Vulnerabilities

Vulnerabilities

  

CVE-2025-7514 | code-projects Modern Bag 1.0 /admin/contact-list.php idStatus sql injection

A vulnerability was found in code-projects Modern Bag 1.0. It has been rated as critical. Affected by this issue is

  

C-Based Automated Login Analyzer with CSRF Token Extraction for SSO bmi.ir Systems

Topic: C-Based Automated Login Analyzer with CSRF Token Extraction for SSO bmi.ir Systems Risk: Low Text:This C-based proof-of-concept automates login

  

Discourse 3.2.x Anonymous Cache Poisoning

Topic: Discourse 3.2.x Anonymous Cache Poisoning Risk: Low Text:#!/usr/bin/env python3 “”” Exploit Title: Discourse 3.2.x – Anonymous Cache Poisoning Date:

  

CVE-2023-38329 | eGroupWare 17.1.20190111 GET Parameter calendar/freebusy.php User cross site scripting

A vulnerability was found in eGroupWare 17.1.20190111. It has been rated as problematic. This issue affects some unknown processing of

  

CVE-2025-53642 | haxcms-nodejs.operations/haxcms-php.operations prior 11.0.6 Refresh Token logout session expiration (GHSA-g4f5-5w5j-p5jg)

A vulnerability was found in haxcms-nodejs.operations and haxcms-php.operations. It has been declared as problematic. This vulnerability affects the function Logout

  

CVE-2025-52986 | Juniper Junos OS/Junos OS Evolved Routing Protocol memory leak (JSA100092)

A vulnerability was found in Juniper Junos OS and Junos OS Evolved. It has been classified as problematic. This affects

  

CVE-2025-52963 | Juniper Junos OS up to 24.4R1-S3 User Interface access control (JSA100078)

A vulnerability was found in Juniper Junos OS up to 24.4R1-S3 and classified as critical. Affected by this issue is

  

CVE-2025-52947 | Juniper Junos OS up to 21.2R3-S8 on ACX exceptional condition (JSA100051)

A vulnerability has been found in Juniper Junos OS up to 21.2R3-S8 on ACX and classified as critical. Affected by

  

CVE-2025-52994 | phpThumb up to 1.7.23 Parameter phpthumb.gif.php gif_outputAsJpeg os command injection

A vulnerability has been found in phpThumb up to 1.7.23 and classified as critical. This vulnerability affects the function gif_outputAsJpeg

  

CVE-2025-52089 | TOTOLINK N300RB 8.54 backdoor

A vulnerability, which was classified as critical, was found in TOTOLINK N300RB 8.54. This affects an unknown part. The manipulation

  

CVE-2024-47065 | Meshtastic Firmware up to 2.5.0 Traceroute_APP Response improper control of interaction frequency (GHSA-4hjx-54gf-2jh7)

A vulnerability, which was classified as critical, has been found in Meshtastic Firmware up to 2.5.0. Affected by this issue

  

CVE-2025-52950 | Juniper Security Director 24.4.1 authorization (JSA100054)

A vulnerability classified as problematic was found in Juniper Security Director 24.4.1. Affected by this vulnerability is an unknown functionality.

  

CVE-2025-48924 | Apache Commons Lang up to 2.6/3.17.x ClassUtils.getClass recursion

A vulnerability classified as problematic has been found in Apache Commons Lang up to 2.6/3.17.x. Affected is the function ClassUtils.getClass.

  

CVE-2025-53641 | gitroomhq postiz-app up to 1.62.2 Outbound Request server-side request forgery (GHSA-48c8-25jq-m55f)

A vulnerability was found in gitroomhq postiz-app up to 1.62.2. It has been declared as critical. Affected by this vulnerability

  

CVE-2025-43856 | immich up to 1.131.x /user-settings incorrect implementation of authentication algorithm (GHSA-3832-6r8h-9cfm)

A vulnerability was found in immich up to 1.131.x. It has been classified as critical. Affected is an unknown function

  

CVE-2025-30402 | PyTorch ExecuTorch heap-based overflow

A vulnerability was found in PyTorch and classified as critical. This issue affects the function ExecuTorch. The manipulation leads to

  

CVE-2025-6057 | WPBookit Plugin up to 1.0.4 on WordPress handle_image_upload unrestricted upload

