Medium - CVE-2024-9994 - The Essential Addons for Elementor – Best...
The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
Medium - CVE-2025-5528 - The Social Sharing Plugin – Sassy Social Share...
The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the heateor_mastodon_share parameter in all versions up to, and including,...
Medium - CVE-2025-5568 - The WpEvently plugin for WordPress is...
The WpEvently plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in all versions up to, and including, 4.4.2 due to insufficient input sanitization and output...
Medium - CVE-2025-5836 - A vulnerability was found in Tenda AC9...
A vulnerability was found in Tenda AC9 15.03.02.13. It has been rated as critical. This issue affects the function formSetIptv of the file /goform/SetIPTVCfg of the component POST Request Handler....
Medium - CVE-2025-5837 - A vulnerability classified as critical has been...
A vulnerability classified as critical has been found in PHPGurukul Employee Record Management System 1.3. Affected is an unknown function of the file /admin/allemployees.php. The manipulation of...
Medium - CVE-2025-5838 - A vulnerability classified as critical was...
A vulnerability classified as critical was found in PHPGurukul Employee Record Management System 1.3. Affected by this vulnerability is an unknown functionality of the file /admin/adminprofile.php....
High - CVE-2025-5839 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, has been found in Tenda AC9 15.03.02.13. Affected by this issue is the function fromadvsetlanip of the file /goform/AdvSetLanip of the component...
High - CVE-2025-5840 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file /user_update_customer_order.php. The...
NA - CVE-2024-55585 - In the moPS App through 1.8.618, all users can...
In the moPS App through 1.8.618, all users can access administrative API endpoints without additional authentication, resulting in unrestricted read and write access, as demonstrated by...