6.8

CVSS3.1

CVE-2025-12502 - Attention Bar <= 0.7.2.1 - Admin+ SQLi

The attention-bar WordPress plugin through 0.7.2.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing high privilege users such as administrator to perform SQL injection attacks

๐Ÿ“… Published: Nov. 20, 2025, 6 a.m. ๐Ÿ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.

5.3

CVSS3.1

CVE-2025-12778 - Ultimate Member Widgets for Elementor <= 2.3 - Missing Authorization to Unauthenticated Informationโ€ฆ

The Ultimate Member Widgets for Elementor โ€“ WordPress User Directory plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the handle_filter_users function in all versions up to, and including, 2.3. This makes it possible for unauthenticated attackerโ€ฆ

๐Ÿ“… Published: Nov. 20, 2025, 4:37 a.m. ๐Ÿ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.

6.9

CVSS4.0

CVE-2025-13451 - SourceCodester Online Shop Project action.php sql injection

A vulnerability was identified in SourceCodester Online Shop Project 1.0. The affected element is an unknown function of the file /action.php. Such manipulation of the argument Search leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might bโ€ฆ

๐Ÿ“… Published: Nov. 20, 2025, 3:02 a.m. ๐Ÿ”„ Last Modified: Nov. 21, 2025, 8:03 p.m.

5.1

CVSS4.0

CVE-2025-13450 - SourceCodester Online Shop Project register.php cross site scripting

A vulnerability was determined in SourceCodester Online Shop Project 1.0. Impacted is an unknown function of the file /shop/register.php. This manipulation of the argument f_name causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been publicly disclosed andโ€ฆ

๐Ÿ“… Published: Nov. 20, 2025, 3:02 a.m. ๐Ÿ”„ Last Modified: Nov. 21, 2025, 8:10 p.m.

6.9

CVSS4.0

CVE-2025-13449 - code-projects Online Shop Project login.php sql injection

A vulnerability was found in code-projects Online Shop Project 1.0. This issue affects some unknown processing of the file /login.php. The manipulation of the argument Password results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used.

๐Ÿ“… Published: Nov. 20, 2025, 2:32 a.m. ๐Ÿ”„ Last Modified: Nov. 21, 2025, 8:14 p.m.

8.7

CVSS4.0

CVE-2025-13446 - Tenda AC21 SetSysTimeCfg stack-based overflow

A vulnerability has been found in Tenda AC21 16.03.08.16. This vulnerability affects unknown code of the file /goform/SetSysTimeCfg. The manipulation of the argument timeZone/time leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosedโ€ฆ

๐Ÿ“… Published: Nov. 20, 2025, 2:32 a.m. ๐Ÿ”„ Last Modified: Nov. 21, 2025, 8:16 p.m.

8.7

CVSS4.0

CVE-2025-13445 - Tenda AC21 SetIpMacBind stack-based overflow

A flaw has been found in Tenda AC21 16.03.08.16. This affects an unknown part of the file /goform/SetIpMacBind. Executing manipulation of the argument list can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been published and may be used.

๐Ÿ“… Published: Nov. 20, 2025, 2:02 a.m. ๐Ÿ”„ Last Modified: Nov. 21, 2025, 8:19 p.m.

5.3

CVSS4.0

CVE-2025-13443 - macrozheng mall delete access control

A vulnerability was detected in macrozheng mall up to 1.0.3. Affected by this issue is the function delete of the file /member/readHistory/delete. Performing manipulation of the argument ids results in improper access controls. Remote exploitation of the attack is possible. The exploit is now publiโ€ฆ

๐Ÿ“… Published: Nov. 20, 2025, 2:02 a.m. ๐Ÿ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.

6.9

CVSS4.0

CVE-2025-13442 - UTT ่ฟ›ๅ– 750W formPdbUpConfig system command injection

A security vulnerability has been detected in UTT ่ฟ›ๅ– 750W up to 3.2.2-191225. Affected by this vulnerability is the function system of the file /goform/formPdbUpConfig. Such manipulation of the argument policyNames leads to command injection. The attack may be launched remotely. The exploit has beeโ€ฆ

๐Ÿ“… Published: Nov. 20, 2025, 1:32 a.m. ๐Ÿ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.

6.3

CVSS4.0

CVE-2025-13435 - Dreampie Resty HttpClient HttpClient.java request path traversal

A security vulnerability has been detected in Dreampie Resty up to 1.3.1.SNAPSHOT. This affects the function Request of the file /resty-httpclient/src/main/java/cn/dreampie/client/HttpClient.java of the component HttpClient Module. Such manipulation of the argument filename leads to path traversal.โ€ฆ

๐Ÿ“… Published: Nov. 20, 2025, 1:32 a.m. ๐Ÿ”„ Last Modified: Nov. 21, 2025, 3:13 p.m.
Total resulsts: 319191
Page 30 of 31,920
ยซ previous page ยป next page
Filters