8.8
CVE-2025-41682 - Credential Disclosure via Insecure Storage on Charge Controller
An authenticated, low-privileged attacker can obtain credentials stored on the charge controller including the manufacturer password.
5.1
CVE-2025-10087 - SourceCodester Pet Grooming Management Software profit_report.php sql injection
A security vulnerability has been detected in SourceCodester Pet Grooming Management Software 1.0. Impacted is an unknown function of the file /admin/profit_report.php. Such manipulation of the argument product_id leads to sql injection. The attack can be launched remotely. The exploit has been disβ¦
5.3
CVE-2025-10086 - fuyang_lipengjun platform AdPositionController queryAll improper authorization
A weakness has been identified in fuyang_lipengjun platform 1.0.0. This issue affects the function queryAll of the file /adposition/queryAll of the component AdPositionController. This manipulation causes improper authorization. The attack can be initiated remotely. The exploit has been made availaβ¦
8.6
CVE-2025-8085 - Ditty < 3.1.58 - Unauthenticated SSRF
The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.
5.3
CVE-2025-10085 - SourceCodester Pet Grooming Management Software manage_website.php unrestricted upload
A security flaw has been discovered in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file manage_website.php. The manipulation results in unrestricted upload. It is possible to launch the attack remotely. The exploit has been released to the pubβ¦
5.3
CVE-2025-10084 - elunez eladmin SysLogController 1 queryErrorLogDetail improper authorization
A vulnerability was identified in elunez eladmin up to 2.7. This affects the function queryErrorLogDetail of the file /api/logs/error/1 of the component SysLogController. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit is publicly availaβ¦
2.3
CVE-2025-58422 -
RICOH Streamline NX versions 3.5.1 to 24R3 are vulnerable to tampering with operation history. If an attacker can perform a man-in-the-middle attack, they may alter the values of HTTP requests, which could result in tampering with the operation history of the productβs management tool.
5.3
CVE-2025-10083 - SourceCodester Pet Grooming Management Software profile.php unrestricted upload
A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. Affected by this issue is some unknown functionality of the file /admin/profile.php. Executing manipulation can lead to unrestricted upload. The attack may be performed from remote. The exploit has been publicly β¦
6.9
CVE-2025-10082 - SourceCodester Online Polling System manage-admins.php sql injection
A vulnerability has been found in SourceCodester Online Polling System 1.0. Affected is an unknown function of the file /admin/manage-admins.php. Such manipulation of the argument email leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and mayβ¦
5.1
CVE-2025-10081 - SourceCodester Pet Management System profile.php unrestricted upload
A flaw has been found in SourceCodester Pet Management System 1.0. This impacts an unknown function of the file /admin/profile.php. This manipulation of the argument website_image causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been published and may be usβ¦