6.1
CVE-2025-9034 - Wp Edit Password Protected < 1.3.5 - Open Redirect
The Wp Edit Password Protected WordPress plugin before 1.3.5 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue
5.3
CVE-2025-10247 - JEPaaS Filter doFilterInternal access control
A security vulnerability has been detected in JEPaaS 7.2.8. This vulnerability affects the function doFilterInternal of the component Filter Handler. Such manipulation leads to improper access controls. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. Thβ¦
8.8
CVE-2025-9059 - Elevation of Privileges Vulnerability in IT Management Suite
The Altiris Core Agent Updater package (AeXNSC.exe) is prone to an elevation of privileges vulnerability through DLL hijacking.
5.1
CVE-2025-10246 - lokibhardwaj PHP-Code-For-Unlimited-File-Upload f.php cross site scripting
A weakness has been identified in lokibhardwaj PHP-Code-For-Unlimited-File-Upload up to 124fe96324915490c81eaf7db3234b0b4e4bab3c. This affects an unknown part of the file /f.php. This manipulation of the argument h causes cross site scripting. Remote exploitation of the attack is possible. The explβ¦
2.3
CVE-2025-9910 -
Versions of the package jsondiffpatch before 0.7.2 are vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeBegin. An attacker can inject malicious scripts into HTML payloads that may lead to code execution if untrusted payloads were used as source for the diff, and the result renderer uβ¦
6.5
CVE-2025-9776 - CatFolders β Tame Your WordPress Media Library by Category <= 2.5.2 - Authenticated (Author+) SQL Iβ¦
The CatFolders β Tame Your WordPress Media Library by Category plugin for WordPress is vulnerable to time-based SQL Injection via the CSV Import contents in all versions up to, and including, 2.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on theβ¦
4.8
CVE-2025-10245 - Display PainΓ©is TGA Galeria rename path traversal
A security flaw has been discovered in Display PainΓ©is TGA up to 7.1.41. Affected by this issue is some unknown functionality of the file /gallery/rename of the component Galeria Page. The manipulation of the argument current_folder results in path traversal. The exploit has been released to the puβ¦
5.3
CVE-2025-10236 - binary-husky gpt_academic LaTeX File latex_toolbox.py merge_tex_files_ path traversal
A vulnerability has been found in binary-husky gpt_academic up to 3.91. Impacted is the function merge_tex_files_ of the file crazy_functions/latex_fns/latex_toolbox.py of the component LaTeX File Handler. Such manipulation of the argument \input{} leads to path traversal. The attack may be launcheβ¦
3.1
CVE-2025-6088 - Improper Authorization in danny-avila/librechat
In version 0.7.8 of danny-avila/librechat, improper authorization controls in the conversation sharing feature allow unauthorized access to other users' conversations if the conversation ID is known. Although UUIDv4 conversation IDs are generated server-side and are difficult to brute force, they cβ¦
4.8
CVE-2025-10235 - Scada-LTS Reports reports.shtm cross site scripting
A flaw has been found in Scada-LTS up to 2.7.8.1. This issue affects some unknown processing of the file /reports.shtm of the component Reports Module. This manipulation of the argument Colour causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may β¦