Vulnerabilities

Vulnerabilities

  

Ubuntu 7303-3: Linux kernel Security Advisory Updates

Several security issues were fixed in the Linux kernel.LinuxSecurity – Security AdvisoriesRead More

  

Ubuntu 7294-4: Linux kernel Security Advisory Updates

Several security issues were fixed in the Linux kernel.LinuxSecurity – Security AdvisoriesRead More

  

CVE-2025-1893 | Open5GS up to 2.7.2 UDM Subscriber Data Management src/amf/gmm-sm.c gmm_state_authentication denial of service (Issue 3707)

A vulnerability was found in Open5GS up to 2.7.2. It has been declared as problematic. Affected by this vulnerability is

  

CVE-2025-1894 | PHPGurukul Restaurant Table Booking System 1.0 /search-result.php searchdata sql injection

A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been rated as critical. Affected by this

  

CVE-2025-1895 | Tenda TX3 16.03.13.11_multi /goform/setMacFilterCfg deviceList buffer overflow

A vulnerability classified as critical has been found in Tenda TX3 16.03.13.11_multi. This affects an unknown part of the file

  

CVE-2025-1896 | Tenda TX3 16.03.13.11_multi SetStaticRouteCfg list buffer overflow

A vulnerability classified as critical was found in Tenda TX3 16.03.13.11_multi. This vulnerability affects unknown code of the file /goform/SetStaticRouteCfg.

  

CVE-2025-1897 | Tenda TX3 16.03.13.11_multi SetNetControlList list buffer overflow

A vulnerability, which was classified as critical, has been found in Tenda TX3 16.03.13.11_multi. This issue affects some unknown processing

  

CVE-2025-1898 | Tenda TX3 16.03.13.11_multi /goform/openSchedWifi schedStartTime/schedEndTime buffer overflow

A vulnerability, which was classified as critical, was found in Tenda TX3 16.03.13.11_multi. Affected is an unknown function of the

  

CVE-2025-1899 | Tenda TX3 16.03.13.11_multi /goform/setPptpUserList list buffer overflow

A vulnerability has been found in Tenda TX3 16.03.13.11_multi and classified as critical. Affected by this vulnerability is an unknown

  

CVE-2025-1900 | PHPGurukul Restaurant Table Booking System 1.0 /add-table.php tableno sql injection

A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0 and classified as critical. Affected by this issue is

  

CVE-2025-1901 | PHPGurukul Restaurant Table Booking System 1.0 check_availability.php username sql injection

A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been classified as critical. This affects an

  

CVE-2025-1902 | PHPGurukul Student Record System 3.2 /password-recovery.php emailid sql injection

A vulnerability was found in PHPGurukul Student Record System 3.2. It has been declared as critical. This vulnerability affects unknown

  

CVE-2025-1903 | Codezips Online Shopping Website 1.0 /cart_add.php id sql injection

A vulnerability was found in Codezips Online Shopping Website 1.0. It has been rated as critical. This issue affects some

  

CVE-2024-30154 | HCL SX 21 cross-site request forgery (KB0119437)

A vulnerability classified as problematic has been found in HCL SX 21. Affected is an unknown function. The manipulation leads

  

CVE-2025-26206 | StoreFront 1.0 index.html cross-site request forgery

A vulnerability classified as problematic was found in StoreFront 1.0. Affected by this vulnerability is an unknown functionality of the

  

CVE-2025-1904 | code-projects Blood Bank System 1.0 /Blood/A+.php Availibility cross site scripting

A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank System 1.0. Affected by this issue

  

CVE-2025-1905 | SourceCodester Employee Management System 1.0 employee.php Full Name cross site scripting

A vulnerability, which was classified as problematic, was found in SourceCodester Employee Management System 1.0. This affects an unknown part

  

CVE-2025-1906 | PHPGurukul Restaurant Table Booking System 1.0 /admin/profile.php mobilenumber sql injection