A vulnerability has been found in WPBookit Plugin up to 1.0.4 on WordPress and classified as critical. Affected by this

  

CVE-2025-6058 | WPBookit Plugin up to 1.0.4 on WordPress image_upload_handle unrestricted upload

A vulnerability, which was classified as critical, was found in WPBookit Plugin up to 1.0.4 on WordPress. Affected is the

  

CVE-2025-7029 | GIGABYTE UEFI-OverClockSmiHandler 1.0.0 Software SMI SwSmiInputValue untrusted pointer dereference

A vulnerability, which was classified as critical, has been found in GIGABYTE UEFI-OverClockSmiHandler 1.0.0. This issue affects the function SwSmiInputValue

  

CVE-2025-7028 | GIGABYTE UEFI-SmiFlash 1.0.0 Software SMI SwSmiInputValue untrusted pointer dereference

A vulnerability classified as critical was found in GIGABYTE UEFI-SmiFlash 1.0.0. This vulnerability affects the function SwSmiInputValue of the component

  

CVE-2025-7027 | GIGABYTE UEFI-GenericComponentSmmEntry 1.0.0 Software SMI SwSmiInputValue untrusted pointer dereference

A vulnerability classified as critical has been found in GIGABYTE UEFI-GenericComponentSmmEntry 1.0.0. This affects the function SwSmiInputValue of the component

  

CVE-2025-7026 | GIGABYTE UEFI-GenericComponentSmmEntry 1.0.0 Software SMI SwSmiInputValue untrusted pointer dereference

A vulnerability was found in GIGABYTE UEFI-GenericComponentSmmEntry 1.0.0. It has been rated as critical. Affected by this issue is the

  

CVE-2025-1313 | Nokri Plugin up to 1.6.3 on WordPress privilege escalation

A vulnerability was found in Nokri Plugin up to 1.6.3 on WordPress and classified as critical. Affected by this issue

  

CVE-2025-7488 | JoeyBling SpringBoot_MyBatisPlus up to a6a825513bd688f717dbae3a196bc9c9622fea26 /file/download Name path traversal (Issue 18)

A vulnerability has been found in JoeyBling SpringBoot_MyBatisPlus up to a6a825513bd688f717dbae3a196bc9c9622fea26 and classified as critical. This vulnerability affects the function

  

CVE-2025-7487 | JoeyBling SpringBoot_MyBatisPlus up to a6a825513bd688f717dbae3a196bc9c9622fea26 /file/upload SysFileController portraitFile unrestricted upload (Issue 19)

A vulnerability, which was classified as critical, was found in JoeyBling SpringBoot_MyBatisPlus up to a6a825513bd688f717dbae3a196bc9c9622fea26. This affects the function SysFileController

  

CVE-2025-51591 | JGM Pandoc 3.6.4 iFrame server-side request forgery (EUVD-2025-21134)

A vulnerability, which was classified as critical, has been found in JGM Pandoc 3.6.4. Affected by this issue is some

  

CVE-2025-7491 | PHPGurukul Vehicle Parking Management System 1.13 manage-outgoingvehicle.php del sql injection

A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13. It has been declared as critical. Affected by this

  

CVE-2025-7490 | PHPGurukul Vehicle Parking Management System 1.13 /admin/reg-users.php del sql injection

A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13. It has been classified as critical. Affected is an

  

CVE-2025-7489 | PHPGurukul Vehicle Parking Management System 1.13 search-vehicle.php searchdata sql injection

A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13 and classified as critical. This issue affects some unknown

  

CVE-2025-7492 | PHPGurukul Vehicle Parking Management System 1.13 manage-incomingvehicle.php del sql injection

A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13. It has been rated as critical. Affected by this

  

CVE-2025-7470 | Campcodes Sales and Inventory System 1.0 /pages/product_add.php image unrestricted upload

A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been classified as critical. Affected is an

  

CVE-2025-7469 | Campcodes Sales and Inventory System 1.0 /pages/product_add.php prod_name sql injection

A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. This issue affects some unknown

  

CVE-2025-7474 | code-projects Job Diary 1.0 /search.php Search sql injection

A vulnerability was found in code-projects Job Diary 1.0. It has been rated as critical. Affected by this issue is

  

CVE-2025-7471 | code-projects Modern Bag 1.0 /admin/login-back.php user-name sql injection

