NA - CVE-2025-52580 - Insertion of sensitive information into log...
Insertion of sensitive information into log file issue exists in "region PAY" App for Android prior to 1.5.28. If exploited, sensitive user information may be exposed to an attacker who has access...
High - CVE-2025-6585 - The WP JobHunt plugin for WordPress is...
The WP JobHunt plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 7.2 via the cs_remove_profile_callback() function due to missing...
Medium - CVE-2025-7495 - The WP-Members Membership Plugin plugin for...
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpmem_login_link' shortcode in all versions up to, and including,...
Medium - CVE-2025-7644 - The Pixel Gallery Addons for Elementor – Easy...
The Pixel Gallery Addons for Elementor – Easy Grid, Creative Gallery, Drag and Drop Grid, Custom Grid Layout, Portfolio Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
High - CVE-2025-7645 - The Extensions For CF7 (Contact form 7...
The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the...
NA - CVE-2025-38352 - In the Linux kernel, the following...
In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If an exiting non-autoreaping task has...
High - CVE-2025-7945 - A vulnerability was found in D-Link DIR-513 up...
A vulnerability was found in D-Link DIR-513 up to 20190831. It has been declared as critical. This vulnerability affects the function formSetWanDhcpplus of the file /goform/formSetWanDhcpplus. The...
Medium - CVE-2025-7946 - A vulnerability was found in PHPGurukul...
A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /search-visitor.php of the...
Medium - CVE-2025-7947 - A vulnerability classified as critical has been...
A vulnerability classified as critical has been found in jshERP up to 3.5. Affected is an unknown function of the file /user/delete of the component Account Handler. The manipulation of the...
Medium - CVE-2025-7948 - A vulnerability classified as problematic was...
A vulnerability classified as problematic was found in jshERP up to 3.5. Affected by this vulnerability is an unknown functionality of the file /jshERP-boot/user/updatePwd. The manipulation leads...