A vulnerability has been found in PHPGurukul Restaurant Table Booking System 1.0 and classified as critical. This vulnerability affects unknown

  

CVE-2025-25303 | ttop32 MouseTooltipTranslator up to 0.1.127 URL Parameter viewer.html server-side request forgery (GHSL-2024-018)

A vulnerability has been found in ttop32 MouseTooltipTranslator up to 0.1.127 and classified as critical. Affected by this vulnerability is

  

CVE-2025-27498 | RustCrypto AEADs up to 0.4.2 aes-gcm signature verification (GHSA-r38m-44fw-h886)

A vulnerability was found in RustCrypto AEADs up to 0.4.2 and classified as problematic. Affected by this issue is some

  

CVE-2024-53384 | tsup 8.3.4 cjs_shims.js document.currentScript Privilege Escalation

A vulnerability was found in tsup 8.3.4. It has been classified as problematic. This affects the function document.currentScript of the

  

CVE-2025-27370 | OpenID Connect up to 1.0 errata set 2 private_key_jwt authorization

A vulnerability was found in OpenID Connect up to 1.0 errata set 2. It has been declared as problematic. This

  

CVE-2023-49031 | Advanced eMarketing Platform 6.8.3.0 OpenLogFile Endpoint filename path traversal

A vulnerability was found in Advanced eMarketing Platform 6.8.3.0. It has been rated as critical. This issue affects some unknown

  

CVE-2024-53387 | umeditor 1.2.3 HTML Element HTML injection

A vulnerability classified as problematic has been found in umeditor 1.2.3. Affected is an unknown function of the component HTML

  

CVE-2024-53388 | mavo 0.3.2 HTML Element HTML injection

A vulnerability classified as problematic was found in mavo 0.3.2. Affected by this vulnerability is an unknown functionality of the

  

CVE-2025-27371 | OpenID Connect IETF OAuth 2.0 authorization

A vulnerability, which was classified as problematic, has been found in OpenID Connect. Affected by this issue is some unknown

  

CVE-2024-51091 | seajs 2.2.3 cross site scripting

A vulnerability, which was classified as problematic, was found in seajs 2.2.3. This affects an unknown part. The manipulation leads

  

CVE-2025-1890 | shishuocms 1.1 ManageUpLoadAction.java handleRequest file unrestricted upload

A vulnerability has been found in shishuocms 1.1 and classified as critical. This vulnerability affects the function handleRequest of the

  

CVE-2025-1891 | shishuocms 1.1 cross-site request forgery

A vulnerability was found in shishuocms 1.1 and classified as problematic. This issue affects some unknown processing. The manipulation leads

  

CVE-2025-1892 | shishuocms 1.1 Directory Deletion Page /manage/folder/add.json folderName cross site scripting

A vulnerability was found in shishuocms 1.1. It has been classified as problematic. Affected is an unknown function of the

  

CVE-2025-27417 | LabRedesCefetRJ WeGIA up to 3.2.15 adicionar_status_atendido.php status cross site scripting

A vulnerability, which was classified as problematic, has been found in LabRedesCefetRJ WeGIA up to 3.2.15. This issue affects some

  

CVE-2025-27418 | LabRedesCefetRJ WeGIA up to 3.2.15 adicionar_tipo_atendido.php tipo cross site scripting

A vulnerability, which was classified as problematic, was found in LabRedesCefetRJ WeGIA up to 3.2.15. Affected is an unknown function

  

CVE-2025-0555 | GitLab-EE up to 17.7.5/17.8.3/17.9.0 cross site scripting

A vulnerability has been found in GitLab-EE up to 17.7.5/17.8.3/17.9.0 and classified as problematic. Affected by this vulnerability is an

  

CVE-2025-27275 | andrew_fisher WOO Codice Fiscale Plugin up to 1.6.3 on WordPress cross site scripting