A vulnerability was found in code-projects Modern Bag 1.0. It has been declared as critical. Affected by this vulnerability is

  

CVE-2025-7476 | code-projects Simple Car Rental System 1.0 /admin/approve.php ID sql injection

A vulnerability classified as critical was found in code-projects Simple Car Rental System 1.0. This vulnerability affects unknown code of

  

CVE-2025-7475 | code-projects Simple Car Rental System 1.0 /pay.php mpesa sql injection

A vulnerability classified as critical has been found in code-projects Simple Car Rental System 1.0. This affects an unknown part

  

CVE-2025-7478 | code-projects Modern Bag 1.0 /admin/category-list.php idCate sql injection

A vulnerability, which was classified as critical, was found in code-projects Modern Bag 1.0. Affected is an unknown function of

  

CVE-2025-7477 | code-projects Simple Car Rental System 1.0 /admin/add_cars.php image unrestricted upload

A vulnerability, which was classified as critical, has been found in code-projects Simple Car Rental System 1.0. This issue affects

  

CVE-2025-7481 | PHPGurukul Vehicle Parking Management System 1.13 /users/profile.php firstname sql injection

A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13. It has been classified as critical. This affects an

  

CVE-2025-7480 | PHPGurukul Vehicle Parking Management System 1.13 /users/signup.php email sql injection

A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13 and classified as critical. Affected by this issue is

  

CVE-2025-7479 | PHPGurukul Vehicle Parking Management System 1.13 /users/view–detail.php viewid sql injection

A vulnerability has been found in PHPGurukul Vehicle Parking Management System 1.13 and classified as critical. Affected by this vulnerability

  

CVE-2025-7483 | PHPGurukul Vehicle Parking Management System 1.13 forgot-password.php email sql injection

A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13. It has been rated as critical. This issue affects

  

CVE-2025-7482 | PHPGurukul Vehicle Parking Management System 1.13 /users/print.php vid sql injection

A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13. It has been declared as critical. This vulnerability affects

  

CVE-2025-7484 | PHPGurukul Vehicle Parking Management System 1.13 view-outgoingvehicle-detail.php viewid sql injection

A vulnerability classified as critical has been found in PHPGurukul Vehicle Parking Management System 1.13. Affected is an unknown function

  

CVE-2025-7485 | Open5GS up to 2.7.3 SCTP Partial Message ngap_recv_handler/s1ap_recv_handler/recv_handler assertion (Issue 3878)

A vulnerability classified as problematic was found in Open5GS up to 2.7.3. Affected by this vulnerability is the function ngap_recv_handler/s1ap_recv_handler/recv_handler

  

CVE-2025-50121 | Schneider Electric EcoStruxure IT Data Center Expert Web Interface os command injection (SEVD-2025-189-01 / EUVD-2025-21128)

A vulnerability was found in Schneider Electric EcoStruxure IT Data Center Expert. It has been classified as critical. Affected is

  

CVE-2025-3933 | huggingface transformers up to 4.52.0 API Service token2json redos (EUVD-2025-21126)

A vulnerability was found in huggingface transformers up to 4.52.0 and classified as problematic. This issue affects the function token2json

  

CVE-2025-50123 | Schneider Electric EcoStruxure IT Data Center Expert code injection (SEVD-2025-189-01 / EUVD-2025-21130)

A vulnerability was found in Schneider Electric EcoStruxure IT Data Center Expert. It has been rated as critical. Affected by

  

CVE-2025-50122 | Schneider Electric EcoStruxure IT Data Center Expert Installation/Upgrade entropy (SEVD-2025-189-01 / EUVD-2025-21127)

A vulnerability was found in Schneider Electric EcoStruxure IT Data Center Expert. It has been declared as problematic. Affected by

  

CVE-2025-7459 | code-projects Mobile Shop 1.0 /EditMobile.php ID sql injection

A vulnerability classified as critical was found in code-projects Mobile Shop 1.0. This vulnerability affects unknown code of the file

  

CVE-2025-6438 | Schneider Electric EcoStruxure IT Data Center Expert SOAP API xml external entity reference (SEVD-2025-189-01 / EUVD-2025-21129)

A vulnerability classified as problematic has been found in Schneider Electric EcoStruxure IT Data Center Expert. This affects an unknown

