8.6
CVE-2025-12235 - Tenda CH22 SetIpBind fromSetIpBind buffer overflow
A vulnerability was found in Tenda CH22 1.0.0.1. This vulnerability affects the function fromSetIpBind of the file /goform/SetIpBind. The manipulation of the argument page results in buffer overflow. The attack must originate from the local network. The exploit has been made public and could be useβ¦
8.7
CVE-2025-12234 - Tenda CH22 SafeMacFilter fromSafeMacFilter buffer overflow
A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function fromSafeMacFilter of the file /goform/SafeMacFilter. The manipulation of the argument page leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
8.7
CVE-2025-12233 - Tenda CH22 SafeUrlFilter fromSafeUrlFilter buffer overflow
A flaw has been found in Tenda CH22 1.0.0.1. Affected by this issue is the function fromSafeUrlFilter of the file /goform/SafeUrlFilter. Executing a manipulation of the argument page can lead to buffer overflow. The attack can be launched remotely. The exploit has been published and may be used.
8.7
CVE-2025-12232 - Tenda CH22 SafeClientFilter fromSafeClientFilter buffer overflow
A vulnerability was detected in Tenda CH22 1.0.0.1. Affected by this vulnerability is the function fromSafeClientFilter of the file /goform/SafeClientFilter. Performing a manipulation of the argument page results in buffer overflow. The attack can be initiated remotely. The exploit is now public anβ¦
4.8
CVE-2025-12231 - projectworlds Expense Management System Expense Categories create cross site scripting
A security vulnerability has been detected in projectworlds Expense Management System 1.0. Affected is an unknown function of the file /public/admin/expense_categories/create of the component Expense Categories Page. Such manipulation leads to cross site scripting. It is possible to launch the attaβ¦
4.8
CVE-2025-12230 - projectworlds Expense Management System Currency create cross site scripting
A weakness has been identified in projectworlds Expense Management System 1.0. This impacts an unknown function of the file /public/admin/currencies/create of the component Currency Page. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has β¦
5.4
CVE-2025-11154 - IDonate < 2.1.13 - Unauthenticated User Deletion
The IDonate WordPress plugin before 2.1.13 does not have authorisation and CSRF when deleting users via an action handler, allowing unauthenticated attackers to delete arbitrary users.
4.8
CVE-2025-12229 - projectworlds Expense Management System Roles Page create cross site scripting
A security flaw has been discovered in projectworlds Expense Management System 1.0. This affects an unknown function of the file /public/admin/roles/create of the component Roles Page. The manipulation results in cross site scripting. The attack may be performed from remote. The exploit has been reβ¦
4.8
CVE-2025-12228 - projectworlds Expense Management System Users Page create cross site scripting
A vulnerability was identified in projectworlds Expense Management System 1.0. The impacted element is an unknown function of the file /public/admin/users/create of the component Users Page. The manipulation leads to cross site scripting. The attack is possible to be carried out remotely. The exploβ¦
5.1
CVE-2025-12227 - projectworlds Gate Pass Management System add-pass.php cross site scripting
A vulnerability was determined in projectworlds Gate Pass Management System 1.0. The affected element is an unknown function of the file /add-pass.php. Executing a manipulation can lead to cross site scripting. The attack can be executed remotely. The exploit has been publicly disclosed and may be β¦