A vulnerability was found in andrew_fisher WOO Codice Fiscale Plugin up to 1.6.3 on WordPress and classified as problematic. Affected

  

CVE-2025-27273 | winking Affiliate Links Manager Plugin up to 1.0 on WordPress cross site scripting

A vulnerability was found in winking Affiliate Links Manager Plugin up to 1.0 on WordPress. It has been classified as

  

CVE-2025-27279 | Flashfader Plugin up to 1.1.1 on WordPress cross site scripting

A vulnerability was found in Flashfader Plugin up to 1.1.1 on WordPress. It has been declared as problematic. This vulnerability

  

CVE-2025-27278 | AcuGIS Leaflet Maps Plugin up to 5.1.1.0 on WordPress cross site scripting

A vulnerability was found in AcuGIS Leaflet Maps Plugin up to 5.1.1.0 on WordPress. It has been rated as problematic.

  

CVE-2025-27274 | GPX Viewer Plugin up to 2.2.11 on WordPress path traversal

A vulnerability classified as problematic has been found in GPX Viewer Plugin up to 2.2.11 on WordPress. Affected is an

  

CVE-2025-23552 | Texteller Plugin up to 1.3.0 on WordPress cross site scripting

A vulnerability classified as problematic was found in Texteller Plugin up to 1.3.0 on WordPress. Affected by this vulnerability is

  

CVE-2025-23496 | WP FPO Plugin up to 1.0 on WordPress cross site scripting

A vulnerability, which was classified as problematic, has been found in WP FPO Plugin up to 1.0 on WordPress. Affected

  

CVE-2025-27420 | LabRedesCefetRJ WeGIA up to 3.2.15 atendido_parentesco_adicionar.php descricao cross site scripting (GHSA-x3wr-75qx-55cw)

A vulnerability, which was classified as problematic, was found in LabRedesCefetRJ WeGIA up to 3.2.15. This affects an unknown part

  

CVE-2025-27421 | JasonLovesDoggo Abacus up to 1.3.x /stream resource consumption

A vulnerability has been found in JasonLovesDoggo Abacus up to 1.3.x and classified as problematic. This vulnerability affects unknown code

  

CVE-2025-27422 | factionsecurity faction up to 1.4.2 improper authentication

A vulnerability was found in factionsecurity faction up to 1.4.2 and classified as critical. This issue affects some unknown processing.

  

CVE-2025-25301 | danielgatis rembg up to 2.0.57 Query Parameter /api/remove server-side request forgery (GHSL-2024-161)

A vulnerability was found in danielgatis rembg up to 2.0.57. It has been classified as critical. Affected is an unknown

  

CVE-2024-55570 | Cubro EXA48200 Network Packet Broker 20231025055018 HTTP PUT Request /api/user/users access control

A vulnerability was found in Cubro EXA48200 Network Packet Broker 20231025055018. It has been declared as critical. Affected by this

  

CVE-2025-27419 | LabRedesCefetRJ WeGIA up to 3.2.15 allocation of resources (GHSA-9rp6-4mqp-g4p8)

A vulnerability was found in LabRedesCefetRJ WeGIA up to 3.2.15. It has been rated as problematic. Affected by this issue

  

CVE-2025-27423 | Vim up to 9.1.1163 Tar command injection

A vulnerability classified as critical has been found in Vim up to 9.1.1163. This affects an unknown part of the

  

CVE-2025-25302 | danielgatis rembg up to 2.0.57 origin validation (GHSL-2024-161)

A vulnerability classified as problematic was found in danielgatis rembg up to 2.0.57. This vulnerability affects unknown code. The manipulation

  

CVE-2024-57240 | Apryse WebViewer up to 11.1 Rendering Engine cross site scripting

A vulnerability, which was classified as problematic, has been found in Apryse WebViewer up to 11.1. This issue affects some

  

CVE-2025-1695 | F5 NGINX Unit up to 1.34.1 Java Language Module infinite loop (K000149959)

