5.3
CVE-2025-4016 - 20120630 Novel-Plus LogController.java deleteIndex improper authorization
A vulnerability classified as critical has been found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. This affects the function deleteIndex of the file novel-admin/src/main/java/com/java2nb/common/controller/LogController.java. The manipulation leads to improper authorizationโฆ
6.9
CVE-2025-4015 - 20120630 Novel-Plus SessionController.java list missing authentication
A vulnerability was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. It has been rated as critical. Affected by this issue is the function list of the file novel-system/src/main/java/com/java2nb/system/controller/SessionController.java. The manipulation leads to missing โฆ
9.1
CVE-2025-3200 - Com-Server Exposed via Weak TLS
An unauthenticated remote attacker could exploit the used, insecure TLS 1.0 and TLS 1.1 protocols to intercept and manipulate encrypted communications between the Com-Server and connected systems.
6.9
CVE-2025-4014 - PHPGurukul Art Gallery Management System manage-art-medium.php sql injection
A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/manage-art-medium.php. The manipulation of the argument artmed leads to sql injection. The attack can be launcheโฆ
3.7
CVE-2025-32471 - Reuse of salt
The deviceโs passwords have not been adequately salted, making them vulnerable to password extraction attacks.
5.3
CVE-2025-39367 - WordPress Kleo theme < 5.4.4 - Broken Access Control vulnerability
Missing Authorization vulnerability in SeventhQueen Kleo kleo.This issue affects Kleo: from n/a through < 5.4.4.
7.5
CVE-2025-32470 - Unauthenticated change of IP adress
A remote unauthenticated attacker may be able to change the IP adress of the device, and therefore affecting the availability of the device.
6.9
CVE-2025-4013 - PHPGurukul Art Gallery Management System aboutus.php sql injection
A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/aboutus.php. The manipulation of the argument pagetitle leads to sql injection. It is possible to launch the attack remotely. The exploitโฆ
5.1
CVE-2025-4012 - playeduxyz PlayEdu ๅผๆบๅน่ฎญ็ณป็ป User Avatar create server-side request forgery
A vulnerability was found in playeduxyz PlayEdu ๅผๆบๅน่ฎญ็ณป็ป up to 1.8 and classified as problematic. This issue affects some unknown processing of the file /api/backend/v1/user/create of the component User Avatar Handler. The manipulation of the argument Avatar leads to server-side request forgery. The โฆ
8.4
CVE-2025-42598 -
Multiple SEIKO EPSON printer drivers for Windows OS are configured with an improper access permission settings when installed or used in a language other than English. If a user is directed to place a crafted DLL file in a location of an attacker's choosing, the attacker may execute arbitrary code โฆ