4.3

CVSS3.1

CVE-2025-9374 - Ultimate Tag Warrior Importer <= 0.2 - Cross-Site Request Forgery

The Ultimate Tag Warrior Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to import tags granted they can tric…

📅 Published: Aug. 29, 2025, 4:25 a.m. 🔄 Last Modified: April 22, 2026, 5 p.m.

4.3

CVSS3.1

CVE-2025-8147 - LWSCache <= 2.8.5 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Activation …

The LWSCache plugin for WordPress is vulnerable to unauthorized modification of data due to improper authorization on the lwscache_activatePlugin() function in all versions up to, and including, 2.8.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to ac…

📅 Published: Aug. 29, 2025, 4:25 a.m. 🔄 Last Modified: April 22, 2026, 5 p.m.

8.6

CVSS4.0

CVE-2025-53508 -

Multiple products provided by iND Co.,Ltd contain an OS command injection vulnerability. If exploited, an arbitrary OS command may be executed and sensitive information may be obtained. As for the details of affected product names and versions, refer to the information under [Product Status].

📅 Published: Aug. 29, 2025, 4:14 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS4.0

CVE-2025-53507 -

Multiple products provided by iND Co.,Ltd contain an insecure storage of sensitive information vulnerability. If exploited, configuration information, such as admin password, may be disclosed. As for the details of affected product names and versions, refer to the information under [Product Status].

📅 Published: Aug. 29, 2025, 4:13 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-9619 - E4 Sistemas Mercatus ERP id resource injection

A security flaw has been discovered in E4 Sistemas Mercatus ERP 2.00.019. The affected element is an unknown function of the file /basico/webservice/imprimir-danfe/id/. Performing manipulation results in improper control of resource identifiers. It is possible to initiate the attack remotely. The v…

📅 Published: Aug. 29, 2025, 4:02 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-9639 - Ai3|QbiCRMGateway - Arbitrary File Reading through Path Traversal

The QbiCRMGateway developed by Ai3 has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files.

📅 Published: Aug. 29, 2025, 3:39 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-8858 - Changing|Clinic Image System - SQL Injection

Clinic Image System developed by Changing has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.

📅 Published: Aug. 29, 2025, 3:36 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-8857 - Changing|Clinic Image System - Use of Hard-coded Credentials

Clinic Image System developed by Changing contains hard-coded Credentials, allowing unauthenticated remote attackers to log into the system using administrator credentials embedded in the source code.

📅 Published: Aug. 29, 2025, 3:33 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-9610 - code-projects Online Event Judging System create_account.php sql injection

A vulnerability was determined in code-projects Online Event Judging System 1.0. This issue affects some unknown processing of the file /create_account.php. This manipulation of the argument fname causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly…

📅 Published: Aug. 29, 2025, 3:32 a.m. 🔄 Last Modified: Nov. 13, 2025, 3:52 p.m.

5.3

CVSS4.0

CVE-2025-9609 - Portabilis i-Educar consulta improper authorization

A vulnerability was found in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /educacenso/consulta. The manipulation results in improper authorization. The attack can be executed remotely. The exploit has been made public and could be used.

📅 Published: Aug. 29, 2025, 3:32 a.m. 🔄 Last Modified: Sept. 4, 2025, 6:31 p.m.
Total resulsts: 349182
Page 4091 of 34,919
« previous page » next page
Filters