A vulnerability, which was classified as problematic, was found in F5 NGINX Unit up to 1.34.1. Affected is an unknown

  

CVE-2025-26999 | Metagauss ProfileGrid Plugin up to 5.9.4.3 on WordPress deserialization

A vulnerability was found in Metagauss ProfileGrid Plugin up to 5.9.4.3 on WordPress and classified as critical. Affected by this

  

CVE-2025-25158 | Uncomplicated SEO Plugin up to 1.2 on WordPress cross site scripting

A vulnerability was found in Uncomplicated SEO Plugin up to 1.2 on WordPress. It has been classified as problematic. This

  

CVE-2025-25161 | WP Find Your Nearest Plugin up to 0.3.1 on WordPress cross site scripting

A vulnerability was found in WP Find Your Nearest Plugin up to 0.3.1 on WordPress. It has been declared as

  

CVE-2025-25129 | Callback Request Plugin up to 1.4 on WordPress cross site scripting

A vulnerability was found in Callback Request Plugin up to 1.4 on WordPress. It has been rated as problematic. This

  

CVE-2025-25164 | Meta Accelerator Plugin up to 1.0.4 on WordPress cross site scripting

A vulnerability classified as problematic has been found in Meta Accelerator Plugin up to 1.0.4 on WordPress. Affected is an

  

CVE-2025-25169 | Authors Autocomplete Meta Box Plugin up to 1.2 on WordPress cross site scripting

A vulnerability classified as problematic was found in Authors Autocomplete Meta Box Plugin up to 1.2 on WordPress. Affected by

  

CVE-2025-25118 | Top Bar Plugin up to 2.0.8 on WordPress cross site scripting

A vulnerability, which was classified as problematic, has been found in Top Bar Plugin up to 2.0.8 on WordPress. Affected

  

CVE-2025-25185 | binary-husky gpt_academic up to 3.91 link following

A vulnerability, which was classified as critical, was found in binary-husky gpt_academic up to 3.91. This affects an unknown part.

  

CVE-2025-25124 | devu Status Updater Plugin up to 1.9.2 on WordPress cross site scripting

A vulnerability has been found in devu Status Updater Plugin up to 1.9.2 on WordPress and classified as problematic. This

  

CVE-2025-25121 | Theme Options Z Plugin up to 1.4 on WordPress cross site scripting

A vulnerability was found in Theme Options Z Plugin up to 1.4 on WordPress and classified as problematic. This issue

  

CVE-2025-27270 | Residential Address Detection Plugin up to 2.5.4 on WordPress authorization

A vulnerability was found in Residential Address Detection Plugin up to 2.5.4 on WordPress. It has been classified as critical.

  

CVE-2025-25115 | Like Dislike Plus Counter Plugin up to 1.0 on WordPress cross site scripting

A vulnerability was found in Like Dislike Plus Counter Plugin up to 1.0 on WordPress. It has been declared as

  

CVE-2025-26967 | Stiofan Events Calendar for GeoDirectory Plugin up to 2.3.14 on WordPress deserialization

A vulnerability was found in Stiofan Events Calendar for GeoDirectory Plugin up to 2.3.14 on WordPress. It has been rated

  

CVE-2025-23493 | Google Transliteration Plugin up to 1.7.2 on WordPress cross site scripting

A vulnerability classified as problematic has been found in Google Transliteration Plugin up to 1.7.2 on WordPress. This affects an

  

CVE-2025-27269 | .htaccess Login block Plugin up to 0.9a on WordPress cross site scripting

A vulnerability classified as problematic was found in .htaccess Login block Plugin up to 0.9a on WordPress. This vulnerability affects

  

CVE-2025-27271 | DB Tables Import Export Plugin up to 1.0.1 on WordPress cross site scripting

A vulnerability, which was classified as problematic, has been found in DB Tables Import Export Plugin up to 1.0.1 on

  

