6.9

CVSS4.0

CVE-2025-5840 - SourceCodester Client Database Management System user_update_customer_order.php unrestricted upload

A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file /user_update_customer_order.php. The manipulation of the argument uploaded_file leads to unrestricted upload. It is possible to initiate the…

📅 Published: June 7, 2025, 6 p.m. 🔄 Last Modified: June 10, 2025, 3:45 p.m.

8.7

CVSS4.0

CVE-2025-5839 - Tenda AC9 POST Request AdvSetLanip fromadvsetlanip buffer overflow

A vulnerability, which was classified as critical, has been found in Tenda AC9 15.03.02.13. Affected by this issue is the function fromadvsetlanip of the file /goform/AdvSetLanip of the component POST Request Handler. The manipulation of the argument lanMask leads to buffer overflow. The attack may…

📅 Published: June 7, 2025, 5:31 p.m. 🔄 Last Modified: June 9, 2025, 7:07 p.m.

5.3

CVSS4.0

CVE-2025-5838 - PHPGurukul Employee Record Management System adminprofile.php sql injection

A vulnerability classified as critical was found in PHPGurukul Employee Record Management System 1.3. Affected by this vulnerability is an unknown functionality of the file /admin/adminprofile.php. The manipulation of the argument AdminName leads to sql injection. The attack can be launched remotel…

📅 Published: June 7, 2025, 4 p.m. 🔄 Last Modified: June 10, 2025, 2:56 p.m.

5.3

CVSS4.0

CVE-2025-5837 - PHPGurukul Employee Record Management System allemployees.php sql injection

A vulnerability classified as critical has been found in PHPGurukul Employee Record Management System 1.3. Affected is an unknown function of the file /admin/allemployees.php. The manipulation of the argument delid leads to sql injection. It is possible to launch the attack remotely. The exploit ha…

📅 Published: June 7, 2025, 2 p.m. 🔄 Last Modified: June 9, 2025, 7:07 p.m.

5.3

CVSS4.0

CVE-2025-5836 - Tenda AC9 POST Request SetIPTVCfg formSetIptv command injection

A vulnerability was found in Tenda AC9 15.03.02.13. It has been rated as critical. This issue affects the function formSetIptv of the file /goform/SetIPTVCfg of the component POST Request Handler. The manipulation of the argument list leads to command injection. The attack may be initiated remotely…

📅 Published: June 7, 2025, 1:31 p.m. 🔄 Last Modified: June 9, 2025, 7:07 p.m.

6.4

CVSS3.1

CVE-2024-9993 - Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= …

The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the eael_event_details_text parameter of Event Calendar Widget in all versions up to, and including, 6.1.12 due to insuffi…

📅 Published: June 7, 2025, 11:17 a.m. 🔄 Last Modified: April 8, 2026, 5:13 p.m.

6.4

CVSS3.1

CVE-2025-5568 - WpEvently <= 4.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

The WpEvently plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in all versions up to, and including, 4.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above…

📅 Published: June 7, 2025, 11:17 a.m. 🔄 Last Modified: April 8, 2026, 5:12 p.m.

6.1

CVSS3.1

CVE-2025-5528 - Social Sharing Plugin – Sassy Social Share <= 3.3.75 - Reflected Cross-Site Scripting via 'heateor_…

The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the heateor_mastodon_share parameter in all versions up to, and including, 3.3.75 due to insufficient input sanitization and output escaping. This makes it possible for unauthenti…

📅 Published: June 7, 2025, 11:17 a.m. 🔄 Last Modified: April 8, 2026, 5:10 p.m.

6.4

CVSS3.1

CVE-2024-9994 - Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= …

The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the eael_pricing_item_tooltip_content parameter of the Pricing Table Widget in all versions up to, and including, 6.1.12 d…

📅 Published: June 7, 2025, 11:17 a.m. 🔄 Last Modified: April 8, 2026, 5:04 p.m.

7.2

CVSS3.1

CVE-2025-5303 - LTL Freight Quotes – Freightview Edition <= 1.0.11, LTL Freight Quotes – Daylight Edition <=2.2.6 a…

The LTL Freight Quotes – Freightview Edition, LTL Freight Quotes – Daylight Edition and LTL Freight Quotes – Day & Ross Edition plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the expiry_date parameter in all versions up to, and including, 1.0.11, 2.2.6 and 2.1.10 respective…

📅 Published: June 7, 2025, 8:22 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 344963
Page 4704 of 34,497
« previous page » next page
Filters