5.3
CVE-2025-8381 - Campcodes Online Hotel Reservation System add_reserve.php sql injection
A vulnerability, which was classified as critical, has been found in Campcodes Online Hotel Reservation System 1.0. This issue affects some unknown processing of the file /add_reserve.php. The manipulation of the argument room_id leads to sql injection. The attack may be initiated remotely. The expโฆ
4.3
CVE-2025-8068 - HT Mega โ Absolute Addons For Elementor <= 2.9.1 - Improper Authorization to Authenticated (Contribโฆ
The HT Mega โ Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification and loss of data due to an improper capability check on the 'ajax_trash_templates' function in all versions up to, and including, 2.9.1. This makes it possible for authenticated attackers, wiโฆ
4.3
CVE-2025-8401 - HT Mega โ Absolute Addons For Elementor <= 2.9.1 - Authenticated (Author+) Sensitive Information Exโฆ
The HT Mega โ Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.1 via the 'get_post_data' function. This makes it possible for authenticated attackers, with Author-level access and above, to extract sensitiveโฆ
4.3
CVE-2025-8151 - HT Mega โ Absolute Addons For Elementor <= 2.9.1 - Authenticated (Author+) Path Traversal to Limiteโฆ
The HT Mega โ Absolute Addons For Elementor plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.9.1 via the 'save_block_css' function. This makes it possible for authenticated attackers, with Author-level access and above, to create CSS files in any directorโฆ
5.1
CVE-2025-8380 - Campcodes Online Hotel Reservation System add_query_account.php cross site scripting
A vulnerability classified as problematic was found in Campcodes Online Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /admin/add_query_account.php. The manipulation of the argument Name leads to cross site scripting. The attack can be initiated remotely. The explโฆ
5.1
CVE-2025-8379 - Campcodes Online Hotel Reservation System edit_room.php unrestricted upload
A vulnerability classified as critical has been found in Campcodes Online Hotel Reservation System 1.0. This affects an unknown part of the file /admin/edit_room.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit hasโฆ
7.5
CVE-2025-2813 - HTTP Service DoS Vulnerability
An unauthenticated remote attacker can cause a Denial of Service by sending a large number of requests to the http service on port 80.
7.2
CVE-2025-41688 - High Privilege RCE via LUA Sandbox Escape
A high privileged remote attacker can execute arbitrary OS commands using an undocumented method allowing to escape the implemented LUA sandbox.
6.9
CVE-2025-8378 - Campcodes Online Hotel Reservation System Login index.php sql injection
A vulnerability was found in Campcodes Online Hotel Reservation System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/index.php of the component Login. The manipulation of the argument username/password leads to sql injection. The attack โฆ
5.1
CVE-2025-40980 - ddd
A Stored Cross Site Scripting vulnerability has been found in UltimatePOS by UltimateFosters. This vulnerability is due to the lack of proper validation of user inputs via โ/products/<PRODUCT_ID>/editโ, affecting to โnameโ parameter via POST. The vulnerability could allow a remote attacker to send โฆ