High - CVE-2025-7417 - A vulnerability has been found in Tenda O3V2...
A vulnerability has been found in Tenda O3V2 1.0.0.12(3880) and classified as critical. Affected by this vulnerability is the function fromNetToolGet of the file /goform/setPingInfo of the...
NA - CVE-2025-1727 - The protocol used for remote linking over RF...
The protocol used for remote linking over RF for End-of-Train and Head-of-Train (also known as a FRED) relies on a BCH checksum for packet creation. It is possible to create these EoT and HoT...
NA - CVE-2025-31267 - An authentication issue was addressed with...
An authentication issue was addressed with improved state management. This issue is fixed in App Store Connect 3.0. An attacker with physical access to an unlocked device may be able to view...
High - CVE-2025-7418 - A vulnerability was found in Tenda O3V2...
A vulnerability was found in Tenda O3V2 1.0.0.12(3880) and classified as critical. Affected by this issue is the function fromPingResultGet of the file /goform/setPing of the component httpd. The...
High - CVE-2025-7419 - A vulnerability was found in Tenda O3V2...
A vulnerability was found in Tenda O3V2 1.0.0.12(3880). It has been classified as critical. This affects the function fromSpeedTestSet of the file /goform/setRateTest of the component httpd. The...
Medium - CVE-2025-3780 - The WCFM – Frontend Manager for WooCommerce...
The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability...
Critical - CVE-2025-4828 - The Support Board plugin for WordPress is...
The Support Board plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the sb_file_delete function in all versions up to, and including, 3.8.0....
Critical - CVE-2025-4855 - The Support Board plugin for WordPress is...
The Support Board plugin for WordPress is vulnerable to unauthorized access/modification/deletion of data due to use of hardcoded default secrets in the sb_encryption() function in all versions up...
Critical - CVE-2025-7206 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, has been found in D-Link DIR-825 2.10. This issue affects the function sub_410DDC of the file switch_language.cgi of the component httpd. The...
NA - CVE-2025-34077 - An authentication bypass vulnerability exists...
An authentication bypass vulnerability exists in the WordPress Pie Register plugin = 3.7.1.4 that allows unauthenticated attackers to impersonate arbitrary users by submitting a crafted POST...