  

CVE-2025-50125 | Schneider Electric EcoStruxure IT Data Center Expert Header Host server-side request forgery (SEVD-2025-189-01)

A vulnerability, which was classified as critical, was found in Schneider Electric EcoStruxure IT Data Center Expert. Affected is an

  

CVE-2025-50124 | Schneider Electric EcoStruxure IT Data Center Expert privileges management (SEVD-2025-189-01)

A vulnerability, which was classified as critical, has been found in Schneider Electric EcoStruxure IT Data Center Expert. This issue

  

CVE-2025-7461 | code-projects Modern Bag 1.0 /action.php proId sql injection

A vulnerability was found in code-projects Modern Bag 1.0 and classified as critical. Affected by this issue is some unknown

  

CVE-2025-7460 | TOTOLINK T6 4.1.5cu.748_B20211015 HTTP POST Request /cgi-bin/cstecgi.cgi setWiFiAclRules mac buffer overflow

A vulnerability has been found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical. Affected by this vulnerability is the function

  

CVE-2025-6788 | Schneider Electric EcoStruxure Power Monitoring Expert TGML Diagram exposure of resource (SEVD-2025-189-04)

A vulnerability was found in Schneider Electric EcoStruxure Power Monitoring Expert and EcoStruxure Power Operation Advanced Reporting and Dashboards Module.

  

CVE-2025-7463 | Tenda FH1201 1.2.0.14 HTTP POST Request /goform/AdvSetWrlsafeset formWrlsafeset mit_ssid buffer overflow

A vulnerability was found in Tenda FH1201 1.2.0.14. It has been declared as critical. This vulnerability affects the function formWrlsafeset

  

CVE-2025-7462 | Artifex GhostPDL up to 3989415a5b8e99b9d1b87cc9902bde9b7cdea145 New Output File Open Error devices/vector/gdevpdf.c pdf_ferror null pointer dereference (619a106ba4c4)

A vulnerability was found in Artifex GhostPDL up to 3989415a5b8e99b9d1b87cc9902bde9b7cdea145. It has been classified as problematic. This affects the function

  

CVE-2025-7465 | Tenda FH1201 1.2.0.14 HTTP POST Request /goform/fromRouteStatic page buffer overflow

A vulnerability classified as critical was found in Tenda FH1201 1.2.0.14. Affected by this vulnerability is the function fromRouteStatic of

  

CVE-2025-7464 | osrg GoBGP up to 3.37.0 pkg/packet/rtr/rtr.go SplitRTR out-of-bounds

A vulnerability classified as problematic has been found in osrg GoBGP up to 3.37.0. Affected is the function SplitRTR of

  

CVE-2025-7466 | 1000projects ABC Courier Management 1.0 /add_dealerrequest.php Name sql injection

A vulnerability, which was classified as critical, has been found in 1000projects ABC Courier Management 1.0. Affected by this issue

  

CVE-2025-7467 | code-projects Modern Bag 1.0 /product-detail.php ID sql injection

A vulnerability, which was classified as critical, was found in code-projects Modern Bag 1.0. This affects an unknown part of

  

CVE-2025-7468 | Tenda FH1201 1.2.0.14 HTTP POST Request fromSafeUrlFilter page buffer overflow

A vulnerability has been found in Tenda FH1201 1.2.0.14 and classified as critical. This vulnerability affects the function fromSafeUrlFilter of

  

CVE-2025-7452 | kone-net go-chat up to f9e58d0afa9bbdb31faf25e7739da330692c4c63 Endpoint file_controller.go GetFile fileName path traversal (Issue 14)

A vulnerability was found in kone-net go-chat up to f9e58d0afa9bbdb31faf25e7739da330692c4c63. It has been declared as critical. This vulnerability affects the

  

CVE-2025-7450 | letseeqiji gorobbs up to 1.0.8 API user.go ResetUserAvatar filename path traversal (Issue 18)

A vulnerability was found in letseeqiji gorobbs up to 1.0.8. It has been classified as critical. This affects the function

  

CVE-2025-7454 | Campcodes Online Movie Theater Seat Reservation System 1.0 manage_theater.php ID sql injection

A vulnerability classified as critical has been found in Campcodes Online Movie Theater Seat Reservation System 1.0. Affected is an

  

