NA - CVE-2025-29930 - imFAQ is an advanced questions and answers...
imFAQ is an advanced questions and answers management system for ImpressCMS. Prior to 1.0.1, if the $_GET['seoOp'] parameter is manipulated to include malicious input (e.g.,...
NA - CVE-2025-30137 - An issue was discovered in the G-Net GNET APK...
An issue was discovered in the G-Net GNET APK 2.6.2. Hardcoded credentials exist in in APK for ports 9091 and 9092. The GNET mobile application contains hardcoded credentials that provide...
NA - CVE-2025-30138 - An issue was discovered on G-Net Dashcam BB...
An issue was discovered on G-Net Dashcam BB GONX devices. Managing Settings and Obtaining Sensitive Data and Sabotaging Car Battery can be performed by unauthorized persons. It allows unauthorized...
NA - CVE-2025-30139 - An issue was discovered on G-Net Dashcam BB...
An issue was discovered on G-Net Dashcam BB GONX devices. Default credentials for SSID cannot be changed. It broadcasts a fixed SSID with default credentials that cannot be changed. This allows any...
NA - CVE-2025-30141 - An issue was discovered on G-Net Dashcam BB...
An issue was discovered on G-Net Dashcam BB GONX devices. One can Remotely Dump Video Footage and the Live Video Stream. It exposes API endpoints on ports 9091 and 9092 that allow remote access to...
NA - CVE-2025-30142 - An issue was discovered on G-Net Dashcam BB...
An issue was discovered on G-Net Dashcam BB GONX devices. Bypassing of Device Pairing can occur. It uses MAC address verification as the sole mechanism for recognizing paired devices, allowing...
High - CVE-2024-12563 - The s2Member Pro plugin for WordPress is...
The s2Member Pro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 250214 via the 'template' attribute. This makes it possible for...
NA - CVE-2024-57151 - SQL Injection vulnerability in rainrocka xinhu...
SQL Injection vulnerability in rainrocka xinhu v.2.6.5 and before allows a remote attacker to execute arbitrary code via the inputAction.php file and the saveAjax function
NA - CVE-2025-30140 - An issue was discovered on G-Net Dashcam BB...
An issue was discovered on G-Net Dashcam BB GONX devices. A Public Domain name is Used for the Internal Domain Name. It uses an unregistered public domain name as an internal domain, creating a...