6.5
CVE-2025-58703 - WordPress Skyword API Plugin Plugin <= 2.5.3 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skyword Skyword API Plugin skyword-plugin allows Stored XSS.This issue affects Skyword API Plugin: from n/a through <= 2.5.3.
6.5
CVE-2025-58704 - WordPress WP Delete User Accounts Plugin <= 1.2.4 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ren Ventura WP Delete User Accounts wp-delete-user-accounts allows Stored XSS.This issue affects WP Delete User Accounts: from n/a through <= 1.2.4.
5.5
CVE-2025-59418 - BunnyPad Vulnerable to Buffer Overflow When Opening Files of Size 20MB or Greater
BunnyPad is a note taking software. Prior to version 11.0.27000.0915, opening files greater than or equal to 20MB causes buffer overflow to occur. This issue has been patched in version 11.0.27000.0915. Users who wish not to upgrade should refrain from opening files larger than 10MB.
6.9
CVE-2025-10809 - Campcodes Online Learning Management System department.php sql injection
A security vulnerability has been detected in Campcodes Online Learning Management System 1.0. The affected element is an unknown function of the file /admin/department.php. Such manipulation of the argument d leads to sql injection. The attack can be executed remotely. The exploit has been disclosβ¦
6.9
CVE-2025-10808 - Campcodes Farm Management System uploadProduct.php sql injection
A weakness has been identified in Campcodes Farm Management System 1.0. Impacted is an unknown function of the file /uploadProduct.php. This manipulation of the argument Type causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and cβ¦
7.5
CVE-2025-59420 - Authlib: JWS/JWT accepts unknown crit headers (RFC violation β possible authz bypass)
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.4, Authlibβs JWS verification accepts tokens that declare unknown critical header parameters (crit), violating RFC 7515 βmustβunderstandβ semantics. An attacker can craft a signed token with a critical hβ¦
0.0
CVE-2025-59885 -
Not used
0.0
CVE-2025-59880 -
Not used
0.0
CVE-2025-59881 -
Not used
0.0
CVE-2025-59882 -
Not used