7

CVSS4.0

CVE-2025-1131 - Asterisk Unsafe Shell Sourcing in safe_asterisk Leads to Local Privilege Escalation

A local privilege escalation vulnerability exists in the safe_asterisk script included with the Asterisk toolkit package. When Asterisk is started via this script (common in SysV init or FreePBX environments), it sources all .sh files located in /etc/asterisk/startup.d/ as root, without validating …

πŸ“… Published: Sept. 23, 2025, 4:31 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:48 p.m.

9.8

CVSS3.1

CVE-2025-9321 - WPCasa <= 1.4.1 - Unauthenticated Code Injection

The WPCasa plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 1.4.1. This is due to insufficient input validation and restriction on the 'api_requests' function. This makes it possible for unauthenticated attackers to call arbitrary functions and execute code.

πŸ“… Published: Sept. 23, 2025, 4:26 a.m. πŸ”„ Last Modified: April 20, 2026, 7:30 p.m.

5.1

CVSS4.0

CVE-2025-10837 - code-projects Simple Food Ordering System order.php cross site scripting

A security vulnerability has been detected in code-projects Simple Food Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file /ordersimple/order.php. The manipulation of the argument ID leads to cross site scripting. The attack may be initiated remotely. The ex…

πŸ“… Published: Sept. 23, 2025, 4:02 a.m. πŸ”„ Last Modified: Sept. 25, 2025, 4:15 p.m.

6.4

CVSS3.1

CVE-2025-8902 - Widget Options - Extended <= 5.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Widget Options - Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'do_sidebar' shortcode in all versions up to, and including, 5.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for auth…

πŸ“… Published: Sept. 23, 2025, 3:34 a.m. πŸ”„ Last Modified: April 21, 2026, 3 a.m.

8.8

CVSS3.1

CVE-2025-10380 - Advanced Views – Display Posts, Custom Fields, and More <= 3.7.19 - Authenticated (Author+) Remote …

The Advanced Views – Display Posts, Custom Fields, and More plugin for WordPress is vulnerable to Server-Side Template Injection in all versions up to, and including, 3.7.19. This is due to insufficient input sanitization and lack of access control when processing custom Twig templates in the Model…

πŸ“… Published: Sept. 23, 2025, 3:34 a.m. πŸ”„ Last Modified: April 22, 2026, 1:30 p.m.

6.9

CVSS4.0

CVE-2025-10836 - SourceCodester Pet Grooming Management Software print1.php sql injection

A weakness has been identified in SourceCodester Pet Grooming Management Software 1.0. Affected is an unknown function of the file /admin/print1.php. Executing manipulation of the argument ID can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the …

πŸ“… Published: Sept. 23, 2025, 3:32 a.m. πŸ”„ Last Modified: Sept. 24, 2025, 8:24 p.m.

5.3

CVSS4.0

CVE-2025-10835 - SourceCodester Pet Grooming Management Software view_payorder.php sql injection

A security flaw has been discovered in SourceCodester Pet Grooming Management Software 1.0. This impacts an unknown function of the file /admin/view_payorder.php. Performing manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit has been released…

πŸ“… Published: Sept. 23, 2025, 3:32 a.m. πŸ”„ Last Modified: Sept. 24, 2025, 8:24 p.m.

6.9

CVSS4.0

CVE-2025-10834 - itsourcecode Open Source Job Portal login.php sql injection

A vulnerability was identified in itsourcecode Open Source Job Portal 1.0. This affects an unknown function of the file /jobportal/admin/login.php. Such manipulation of the argument user_email leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available an…

πŸ“… Published: Sept. 23, 2025, 3:02 a.m. πŸ”„ Last Modified: Sept. 25, 2025, 4:16 p.m.

6.9

CVSS4.0

CVE-2025-10833 - 1000projects Bookstore Management System login.php sql injection

A vulnerability was determined in 1000projects Bookstore Management System 1.0. The impacted element is an unknown function of the file /login.php. This manipulation of the argument unm causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and…

πŸ“… Published: Sept. 23, 2025, 2:32 a.m. πŸ”„ Last Modified: Sept. 25, 2025, 6:07 p.m.

6.5

CVSS3.1

CVE-2025-58915 - WordPress Request a Quote plugin <= 2.5.0 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in emarket-design Request a Quote request-a-quote allows Stored XSS.This issue affects Request a Quote: from n/a through <= 2.5.0.

πŸ“… Published: Sept. 23, 2025, 2:08 a.m. πŸ”„ Last Modified: April 23, 2026, 3:33 p.m.
Total resulsts: 349182
Page 3711 of 34,919
Β« previous page Β» next page
Filters