CVE-2025-7453 | saltbo zpan up to 1.6.5/1.7.0-beta2 JSON Web Token token.go NewToken hard-coded password (Issue 219)

A vulnerability was found in saltbo zpan up to 1.6.5/1.7.0-beta2. It has been rated as problematic. This issue affects the

  

CVE-2025-7455 | Campcodes Online Movie Theater Seat Reservation System 1.0 /manage_reserve.php mid sql injection

A vulnerability classified as critical was found in Campcodes Online Movie Theater Seat Reservation System 1.0. Affected by this vulnerability

  

CVE-2025-7457 | Campcodes Online Movie Theater Seat Reservation System 1.0 /admin/manage_movie.php ID sql injection

A vulnerability, which was classified as critical, was found in Campcodes Online Movie Theater Seat Reservation System 1.0. This affects

  

CVE-2025-7456 | Campcodes Online Movie Theater Seat Reservation System 1.0 /reserve.php ID sql injection

A vulnerability, which was classified as critical, has been found in Campcodes Online Movie Theater Seat Reservation System 1.0. Affected

  

VDB-316102 | Campcodes Online Movie Theater Seat Reservation System 1.0 /admin/manage_seat.php ID sql injection

A vulnerability has been found in Campcodes Online Movie Theater Seat Reservation System 1.0 and classified as critical. This vulnerability

  

CVE-2025-30023 | Axis Camera Station Pro/Camera Station/Device Manager Communication Protocol deserialization (EUVD-2025-21112)

A vulnerability classified as critical has been found in Axis Camera Station Pro, Camera Station and Device Manager. This affects

  

CVE-2025-6200 | GeoDirectory Plugin up to 2.8.119 on WordPress Shortcode Attribute cross site scripting (EUVD-2025-21113)

A vulnerability was found in GeoDirectory Plugin up to 2.8.119 on WordPress. It has been rated as problematic. Affected by

  

CVE-2025-30026 | Axis Camera Station Pro/Camera Station authentication bypass (EUVD-2025-21109)

A vulnerability, which was classified as critical, has been found in Axis Camera Station Pro and Camera Station. This issue

  

CVE-2025-30024 | Axis Device Manager Communication Protocol certificate validation (EUVD-2025-21111)

A vulnerability classified as critical was found in Axis Device Manager. This vulnerability affects unknown code of the component Communication

  

CVE-2025-30025 | Axis Device Manager/Camera Station Pro/Camera Station Communication Protocol deserialization (EUVD-2025-21110)

A vulnerability, which was classified as problematic, was found in Axis Device Manager, Camera Station Pro and Camera Station. Affected

  

CVE-2025-5992 | Qt up to 6.5.x/6.8.2/6.8.3/6.9.0/6.9.1 ICC Profile fromICCProfile denial of service

A vulnerability has been found in Qt up to 6.5.x/6.8.2/6.8.3/6.9.0/6.9.1 and classified as problematic. Affected by this vulnerability is the

  

CVE-2025-5028 | ESET NOD32 Antivirus privileges management

A vulnerability was found in ESET NOD32 Antivirus, Internet Security, Smart Security Premium, Security Ultimate, Endpoint Antivirus for Windows, Endpoint

  

CVE-2025-2942 | Order Delivery Date Plugin up to 12.5.x on WordPress Private Post information disclosure (EUVD-2025-21114)

A vulnerability was found in Order Delivery Date Plugin up to 12.5.x on WordPress. It has been declared as problematic.

  

CVE-2025-3947 | Honeywell C300 PCNT02 Control data Access integer underflow

A vulnerability was found in Honeywell C300 PCNT02, C300 PCNT05, FIM4, FIM8, UOC, CN100, HCA, C300PM and C200E. It has

  

CVE-2025-52459 | Advantech iView NetworkServlet.backupDatabase argument injection (icsa-25-191-08)

A vulnerability was found in Advantech iView and classified as critical. This issue affects the function NetworkServlet.backupDatabase. The manipulation leads

  

CVE-2025-52577 | Advantech iView NetworkServlet.archiveTrapRange sql injection (icsa-25-191-08)

A vulnerability was found in Advantech iView. It has been rated as critical. Affected by this issue is the function

  

CVE-2025-53509 | Advantech iView NetworkServlet.restoreDatabase argument injection (icsa-25-191-08)

