vulnerability was detected in UTT ่ฟๅ 520W 1.7.7-180627. This affects the function strcpy of the file /goform/formPptpClientConfig. Performing a manipulation of the argument EncryptionMode results in buffer overflow. Remote exploitation of the attack is possible. The exploit is now public and may โฆ
3.5
CVE-2025-9543 - FlexTable Google Sheets Connector < 3.19.2 - Admin+ Stored XSS
The FlexTable WordPress plugin before 3.19.2 does not sanitise and escape the imported links from Google Sheet cells, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisiteโฆ
8.6
CVE-2025-14124 - Team < 5.0.11 - Unauthenticated SQLi
The Team WordPress plugin before 5.0.11 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
8.7
CVE-2025-15459 - UTT ่ฟๅ 520W formUser strcpy buffer overflow
A security vulnerability has been detected in UTT ่ฟๅ 520W 1.7.7-180627. Affected by this issue is the function strcpy of the file /goform/formUser. Such manipulation of the argument passwd1 leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed publicly and maโฆ