2.3

CVSS4.0

CVE-2025-9019 - tcpreplay tcpprep cidr.c mask_cidr6 heap-based overflow

A vulnerability has been found in tcpreplay 4.5.1. This vulnerability affects the function mask_cidr6 of the file cidr.c of the component tcpprep. The manipulation leads to heap-based buffer overflow. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation…

📅 Published: Aug. 15, 2025, 7:02 a.m. 🔄 Last Modified: Sept. 11, 2025, 5:53 p.m.

5.3

CVSS4.0

CVE-2025-9017 - PHPGurukul Zoo Management System add-foreigner-ticket.php cross site scripting

A vulnerability has been found in PHPGurukul Zoo Management System 2.1. This vulnerability affects unknown code of the file /admin/add-foreigner-ticket.php. The manipulation of the argument visitorname leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclos…

📅 Published: Aug. 15, 2025, 7:02 a.m. 🔄 Last Modified: Aug. 21, 2025, 8:58 p.m.

9.8

CVSS3.1

CVE-2025-6679 - Contact Form by Bit Form - Bit Form <= 2.20.3 - Unauthenticated Arbitrary File Upload

The Bit Form builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 2.20.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code…

📅 Published: Aug. 15, 2025, 6:40 a.m. 🔄 Last Modified: April 22, 2026, 1 a.m.

6.4

CVSS3.1

CVE-2025-8451 - Essential Addons for Elementor – Popular Elementor Templates and Widgets <= 6.2.2 - Authenticated (…

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘data-gallery-items’ parameter in all versions up to, and including, 6.2.2 due to insufficient input sanitization and output escaping. This …

📅 Published: Aug. 15, 2025, 6:40 a.m. 🔄 Last Modified: April 21, 2026, 3:45 a.m.

3.8

CVSS3.1

CVE-2025-8013 - Quttera Web Malware Scanner <= 3.5.1.41 - Authenticated (Administrator+) Server-Side Request Forgery

The Quttera Web Malware Scanner plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.5.1.41 via the 'RunExternalScan' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to…

📅 Published: Aug. 15, 2025, 6:40 a.m. 🔄 Last Modified: April 21, 2026, 3:45 a.m.

7.3

CVSS4.0

CVE-2025-9016 - Mechrevo Control Center GX V2 Powershell Script Command uncontrolled search path

A vulnerability was identified in Mechrevo Control Center GX V2 5.56.51.48. This affects an unknown part of the file C:\Program Files\OEM\机械革命控制中心\AiStoneService\MyControlCenter\Command of the component Powershell Script Handler. The manipulation leads to uncontrolled search path. Local access is r…

📅 Published: Aug. 15, 2025, 6:32 a.m. 🔄 Last Modified: Sept. 11, 2025, 6 p.m.

6.9

CVSS4.0

CVE-2025-9013 - PHPGurukul Online Shopping Portal Project password-recovery.php sql injection

A vulnerability has been found in PHPGurukul Online Shopping Portal Project 2.0. This vulnerability affects unknown code of the file /shopping/password-recovery.php. The manipulation of the argument emailid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed…

📅 Published: Aug. 15, 2025, 6:02 a.m. 🔄 Last Modified: Aug. 21, 2025, 1:56 p.m.

6.9

CVSS4.0

CVE-2025-9012 - PHPGurukul Online Shopping Portal Project bill-ship-addresses.php sql injection

A vulnerability was identified in PHPGurukul Online Shopping Portal Project 2.0. This affects an unknown part of the file shopping/bill-ship-addresses.php. The manipulation of the argument billingpincode leads to sql injection. It is possible to initiate the attack remotely. The exploit has been di…

📅 Published: Aug. 15, 2025, 5:32 a.m. 🔄 Last Modified: Aug. 21, 2025, 2:19 p.m.

6.9

CVSS4.0

CVE-2025-9011 - PHPGurukul Online Shopping Portal Project signup.php sql injection

A vulnerability was determined in PHPGurukul Online Shopping Portal Project 2.0. Affected by this issue is some unknown functionality of the file /shopping/signup.php. The manipulation of the argument emailid leads to sql injection. The attack may be launched remotely. The exploit has been disclose…

📅 Published: Aug. 15, 2025, 5:02 a.m. 🔄 Last Modified: Aug. 21, 2025, 2:22 p.m.

6.9

CVSS4.0

CVE-2025-9010 - itsourcecode Online Tour and Travel Management System booking_report.php sql injection

A vulnerability was found in itsourcecode Online Tour and Travel Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/booking_report.php. The manipulation of the argument from_date leads to sql injection. The attack can be launched remotely. The explo…

📅 Published: Aug. 15, 2025, 4:32 a.m. 🔄 Last Modified: Aug. 18, 2025, 3:10 p.m.
Total resulsts: 349182
Page 4262 of 34,919
« previous page » next page
Filters