6.4
CVE-2025-9496 - Enable Media Replace <= 4.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via file_m…
The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file_modified shortcode in all versions up to, and including, 4.1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenti…
5.3
CVE-2025-11593 - CodeAstro Gym Management System delete-equipment.php sql injection
A flaw has been found in CodeAstro Gym Management System 1.0. This vulnerability affects unknown code of the file /admin/actions/delete-equipment.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
5.3
CVE-2025-11592 - CodeAstro Gym Management System edit-equipmentform.php sql injection
A vulnerability was detected in CodeAstro Gym Management System 1.0. This affects an unknown part of the file /admin/edit-equipmentform.php. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit is now public and may be used.
5.3
CVE-2025-11591 - CodeAstro Gym Management System delete-member.php sql injection
A security vulnerability has been detected in CodeAstro Gym Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/actions/delete-member.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has bee…
5.3
CVE-2025-58285 -
Permission control vulnerability in the media module. Successful exploitation of this vulnerability may affect service confidentiality.
5.9
CVE-2025-58284 -
Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service confidentiality.
5.5
CVE-2025-58283 -
Permission control vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service confidentiality.
2.8
CVE-2025-58282 -
Permission control vulnerability in the camera module. Successful exploitation of this vulnerability may affect service confidentiality.
6.2
CVE-2025-58278 -
Identity authentication bypass vulnerability in the Gallery app. Successful exploitation of this vulnerability may affect service confidentiality.
4
CVE-2025-58277 -
Permission verification bypass vulnerability in the Camera app. Successful exploitation of this vulnerability may affect service confidentiality.