8.7
CVE-2025-12232 - Tenda CH22 SafeClientFilter fromSafeClientFilter buffer overflow
A vulnerability was detected in Tenda CH22 1.0.0.1. Affected by this vulnerability is the function fromSafeClientFilter of the file /goform/SafeClientFilter. Performing a manipulation of the argument page results in buffer overflow. The attack can be initiated remotely. The exploit is now public anβ¦
4.8
CVE-2025-12231 - projectworlds Expense Management System Expense Categories create cross site scripting
A security vulnerability has been detected in projectworlds Expense Management System 1.0. Affected is an unknown function of the file /public/admin/expense_categories/create of the component Expense Categories Page. Such manipulation leads to cross site scripting. It is possible to launch the attaβ¦
4.8
CVE-2025-12230 - projectworlds Expense Management System Currency create cross site scripting
A weakness has been identified in projectworlds Expense Management System 1.0. This impacts an unknown function of the file /public/admin/currencies/create of the component Currency Page. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has β¦
5.4
CVE-2025-11154 - IDonate < 2.1.13 - Unauthenticated User Deletion
The IDonate WordPress plugin before 2.1.13 does not have authorisation and CSRF when deleting users via an action handler, allowing unauthenticated attackers to delete arbitrary users.
4.8
CVE-2025-12229 - projectworlds Expense Management System Roles Page create cross site scripting
A security flaw has been discovered in projectworlds Expense Management System 1.0. This affects an unknown function of the file /public/admin/roles/create of the component Roles Page. The manipulation results in cross site scripting. The attack may be performed from remote. The exploit has been reβ¦
4.8
CVE-2025-12228 - projectworlds Expense Management System Users Page create cross site scripting
A vulnerability was identified in projectworlds Expense Management System 1.0. The impacted element is an unknown function of the file /public/admin/users/create of the component Users Page. The manipulation leads to cross site scripting. The attack is possible to be carried out remotely. The exploβ¦
5.1
CVE-2025-12227 - projectworlds Gate Pass Management System add-pass.php cross site scripting
A vulnerability was determined in projectworlds Gate Pass Management System 1.0. The affected element is an unknown function of the file /add-pass.php. Executing a manipulation can lead to cross site scripting. The attack can be executed remotely. The exploit has been publicly disclosed and may be β¦
5.1
CVE-2025-12226 - SourceCodester Best House Rental Management System admin_class.php save_house sql injection
A vulnerability was found in SourceCodester Best House Rental Management System 1.0. Impacted is the function save_house of the file /admin_class.php. Performing manipulation of the argument house_no results in sql injection. Remote exploitation of the attack is possible. The exploit has been made β¦
8.7
CVE-2025-12225 - Tenda AC6 HTTP Request WifiGuestSet stack-based overflow
A vulnerability has been found in Tenda AC6 15.03.06.50. This issue affects some unknown processing of the file /goform/WifiGuestSet of the component HTTP Request Handler. Such manipulation of the argument shareSpeed leads to stack-based buffer overflow. The attack may be launched remotely. The expβ¦
5.1
CVE-2025-12224 - Iqbolshoh php-business-website contact.php cross site scripting
A flaw has been found in Iqbolshoh php-business-website up to 10677743a8dfc281f85291a27cf63a0bce043c24. This vulnerability affects unknown code of the file admin/contact.php. This manipulation of the argument twitter causes cross site scripting. The attack may be initiated remotely. The exploit hasβ¦