CVE-2025-23517 | Google Map on Post Page Plugin up to 1.1 on WordPress cross site scripting

A vulnerability, which was classified as problematic, was found in Google Map on Post Page Plugin up to 1.1 on

  

CVE-2025-24023 | dpgaspar Flask-AppBuilder up to 4.5.2 observable response discrepancy

A vulnerability has been found in dpgaspar Flask-AppBuilder up to 4.5.2 and classified as problematic. Affected by this vulnerability is

  

CVE-2025-26994 | softdiscover Zigaform Plugin up to 7.4.2 on WordPress cross site scripting

A vulnerability was found in softdiscover Zigaform Plugin up to 7.4.2 on WordPress and classified as problematic. Affected by this

  

CVE-2025-23556 | Push Envoy Notifications Plugin up to 1.0.0 on WordPress cross site scripting

A vulnerability was found in Push Envoy Notifications Plugin up to 1.0.0 on WordPress. It has been classified as problematic.

  

CVE-2025-23635 | mobde3net ePermissions Plugin up to 1.2 on WordPress cross site scripting

A vulnerability was found in mobde3net ePermissions Plugin up to 1.2 on WordPress and classified as problematic. Affected by this

  

CVE-2025-23585 | CantonBolo Goo.gl Url Shorter Plugin up to 1.0.1 on WordPress cross site scripting

A vulnerability was found in CantonBolo Goo.gl Url Shorter Plugin up to 1.0.1 on WordPress. It has been classified as

  

CVE-2025-23616 | Canalplan Plugin up to 5.31 on WordPress cross site scripting

A vulnerability was found in Canalplan Plugin up to 5.31 on WordPress. It has been declared as problematic. This vulnerability

  

CVE-2025-23473 | Killer Theme Options Plugin up to 2.0 on WordPress cross site scripting

A vulnerability, which was classified as problematic, was found in Killer Theme Options Plugin up to 2.0 on WordPress. This

  

CVE-2025-23613 | WP Journal Plugin up to 1.1 on WordPress authorization

A vulnerability was found in WP Journal Plugin up to 1.1 on WordPress. It has been rated as problematic. This

  

CVE-2025-23584 | Pin Locations on Map Plugin up to 1.0 on WordPress cross site scripting

A vulnerability classified as problematic has been found in Pin Locations on Map Plugin up to 1.0 on WordPress. Affected

  

CVE-2025-23619 | Catch Duplicate Switcher Plugin up to 2.0 on WordPress cross site scripting

A vulnerability classified as problematic was found in Catch Duplicate Switcher Plugin up to 2.0 on WordPress. Affected by this

  

CVE-2025-23586 | WP Post Category Notifications Plugin up to 1.0 on WordPress cross site scripting

A vulnerability, which was classified as problematic, has been found in WP Post Category Notifications Plugin up to 1.0 on

  

CVE-2025-23663 | Adrian Vaquez Contexto Plugin up to 1.0 on WordPress cross site scripting

A vulnerability, which was classified as problematic, was found in Adrian Vaquez Contexto Plugin up to 1.0 on WordPress. This

  

CVE-2025-23478 | Photo Video Store Plugin up to 21.07 on WordPress cross site scripting

A vulnerability has been found in Photo Video Store Plugin up to 21.07 on WordPress and classified as problematic. This

  

CVE-2025-23600 | pinal.shah Send to a Friend Addon Plugin up to 1.4.1 on WordPress cross site scripting

A vulnerability has been found in pinal.shah Send to a Friend Addon Plugin up to 1.4.1 on WordPress and classified

  

CVE-2025-23433 | jnwry vcOS Plugin up to 1.4.0 on WordPress cross site scripting

A vulnerability was found in jnwry vcOS Plugin up to 1.4.0 on WordPress and classified as problematic. This issue affects

  

CVE-2025-23446 | WP SpaceContent Plugin up to 0.4.5 on WordPress cross-site request forgery

