8.4
CVE-2025-27998 -
An issue in Valvesoftware Steam Client Steam Client 1738026274 allows attackers to escalate privileges via a crafted executable or DLL.
8.6
CVE-2025-48201 -
The ns_backup extension through 13.0.0 for TYPO3 has a Predictable Resource Location.
6.5
CVE-2025-44892 -
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ownekey parameter in the web_rmon_alarm_post_rmon_alarm function.
6.1
CVE-2025-48206 -
The ns_backup extension through 13.0.0 for TYPO3 allows XSS.
6.5
CVE-2024-42922 -
AAPanel v7.0.7 was discovered to contain an OS command injection vulnerability.
9.1
CVE-2025-27558 -
IEEE P802.11-REVme D1.1 through D7.0 allows FragAttacks against mesh networks. In mesh networks using Wi-Fi Protected Access (WPA, WPA2, or WPA3) or Wired Equivalent Privacy (WEP), an adversary can exploit this vulnerability to inject arbitrary frames towards devices that support receiving non-SSP β¦
4.8
CVE-2025-5010 - moonlightL hexo-boot Blog Backend index.html cross site scripting
A vulnerability classified as problematic has been found in moonlightL hexo-boot 4.3.0. This affects an unknown part of the file /admin/home/index.html of the component Blog Backend. The manipulation of the argument Description leads to cross site scripting. It is possible to initiate the attack reβ¦
6.9
CVE-2025-5008 - projectworlds Online Time Table Generator add_teacher.php sql injection
A vulnerability was found in projectworlds Online Time Table Generator 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/add_teacher.php. The manipulation of the argument e leads to sql injection. The attack may be launched remotely. The expβ¦
5.1
CVE-2025-5007 - Part-DB Profile Picture Feature AttachmentSubmitHandler.php handleUpload cross site scripting
A vulnerability was found in Part-DB up to 1.17.0. It has been declared as problematic. Affected by this vulnerability is the function handleUpload of the file src/Services/Attachments/AttachmentSubmitHandler.php of the component Profile Picture Feature. The manipulation of the argument attachment β¦
6.9
CVE-2025-5006 - Campcodes Online Shopping Portal category.php sql injection
A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/category.php. The manipulation of the argument Category leads to sql injection. It is possible to launch the attack remotely. The exploit has beeβ¦