Critical - CVE-2025-7343 - The SFT developed by Digiwin has a SQL...
The SFT developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
High - CVE-2025-7344 - The EAI developed by Digiwin has a Privilege...
The EAI developed by Digiwin has a Privilege Escalation vulnerability, allowing remote attackers with regular privileges to elevate their privileges to administrator level via a specific API.
NA - CVE-2025-7919 - WinMatrix3 Web package developed by Simopro...
WinMatrix3 Web package developed by Simopro Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete...
NA - CVE-2025-7920 - WinMatrix3 Web package developed by Simopro...
WinMatrix3 Web package developed by Simopro Technology has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in...
Critical - CVE-2025-7921 - Certain modem models developed by Askey has a...
Certain modem models developed by Askey has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to control the program's execution flow and potentially...
NA - CVE-2025-4049 - Use of hard-coded, the same among all...
Use of hard-coded, the same among all vulnerable installations SQLite credentials vulnerability in SIGNUM-NET FARA allows to read and manipulate local-stored database.This issue affects FARA:...
NA - CVE-2025-4569 - An insecure sensitive key storage issue was...
An insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized actor to obtain a token that could be used to communicate with certain services. Refer to the...
NA - CVE-2025-4570 - An insecure sensitive key storage issue was...
An insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized actor to obtain a token that could be used to communicate with certain services. Refer to the...
Medium - CVE-2025-4685 - The Gutentor – Gutenberg Blocks – Page Builder...
The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTML data attributes of multiple widgets, in all...
Medium - CVE-2025-7354 - The WP Shortcodes Plugin — Shortcodes Ultimate...
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 7.4.2 due to...