6.9

CVSS4.0

CVE-2025-9009 - itsourcecode Online Tour and Travel Management System email_setup.php sql injection

A vulnerability has been found in itsourcecode Online Tour and Travel Management System 1.0. Affected is an unknown function of the file /admin/email_setup.php. The manipulation of the argument Name leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosedโ€ฆ

๐Ÿ“… Published: Aug. 15, 2025, 4:32 a.m. ๐Ÿ”„ Last Modified: Sept. 26, 2025, 12:30 p.m.

3.7

CVSS3.1

CVE-2025-31961 - HCL Connections is vulnerable to broken access control

HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.

๐Ÿ“… Published: Aug. 15, 2025, 4:29 a.m. ๐Ÿ”„ Last Modified: Oct. 10, 2025, 4:59 p.m.

6.9

CVSS4.0

CVE-2025-9008 - itsourcecode Online Tour and Travel Management System sms_setting.php sql injection

A vulnerability was identified in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown processing of the file /admin/sms_setting.php. The manipulation of the argument uname leads to sql injection. The attack may be initiated remotely. The exploit has been disclโ€ฆ

๐Ÿ“… Published: Aug. 15, 2025, 4:02 a.m. ๐Ÿ”„ Last Modified: Aug. 18, 2025, 3:11 p.m.

8.7

CVSS4.0

CVE-2025-9007 - Tenda CH22 editFileName formeditFileName buffer overflow

A vulnerability has been found in Tenda CH22 1.0.0.1. Affected by this issue is the function formeditFileName of the file /goform/editFileName. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

๐Ÿ“… Published: Aug. 15, 2025, 3:32 a.m. ๐Ÿ”„ Last Modified: Sept. 26, 2025, 12:30 p.m.

8.7

CVSS4.0

CVE-2025-9006 - Tenda CH22 delFileName formdelFileName buffer overflow

A vulnerability was identified in Tenda CH22 1.0.0.1. Affected by this vulnerability is the function formdelFileName of the file /goform/delFileName. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

๐Ÿ“… Published: Aug. 15, 2025, 3:02 a.m. ๐Ÿ”„ Last Modified: Sept. 26, 2025, 12:30 p.m.

6.3

CVSS4.0

CVE-2025-9005 - mtons mblog register information exposure

A vulnerability was determined in mtons mblog up to 3.5.0. Affected is an unknown function of the file /register. The manipulation leads to information exposure through error message. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is tolโ€ฆ

๐Ÿ“… Published: Aug. 15, 2025, 3:02 a.m. ๐Ÿ”„ Last Modified: Aug. 27, 2025, 7:16 p.m.

6.3

CVSS4.0

CVE-2025-9004 - mtons mblog password excessive authentication

A vulnerability was found in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /settings/password. The manipulation leads to improper restriction of excessive authentication attempts. The attack may be initiated remotely. The complexity of an attack is rather high. Theโ€ฆ

๐Ÿ“… Published: Aug. 15, 2025, 2:32 a.m. ๐Ÿ”„ Last Modified: Aug. 27, 2025, 6:23 p.m.

5.1

CVSS4.0

CVE-2025-9003 - D-Link DIR-818LW DHCP Reserved Address bsc_lan.php cross site scripting

A vulnerability has been found in D-Link DIR-818LW 1.04. This vulnerability affects unknown code of the file /bsc_lan.php of the component DHCP Reserved Address Handler. The manipulation of the argument Name leads to cross site scripting. The attack can be initiated remotely. This vulnerability onlโ€ฆ

๐Ÿ“… Published: Aug. 15, 2025, 2:32 a.m. ๐Ÿ”„ Last Modified: Oct. 3, 2025, 6:39 p.m.

4.3

CVSS3.1

CVE-2025-8676 - B Slider - Gutenberg Slider Block for WP <= 2.0.0 - Authenticated (Subscriber+) Sensitive Informatiโ€ฆ

The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Sensitive Information Exposure in versions less than, or equal to, 2.0.0 via the get_active_plugins function. This makes it possible for authenticated attackers, with subscriber-level access and above to extract sensiโ€ฆ

๐Ÿ“… Published: Aug. 15, 2025, 2:24 a.m. ๐Ÿ”„ Last Modified: April 20, 2026, 10:15 p.m.

6.4

CVSS3.1

CVE-2025-8867 - Graphina - Elementor Charts and Graphs <= 3.1.3 - Authenticated (Contributor+) Stored Cross-Site Scโ€ฆ

The Graphina - Elementor Charts and Graphs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple chart widget parameters in version 3.1.3 and below. This is due to insufficient input sanitization and output escaping on user supplied attributes such as chart categories, titlโ€ฆ

๐Ÿ“… Published: Aug. 15, 2025, 2:24 a.m. ๐Ÿ”„ Last Modified: April 20, 2026, 8 p.m.
Total resulsts: 349182
Page 4263 of 34,919
ยซ previous page ยป next page
Filters