5.1
CVE-2025-4006 - youyiio BeyongCms Document Management Page Upload.html unrestricted upload
A vulnerability classified as critical has been found in youyiio BeyongCms 1.6.0. Affected is an unknown function of the file /admin/theme/Upload.html of the component Document Management Page. The manipulation of the argument File leads to unrestricted upload. It is possible to launch the attack rβ¦
6.9
CVE-2025-4005 - PHPGurukul COVID19 Testing Management System patient-report.php sql injection
A vulnerability was found in PHPGurukul COVID19 Testing Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /patient-report.php. The manipulation of the argument searchdata leads to sql injection. The attack may be initiated remotely. The expβ¦
6.9
CVE-2025-4004 - PHPGurukul COVID19 Testing Management System password-recovery.php sql injection
A vulnerability was found in PHPGurukul COVID19 Testing Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /password-recovery.php. The manipulation of the argument username/contactno leads to sql injection. The attack can be initiated remoteβ¦
3.5
CVE-2025-0627 - AI Autotagger < 3.30.0 - Admin+ Stored XSS
The WordPress Tag, Category, and Taxonomy Manager WordPress plugin before 3.30.0 does not sanitise and escape some of its Widgets settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (foβ¦
3.5
CVE-2024-9771 - WP-Recall < 16.26.12 - Admin+ Stored XSS
The WP-Recall WordPress plugin before 16.26.12 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
5.3
CVE-2024-13688 - Admin and Site Enhancements (ASE) < 7.6.10 - Password Protection Bypass
The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 uses a hardcoded password in its Password Protection feature, allowing attacker to bypass the protection offered via a crafted request
6.8
CVE-2025-4003 - RefindPlusRepo RefindPlus RP_ApfsIo.c InternalApfsTranslateBlock null pointer dereference
A vulnerability was found in RefindPlusRepo RefindPlus 0.14.2.AB. It has been classified as problematic. This affects the function InternalApfsTranslateBlock of the file Library/RP_ApfsLib/RP_ApfsIo.c. The manipulation leads to null pointer dereference. It is possible to launch the attack on the loβ¦
6.8
CVE-2025-4002 - RefindPlusRepo RefindPlus BootLog.c GetDebugLogFile null pointer dereference
A vulnerability was found in RefindPlusRepo RefindPlus 0.14.2.AB and classified as problematic. Affected by this issue is the function GetDebugLogFile of the file Library/MemLogLib/BootLog.c. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The patch is identiβ¦
4.8
CVE-2025-4001 - scipopt scip File Descriptor genRandomLOPInstance.c main file descriptor consumption
A vulnerability has been found in scipopt scip up to 9.2.1 and classified as problematic. Affected by this vulnerability is the function main of the file examples/LOP/src/genRandomLOPInstance.c of the component File Descriptor Handler. The manipulation of the argument File leads to uncontrolled filβ¦
5.1
CVE-2025-4000 - Seeyon Zhiyuan OA Web Application System ssoproxy.jsp cross site scripting
A vulnerability, which was classified as problematic, was found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. Affected is an unknown function of the file seeyon\opt\Seeyon\A8\ApacheJetspeed\webapps\seeyon\ssoproxy\jsp\ssoproxy.jsp. The manipulation of the argument Name leads to cross site scβ¦