6.9

CVSS4.0

CVE-2025-8439 - code-projects Wazifa System updatesettings.php sql injection

A vulnerability, which was classified as critical, has been found in code-projects Wazifa System 1.0. This issue affects some unknown processing of the file /controllers/updatesettings.php. The manipulation of the argument Password leads to sql injection. The attack may be initiated remotely. The e…

πŸ“… Published: Aug. 1, 2025, 7:02 a.m. πŸ”„ Last Modified: Aug. 5, 2025, 6:54 p.m.

6.4

CVSS3.1

CVE-2025-7646 - The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <…

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom script parameter in all versions up to, and including, 6.3.10 even when the user does not have the unfiltered_html c…

πŸ“… Published: Aug. 1, 2025, 6:44 a.m. πŸ”„ Last Modified: April 21, 2026, 4 a.m.

6.9

CVSS4.0

CVE-2025-8438 - code-projects Wazifa System postpublish.php sql injection

A vulnerability classified as critical was found in code-projects Wazifa System 1.0. This vulnerability affects unknown code of the file /controllers/postpublish.php. The manipulation of the argument post leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed t…

πŸ“… Published: Aug. 1, 2025, 6:32 a.m. πŸ”„ Last Modified: Aug. 5, 2025, 6:54 p.m.

6.9

CVSS4.0

CVE-2025-8437 - code-projects Kitchen Treasure userregistration.php sql injection

A vulnerability classified as critical has been found in code-projects Kitchen Treasure 1.0. This affects an unknown part of the file /userregistration.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed …

πŸ“… Published: Aug. 1, 2025, 6:02 a.m. πŸ”„ Last Modified: Aug. 5, 2025, 6:55 p.m.

5.8

CVSS3.1

CVE-2025-5921 - SureForms < 1.7.2 - Reflected XSS

The SureForms WordPress plugin before 1.7.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against both authenticated and unauthenticated users.

πŸ“… Published: Aug. 1, 2025, 6 a.m. πŸ”„ Last Modified: Aug. 6, 2025, 4:48 p.m.

5.1

CVSS3.1

CVE-2025-31716 -

In bootloader, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed.

πŸ“… Published: Aug. 1, 2025, 5:55 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-8454 -

It was discovered that uscan, a tool to scan/watch upstream sources for new releases of software, included in devscripts (a collection of scripts to make the life of a Debian Package maintainer easier), skips OpenPGP verification if the upstream source is already downloaded from a previous run even…

πŸ“… Published: Aug. 1, 2025, 5:41 a.m. πŸ”„ Last Modified: Aug. 6, 2025, 4:17 p.m.

6.9

CVSS4.0

CVE-2025-8436 - projectworlds Online Admission System viewdoc.php sql injection

A vulnerability was found in projectworlds Online Admission System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /viewdoc.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been…

πŸ“… Published: Aug. 1, 2025, 5:32 a.m. πŸ”„ Last Modified: Aug. 6, 2025, 4:48 p.m.

6.9

CVSS4.0

CVE-2025-8435 - code-projects Online Movie Streaming admin-control.php authorization

A vulnerability was found in code-projects Online Movie Streaming 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin-control.php. The manipulation of the argument ID leads to missing authorization. The attack can be launched remotely…

πŸ“… Published: Aug. 1, 2025, 4:32 a.m. πŸ”„ Last Modified: Aug. 5, 2025, 6:55 p.m.

6.4

CVSS3.1

CVE-2025-7845 - Stratum – Elementor Widgets <= 1.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via…

The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Advanced Google Maps and Image Hotspot widgets in all versions up to, and including, 1.6.0 due to insufficient input sanitization and output escaping on user supplied attributes. This …

πŸ“… Published: Aug. 1, 2025, 4:24 a.m. πŸ”„ Last Modified: April 20, 2026, 8:15 p.m.
Total resulsts: 347814
Page 4303 of 34,782
Β« previous page Β» next page
Filters