8.8

CVSS3.1

CVE-2023-49564 - Authentication Bypass

The CBIS/NCS Manager API is vulnerable to an authentication bypass. By sending a specially crafted HTTP header, an unauthenticated user can gain unauthorized access to API functions. This flaw allows attackers to reach restricted or sensitive endpoints of the HTTP API without providing any valid cr…

πŸ“… Published: Sept. 18, 2025, 6:10 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-9083 - Ninja-forms < 3.11.1 - Unauthenticated PHP Objection

The Ninja Forms WordPress plugin before 3.11.1 unserializes user input via form field, which could allow Unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.

πŸ“… Published: Sept. 18, 2025, 6 a.m. πŸ”„ Last Modified: Dec. 23, 2025, 6:59 p.m.

9.1

CVSS3.1

CVE-2025-8942 - WP Hotel Booking < 2.2.3 - Subscriber+ Rating Manipulation

The WP Hotel Booking WordPress plugin before 2.2.3 lacks proper server-side validation for review ratings, allowing an attacker to manipulate the rating value (e.g., sending negative or out-of-range values) by intercepting and modifying requests.

πŸ“… Published: Sept. 18, 2025, 6 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-5305 - Password Reset with Code < 0.0.17 - Insecure Password Reset Code Creation

The Password Reset with Code for WordPress REST API WordPress plugin before 0.0.17 does not use cryptographically sound algorithms to generate OTP codes, potentially leading to account takeovers.

πŸ“… Published: Sept. 18, 2025, 6 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-10642 - wangchenyi1996 chat_forum q.php cross site scripting

A vulnerability has been found in wangchenyi1996 chat_forum up to 80bdb92f5b460d36cab36e530a2c618acef5afd2. This impacts an unknown function of the file /q.php. Such manipulation of the argument path leads to cross site scripting. The attack may be launched remotely. This product operates on a roll…

πŸ“… Published: Sept. 18, 2025, 1:32 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-10634 - D-Link DIR-823X Environment Variable goahead sub_412E7C command injection

A weakness has been identified in D-Link DIR-823X 240126/240802/250416. The impacted element is the function sub_412E7C of the file /usr/sbin/goahead of the component Environment Variable Handler. This manipulation of the argument terminal_addr/server_ip/server_port causes command injection. The at…

πŸ“… Published: Sept. 18, 2025, 1:02 a.m. πŸ”„ Last Modified: Sept. 24, 2025, 6:42 p.m.

5.1

CVSS4.0

CVE-2025-10632 - itsourcecode Online Petshop Management System Admin Dashboard availableframe.php cross site scripti…

A security flaw has been discovered in itsourcecode Online Petshop Management System 1.0. The affected element is an unknown function of the file availableframe.php of the component Admin Dashboard. The manipulation of the argument name/address results in cross site scripting. It is possible to lau…

πŸ“… Published: Sept. 18, 2025, 1:02 a.m. πŸ”„ Last Modified: Sept. 20, 2025, 2:36 a.m.

5.1

CVSS4.0

CVE-2025-10631 - itsourcecode Online Petshop Management System Available Products addcnp.php cross site scripting

A vulnerability was identified in itsourcecode Online Petshop Management System 1.0. Impacted is an unknown function of the file addcnp.php of the component Available Products Page. The manipulation of the argument name/description leads to cross site scripting. It is possible to initiate the attac…

πŸ“… Published: Sept. 18, 2025, 12:32 a.m. πŸ”„ Last Modified: Sept. 20, 2025, 2:37 a.m.

5.3

CVSS4.0

CVE-2025-10629 - D-Link DIR-852 Simple Service Discovery Protocol Service cgibin ssdpcgi_main command injection

A vulnerability was determined in D-Link DIR-852 1.00CN B09. This issue affects the function ssdpcgi_main of the file htodcs/cgibin of the component Simple Service Discovery Protocol Service. Executing manipulation of the argument ST can lead to command injection. The attack may be performed from r…

πŸ“… Published: Sept. 18, 2025, 12:32 a.m. πŸ”„ Last Modified: Sept. 22, 2025, 6:20 p.m.

5.3

CVSS4.0

CVE-2025-10628 - D-Link DIR-852 Web Management hedwig.cgi command injection

A vulnerability was found in D-Link DIR-852 1.00CN B09. This vulnerability affects unknown code of the file /htdocs/cgibin/hedwig.cgi of the component Web Management Interface. Performing manipulation results in command injection. The attack is possible to be carried out remotely. The exploit has b…

πŸ“… Published: Sept. 18, 2025, 12:02 a.m. πŸ”„ Last Modified: Sept. 22, 2025, 6:22 p.m.
Total resulsts: 349182
Page 3783 of 34,919
Β« previous page Β» next page
Filters