High - CVE-2025-5395 - The WordPress Automatic Plugin plugin for...
The WordPress Automatic Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'core.php' file in all versions up to, and...
NA - CVE-2025-29756 - SunGrow's back end users system...
SunGrow's back end users system iSolarCloud https://isolarcloud.com uses an MQTT service to transport data from the user's connected devices to the user's web browser. The MQTT...
NA - CVE-2025-5991 - There is a "Use After Free" vulnerability in...
There is a "Use After Free" vulnerability in Qt's QHttp2ProtocolHandler in the QtNetwork module. This only affects HTTP/2 handling, HTTP handling is not affected by this at all. This happens...
NA - CVE-2025-26412 - The SIMCom SIM7600G modem supports an...
The SIMCom SIM7600G modem supports an undocumented AT command, which allows an attacker to execute system commands with root permission on the modem. An attacker needs either physical access or...
High - CVE-2025-41661 - An unauthenticated remote attacker can execute...
An unauthenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of Cross-Site Request Forgery (CSRF) protection in the Main Web Interface...
High - CVE-2025-41662 - An unauthenticated remote attacker can execute...
An unauthenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of Cross-Site Request Forgery (CSRF) protection in the Main Web Interface...
High - CVE-2025-41663 - An unauthenticated remote attacker in a...
An unauthenticated remote attacker in a man-in-the-middle position can inject arbitrary commands in responses returned by WWH servers and gain arbitrary command execution with elevated privileges.
High - CVE-2025-4315 - The CubeWP – All-in-One Dynamic Content...
The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.23. This is due to the plugin allowing a user...