4.5
CVE-2025-9913 - Cross Site Scripting: Session Hijacking
JavaScript can be ran inside the address bar via the dashboard "Open in new Tab" Button, making the application vulnerable to session hijacking.
8.7
CVE-2025-11324 - Tenda AC18 setNotUpgrade stack-based overflow
A vulnerability was identified in Tenda AC18 15.03.05.19(6318). Affected by this vulnerability is an unknown functionality of the file /goform/setNotUpgrade. Such manipulation of the argument newVersion leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicโฆ
8.7
CVE-2025-11323 - UTT 1250GW formUserStatusRemark strcpy buffer overflow
A vulnerability was determined in UTT 1250GW up to v2v3.2.2-200710. Affected is the function strcpy of the file /goform/formUserStatusRemark. This manipulation of the argument Username causes buffer overflow. Remote exploitation of the attack is possible. The exploit has been publicly disclosed andโฆ
6.3
CVE-2025-9710 - Responsive Lightbox & Gallery < 2.5.3 - Unauthenticated Stored-XSS via Comments
The Responsive Lightbox & Gallery WordPress plugin before 2.5.3 does not properly handle HTML tag attributes modifications, potentially allowing unauthenticated attackers to abuse the functionality to include event handlers and conduct Stored XSS attacks.
4.3
CVE-2025-9703 - Ultimate Addons for Elementor Lite < 2.5.0 - Author+ Stored XSS
The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) WordPress plugin before 2.5.0 does not sanitize SVG file contents when uploaded through the xmlrpc.php endpoint using base64 encode, leading to a Cross-Site Scripting vulnerability.
6.3
CVE-2025-11322 - Mangati NovoSGA User Creation new weak password
A flaw has been found in Mangati NovoSGA up to 2.2.12. The impacted element is an unknown function of the file /novosga.users/new of the component User Creation Page. Executing manipulation of the argument Senha/Confirmaรงรฃo da senha can lead to weak password requirements. The attack can be launchedโฆ
8.4
CVE-2025-57781 -
The installers of DENSO TEN drive recorder viewer contain an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privilege of the user invoking the installer.
5.3
CVE-2025-11321 - zhuimengshaonian wisdom-education WrongBookController.java authorization
A vulnerability was detected in zhuimengshaonian wisdom-education up to 1.0.4. The affected element is an unknown function of the file src/main/java/com/education/api/controller/student/WrongBookController.java. Performing manipulation of the argument subjectId results in authorization bypass. The โฆ
5.3
CVE-2025-11320 - zhuimengshaonian wisdom-education UploadController.java uploadFile unrestricted upload
A security vulnerability has been detected in zhuimengshaonian wisdom-education up to 1.0.4. Impacted is the function uploadFile of the file src/main/java/com/education/core/controller/UploadController.java. Such manipulation of the argument File leads to unrestricted upload. It is possible to launโฆ
5.3
CVE-2025-11319 - nahiduddinahammed Hospital-Management-System-Website delete.php sql injection
A weakness has been identified in nahiduddinahammed Hospital-Management-System-Website up to e6562429e14b2f88bd2139cae16e87b965024097. This issue affects some unknown processing of the file /delete.php. This manipulation of the argument ai causes sql injection. It is possible to initiate the attackโฆ