5.3
CVE-2025-8128 - zhousg letao product.js unrestricted upload
A vulnerability, which was classified as critical, has been found in zhousg letao up to 7d8df0386a65228476290949e0413de48f7fbe98. This issue affects some unknown processing of the file routes\bf\product.js. The manipulation of the argument pictrdtz leads to unrestricted upload. The attack may be inβ¦
5.3
CVE-2025-8127 - deerwms deer-wms-2 list sql injection
A vulnerability classified as critical was found in deerwms deer-wms-2 up to 3.3. This vulnerability affects unknown code of the file /system/user/list. The manipulation of the argument params[dataScope] leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed toβ¦
9.8
CVE-2019-25224 - WP Database Backup < 5.2 - Unauthenticated OS Command Injection
The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldump function. This vulnerability allows unauthenticated attackers to execute arbitrary commands on the host operating system.
9.8
CVE-2015-10143 - Platform < 1.4.4 - Missing Authorization to Unauthenticated Arbitrary Options Update
The Platform theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the *_ajax_save_options() function in all versions up to 1.4.4 (exclusive). This makes it possible for unauthenticated attackers to update aβ¦
8.8
CVE-2015-10144 - Responsive Thumbnail Slider < 1.0.1 - Authenticated (Subscriber+) Arbitrary File Upload
The Responsive Thumbnail Slider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type sanitization in the via the image uploader in versions up to 1.0.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary fβ¦
5.3
CVE-2025-8126 - deerwms deer-wms-2 export sql injection
A vulnerability classified as critical has been found in deerwms deer-wms-2 up to 3.3. This affects an unknown part of the file /system/user/export. The manipulation of the argument params[dataScope] leads to sql injection. It is possible to initiate the attack remotely. The exploit has been discloβ¦
5.3
CVE-2025-8125 - deerwms deer-wms-2 allocatedList sql injection
A vulnerability was found in deerwms deer-wms-2 up to 3.3. It has been rated as critical. Affected by this issue is some unknown functionality of the file /system/role/authUser/allocatedList. The manipulation of the argument params[dataScope] leads to sql injection. The attack may be launched remotβ¦
2
CVE-2025-0253 - HCL IEM is affected by a cookie attribute not set vulnerability
HCL IEM is affected by a cookie attribute not set vulnerability due to inconsistency of certain security-related configurations which could increase exposure to potential vulnerabilities.
2.6
CVE-2025-0252 - HCL IEM is affected by a password in cleartext vulnerability
HCL IEM is affected by a password in cleartext vulnerability.Β Sensitive information is transmitted without adequate protection, potentially exposing it to unauthorized access during transit.
2.6
CVE-2025-0251 - HCL IEM is affected by a concurrent login vulnerability
HCL IEM is affected by a concurrent login vulnerability.Β The application allows multiple concurrent sessions using the same user credentials, which may introduce security risks.