6.5

CVSS3.1

CVE-2025-49235 - WordPress RTMKit Addons for Elementor plugin <= 1.6.0 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rometheme RTMKit rometheme-for-elementor allows Stored XSS.This issue affects RTMKit: from n/a through <= 1.6.0.

πŸ“… Published: June 6, 2025, 12:53 p.m. πŸ”„ Last Modified: April 23, 2026, 3:31 p.m.

5.1

CVSS4.0

CVE-2025-5765 - code-projects Laundry System edit_laundry.php cross site scripting

A vulnerability was found in code-projects Laundry System 1.0. It has been classified as problematic. This affects an unknown part of the file /data/edit_laundry.php. The manipulation of the argument Customer leads to cross site scripting. It is possible to initiate the attack remotely. The exploit…

πŸ“… Published: June 6, 2025, 12:31 p.m. πŸ”„ Last Modified: June 10, 2025, 7:29 p.m.

5.1

CVSS4.0

CVE-2025-5764 - code-projects Laundry System insert_laundry.php cross site scripting

A vulnerability was found in code-projects Laundry System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /data/insert_laundry.php. The manipulation of the argument Customer leads to cross site scripting. The attack may be launched remotely. The e…

πŸ“… Published: June 6, 2025, 12:31 p.m. πŸ”„ Last Modified: June 10, 2025, 7:29 p.m.

9.8

CVSS3.1

CVE-2025-49072 - WordPress Mr. Murphy < 1.2.12.1 - PHP Object Injection Vulnerability

Deserialization of Untrusted Data vulnerability in AncoraThemes Mr. Murphy mr-murphy allows Object Injection.This issue affects Mr. Murphy: from n/a through < 1.2.12.1.

πŸ“… Published: June 6, 2025, 12:15 p.m. πŸ”„ Last Modified: April 23, 2026, 3:31 p.m.

9.8

CVSS3.1

CVE-2025-49073 - WordPress Sweet Dessert < 1.1.13 - PHP Object Injection Vulnerability

Deserialization of Untrusted Data vulnerability in axiomthemes Sweet Dessert sweet-dessert allows Object Injection.This issue affects Sweet Dessert: from n/a through < 1.1.13.

πŸ“… Published: June 6, 2025, 12:13 p.m. πŸ”„ Last Modified: April 23, 2026, 3:31 p.m.

5.1

CVSS4.0

CVE-2025-5763 - Tenda CP3 apollo sub_F3C8C command injection

A vulnerability has been found in Tenda CP3 11.10.00.2311090948 and classified as critical. Affected by this vulnerability is the function sub_F3C8C of the file apollo. The manipulation leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and…

πŸ“… Published: June 6, 2025, noon πŸ”„ Last Modified: June 10, 2025, 2:55 p.m.

5.3

CVSS4.0

CVE-2025-5762 - code-projects Patient Record Management System view_hematology.php sql injection

A vulnerability, which was classified as critical, was found in code-projects Patient Record Management System 1.0. Affected is an unknown function of the file view_hematology.php. The manipulation of the argument itr_no leads to sql injection. It is possible to launch the attack remotely. The expl…

πŸ“… Published: June 6, 2025, noon πŸ”„ Last Modified: June 10, 2025, 2:57 p.m.

8.3

CVSS4.0

CVE-2025-41361 - Uncontrolled resource consumption vulnerability in IDF and ZLF

Uncontrolled resource consumption vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. The devices improperly handle TLS requests associated with PROCOME sockets, so TLS requests sent to those PROCOME ports could cause the device to reboot and result in a denial of service. To exploit this…

πŸ“… Published: June 6, 2025, 11:53 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-41367 - Stored Cross-Site Scripting (XSS) vulnerability in IDF and ZLF

Stored Cross-Site Scripting (XSS) vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. This vulnerability allows an attacker to store malicious JavaScript payload in software that will run in the victim's browser. Exploiting this vulnerability requires authenticating to the device and exec…

πŸ“… Published: June 6, 2025, 11:51 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-41366 - CORS vulnerability in IDF and ZLF

In IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04, a configuration error has been detected in cross-origin resource sharing (CORS). Exploiting this vulnerability requires authenticating to the device and executing certain commands that can only be executed with permissions higher than the view permiss…

πŸ“… Published: June 6, 2025, 11:50 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 5150 of 34,919
Β« previous page Β» next page
Filters