4.3
CVE-2025-0476 - Mobile crash via file with specially crafted filename
Mattermost Mobile Apps versions <=2.22.0 fail to properly handle specially crafted attachment names, which allows an attacker to crash the mobile app for any user who opened a channel containing the specially crafted attachment
6.1
CVE-2025-0215 - UpdraftPlus - Backup/Restore <= 1.24.12 - Reflected Cross-Site Scripting
The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the showdata and initiate_restore parameters in all versions up to, and including, 1.24.12 due to insufficient input sanitization and output escaping. This makes it possible for unβ¦
8.7
CVE-2025-0492 - D-Link DIR-823X FUN_00412244 null pointer dereference
A vulnerability has been found in D-Link DIR-823X 240126/240802 and classified as critical. Affected by this vulnerability is the function FUN_00412244. The manipulation leads to null pointer dereference. The attack can be launched remotely. The exploit has been disclosed to the public and may be uβ¦
5.3
CVE-2025-0491 - Fanli2012 native-php-cms cat_dodel.php sql injection
A vulnerability, which was classified as critical, was found in Fanli2012 native-php-cms 1.0. Affected is an unknown function of the file /fladmin/cat_dodel.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed β¦
5.3
CVE-2025-0490 - Fanli2012 native-php-cms article_dodel.php sql injection
A vulnerability, which was classified as critical, has been found in Fanli2012 native-php-cms 1.0. This issue affects some unknown processing of the file /fladmin/article_dodel.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has beeβ¦
5.3
CVE-2025-0489 - Fanli2012 native-php-cms friendlink_dodel.php sql injection
A vulnerability classified as critical was found in Fanli2012 native-php-cms 1.0. This vulnerability affects unknown code of the file /fladmin/friendlink_dodel.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to thβ¦
5.3
CVE-2025-0488 - Fanli2012 native-php-cms product_list.php sql injection
A vulnerability classified as critical has been found in Fanli2012 native-php-cms 1.0. This affects an unknown part of the file product_list.php. The manipulation of the argument cat leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the publicβ¦
5.3
CVE-2025-0487 - Fanli2012 native-php-cms cat_edit.php sql injection
A vulnerability was found in Fanli2012 native-php-cms 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /fladmin/cat_edit.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disβ¦
6.9
CVE-2025-0486 - Fanli2012 native-php-cms login.php sql injection
A vulnerability was found in Fanli2012 native-php-cms 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /fladmin/login.php. The manipulation of the argument username leads to sql injection. The attack can be launched remotely. The exploit β¦
5.3
CVE-2025-0485 - Fanli2012 native-php-cms sysconfig_doedit.php cross site scripting
A vulnerability was found in Fanli2012 native-php-cms 1.0. It has been classified as problematic. Affected is an unknown function of the file /fladmin/sysconfig_doedit.php. The manipulation of the argument info leads to cross site scripting. It is possible to launch the attack remotely. The exploitβ¦