A vulnerability was found in Advantech iView. It has been declared as critical. Affected by this vulnerability is the function

  

CVE-2025-53475 | Advantech iView NetworkServlet.getNextTrapPage sql injection (icsa-25-191-08)

A vulnerability, which was classified as critical, has been found in Advantech iView. This issue affects the function NetworkServlet.getNextTrapPage. The

  

CVE-2025-41442 | Advantech iView 5.7.03.6112/5.7.03.6182/5.7.04.6469 cross site scripting (icsa-25-191-08)

A vulnerability classified as problematic was found in Advantech iView 5.7.03.6112/5.7.03.6182/5.7.04.6469. This vulnerability affects unknown code. The manipulation leads to

  

CVE-2025-6392 | Broadcom Brocade SANnav up to 2.4.0 Database Password log file

A vulnerability classified as problematic has been found in Broadcom Brocade SANnav up to 2.4.0. This affects an unknown part

  

CVE-2025-53515 | Advantech iView NetworkServlet.archiveTrap sql injection (icsa-25-191-08)

A vulnerability has been found in Advantech iView and classified as critical. Affected by this vulnerability is the function NetworkServlet.archiveTrap.

  

CVE-2025-6390 | Broadcom Brocade SANnav up to 2.4.0 exposure of sensitive system information to an unauthorized control sphere

A vulnerability, which was classified as problematic, was found in Broadcom Brocade SANnav up to 2.4.0. Affected is an unknown

  

CVE-2025-53519 | Advantech iView 5.7.03.6112/5.7.03.6182/5.7.04.6469 specific cross site scripting (icsa-25-191-08)

A vulnerability was found in Advantech iView 5.7.03.6112/5.7.03.6182/5.7.04.6469. It has been classified as problematic. This affects an unknown part. The

  

CVE-2025-53397 | Advantech iView 5.7.03.6112/5.7.03.6182/5.7.04.6469 cross site scripting (icsa-25-191-08)

A vulnerability was found in Advantech iView 5.7.03.6112/5.7.03.6182/5.7.04.6469 and classified as problematic. Affected by this issue is some unknown functionality.

  

CVE-2025-7442 | WPGYM Plugin up to 67.7.x on WordPress sql injection

A vulnerability was found in WPGYM Plugin up to 67.7.x on WordPress. It has been rated as critical. This issue

  

CVE-2025-31267 | Apple App Store Connect up to 2.x User Information improper authentication

A vulnerability was found in Apple App Store Connect up to 2.x. It has been declared as problematic. This vulnerability

  

CVE-2025-6745 | WoodMart Plugin up to 8.2.5 on WordPress Password Protect woodmart_get_posts_by_query improper authentication

A vulnerability classified as critical has been found in WoodMart Plugin up to 8.2.5 on WordPress. Affected is the function

  

CVE-2025-5530 | WPC Smart Compare for WooCommerce Plugin up to 6.4.6 on WordPress Shortcode shortcode_btn cross site scripting

A vulnerability classified as problematic was found in WPC Smart Compare for WooCommerce Plugin up to 6.4.6 on WordPress. Affected

  

CVE-2025-6838 | Broken Link Notifier Plugin up to 1.3.0 on WordPress csv injection

A vulnerability, which was classified as critical, was found in Broken Link Notifier Plugin up to 1.3.0 on WordPress. This

  

CVE-2025-4593 | aviplugins WP Register Profile With Shortcode Plugin up to 3.6.2 on WordPress information disclosure

A vulnerability, which was classified as problematic, has been found in aviplugins WP Register Profile With Shortcode Plugin up to

  

CVE-2025-53861 | Red Hat Ansible Automation Platform missing secure attribute

A vulnerability was found in Red Hat Ansible Automation Platform and classified as problematic. This issue affects some unknown processing.

  

CVE-2025-6851 | Broken Link Notifier Plugin up to 1.3.0 on WordPress ajax_blinks server-side request forgery

A vulnerability has been found in Broken Link Notifier Plugin up to 1.3.0 on WordPress and classified as critical. This

  

CVE-2025-53862 | Red Hat Ansible Automation Platform aap-gateway information disclosure

A vulnerability was found in Red Hat Ansible Automation Platform. It has been classified as problematic. Affected is an unknown