A vulnerability was found in WP SpaceContent Plugin up to 0.4.5 on WordPress. It has been classified as problematic. Affected

  

CVE-2024-47092 | Checkmk Exchange Plugin up to 5.8.0 deserialization

A vulnerability was found in Checkmk Exchange Plugin up to 5.8.0 and classified as problematic. This issue affects some unknown

  

CVE-2025-23670 | 4 author cheer up donate Plugin up to 1.3 on WordPress cross site scripting

A vulnerability was found in 4 author cheer up donate Plugin up to 1.3 on WordPress. It has been classified

  

CVE-2025-23829 | Woo Update Variations In Cart Plugin up to 0.0.9 on WordPress cross site scripting

A vulnerability was found in Woo Update Variations In Cart Plugin up to 0.0.9 on WordPress. It has been declared

  

CVE-2025-23762 | DsgnWrks Twitter Importer Plugin up to 1.1.4 on WordPress cross site scripting

A vulnerability was found in DsgnWrks Twitter Importer Plugin up to 1.1.4 on WordPress. It has been rated as problematic.

  

CVE-2025-23852 | First Comment Redirect Plugin up to 1.0.3 on WordPress cross site scripting

A vulnerability classified as problematic has been found in First Comment Redirect Plugin up to 1.0.3 on WordPress. This affects

  

CVE-2025-23850 | Mojo Under Construction Plugin up to 1.1.2 on WordPress cross site scripting

A vulnerability classified as problematic was found in Mojo Under Construction Plugin up to 1.1.2 on WordPress. This vulnerability affects

  

CVE-2025-23741 | Notifications Center Plugin up to 1.5.2 on WordPress cross site scripting

A vulnerability, which was classified as problematic, has been found in Notifications Center Plugin up to 1.5.2 on WordPress. This

  

CVE-2025-1876 | D-Link DAP-1562 1.10 HTTP Header http_request_parse Authorization stack-based overflow

A vulnerability, which was classified as critical, has been found in D-Link DAP-1562 1.10. Affected by this issue is the

  

CVE-2025-1877 | D-Link DAP-1562 1.10 HTTP POST Request pure_auth_check a1 null pointer dereference

A vulnerability, which was classified as critical, was found in D-Link DAP-1562 1.10. This affects the function pure_auth_check of the

  

CVE-2025-1878 | i-Drive i11/i12 up to 20250227 WiFi default password

A vulnerability has been found in i-Drive i11 and i12 up to 20250227 and classified as problematic. This vulnerability affects

  

CVE-2025-1879 | i-Drive i11/i12 up to 20250227 APK hard-coded credentials

A vulnerability was found in i-Drive i11 and i12 up to 20250227 and classified as problematic. This issue affects some

  

CVE-2025-1880 | i-Drive i11/i12 up to 20250227 Device Pairing authentication bypass

A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been classified as problematic. Affected is

  

CVE-2025-1881 | i-Drive i11/i12 up to 20250227 Video Footage/Live Video Stream access control

A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been declared as problematic. Affected by

  

CVE-2025-1882 | i-Drive i11/i12 up to 20250227 Device Setting improper access control for register interface

A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been rated as critical. Affected by

  

CVE-2024-56325 | Apache Pinot up to 1.2.x AuthenticationFilter neutralization

A vulnerability classified as critical has been found in Apache Pinot up to 1.2.x. This affects the function AuthenticationFilter. The

  

CVE-2025-1867 | ithewei libhv up to 1.3.3 request smuggling

A vulnerability was found in ithewei libhv up to 1.3.3 and classified as critical. Affected by this issue is some

  

CVE-2025-25280 | Century Systems FutureNet FA-215 buffer overflow

A vulnerability was found in Century Systems FutureNet AS-250 S, FutureNet AS-250 F-SC, FutureNet AS-250 F-KO, FutureNet AS-250 NL, FutureNet