6.9

CVSS4.0

CVE-2025-9008 - itsourcecode Online Tour and Travel Management System sms_setting.php sql injection

A vulnerability was identified in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown processing of the file /admin/sms_setting.php. The manipulation of the argument uname leads to sql injection. The attack may be initiated remotely. The exploit has been discl…

📅 Published: Aug. 15, 2025, 4:02 a.m. 🔄 Last Modified: Aug. 18, 2025, 3:11 p.m.

8.7

CVSS4.0

CVE-2025-9007 - Tenda CH22 editFileName formeditFileName buffer overflow

A vulnerability has been found in Tenda CH22 1.0.0.1. Affected by this issue is the function formeditFileName of the file /goform/editFileName. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

📅 Published: Aug. 15, 2025, 3:32 a.m. 🔄 Last Modified: Sept. 26, 2025, 12:30 p.m.

8.7

CVSS4.0

CVE-2025-9006 - Tenda CH22 delFileName formdelFileName buffer overflow

A vulnerability was identified in Tenda CH22 1.0.0.1. Affected by this vulnerability is the function formdelFileName of the file /goform/delFileName. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

📅 Published: Aug. 15, 2025, 3:02 a.m. 🔄 Last Modified: Sept. 26, 2025, 12:30 p.m.

6.3

CVSS4.0

CVE-2025-9005 - mtons mblog register information exposure

A vulnerability was determined in mtons mblog up to 3.5.0. Affected is an unknown function of the file /register. The manipulation leads to information exposure through error message. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is tol…

📅 Published: Aug. 15, 2025, 3:02 a.m. 🔄 Last Modified: Aug. 27, 2025, 7:16 p.m.

6.3

CVSS4.0

CVE-2025-9004 - mtons mblog password excessive authentication

A vulnerability was found in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /settings/password. The manipulation leads to improper restriction of excessive authentication attempts. The attack may be initiated remotely. The complexity of an attack is rather high. The…

📅 Published: Aug. 15, 2025, 2:32 a.m. 🔄 Last Modified: Aug. 27, 2025, 6:23 p.m.

5.1

CVSS4.0

CVE-2025-9003 - D-Link DIR-818LW DHCP Reserved Address bsc_lan.php cross site scripting

A vulnerability has been found in D-Link DIR-818LW 1.04. This vulnerability affects unknown code of the file /bsc_lan.php of the component DHCP Reserved Address Handler. The manipulation of the argument Name leads to cross site scripting. The attack can be initiated remotely. This vulnerability onl…

📅 Published: Aug. 15, 2025, 2:32 a.m. 🔄 Last Modified: Oct. 3, 2025, 6:39 p.m.

4.3

CVSS3.1

CVE-2025-8676 - B Slider - Gutenberg Slider Block for WP <= 2.0.0 - Authenticated (Subscriber+) Sensitive Informati…

The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Sensitive Information Exposure in versions less than, or equal to, 2.0.0 via the get_active_plugins function. This makes it possible for authenticated attackers, with subscriber-level access and above to extract sensi…

📅 Published: Aug. 15, 2025, 2:24 a.m. 🔄 Last Modified: April 20, 2026, 10:15 p.m.

6.4

CVSS3.1

CVE-2025-8867 - Graphina - Elementor Charts and Graphs <= 3.1.3 - Authenticated (Contributor+) Stored Cross-Site Sc…

The Graphina - Elementor Charts and Graphs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple chart widget parameters in version 3.1.3 and below. This is due to insufficient input sanitization and output escaping on user supplied attributes such as chart categories, titl…

📅 Published: Aug. 15, 2025, 2:24 a.m. 🔄 Last Modified: April 20, 2026, 8 p.m.

4.3

CVSS3.1

CVE-2025-8680 - B Slider - Gutenberg Slider Block for WP <= 2.0.0 - Authenticated (Subscriber+) Server-Side Request…

The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Server-Side Request Forgery in version less than, or equal to, 2.0.0 via the fs_api_request function. This makes it possible for authenticated attackers, with subscriber-level access and above to make web requests to …

📅 Published: Aug. 15, 2025, 2:24 a.m. 🔄 Last Modified: April 20, 2026, 10:15 p.m.

7.5

CVSS3.1

CVE-2025-6025 - Order Tip for WooCommerce <= 1.5.4 - Unauthenticated Tip Manipulation to Negative Value Leading to …

The Order Tip for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Improper Input Validation in all versions up to, and including, 1.5.4. This is due to lack of server-side validation on the `data-tip` attribute, which makes it possible for unauthenticated attackers to apply an exc…

📅 Published: Aug. 15, 2025, 2:24 a.m. 🔄 Last Modified: April 21, 2026, 7:30 p.m.
Total resulsts: 348450
Page 4190 of 34,845
« previous page » next page
Filters