NA - CVE-2025-24309 - in OpenHarmony v5.0.2 and prior versions allow...
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted...
High - CVE-2025-1306 - The Newscrunch theme for WordPress is...
The Newscrunch theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.4. This is due to missing or incorrect nonce validation on the...
Critical - CVE-2025-1307 - The Newscrunch theme for WordPress is...
The Newscrunch theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check in the newscrunch_install_and_activate_plugin() function in all versions up to, and...
Low - CVE-2025-1904 - A vulnerability, which was classified as...
A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank System 1.0. Affected by this issue is some unknown functionality of the file /Blood/A+.php. The...
Low - CVE-2025-1905 - A vulnerability, which was classified as...
A vulnerability, which was classified as problematic, was found in SourceCodester Employee Management System 1.0. This affects an unknown part of the file employee.php. The manipulation of the...
Medium - CVE-2025-1906 - A vulnerability has been found in PHPGurukul...
A vulnerability has been found in PHPGurukul Restaurant Table Booking System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/profile.php. The manipulation...
NA - CVE-2024-13685 - The Admin and Site Enhancements (ASE) WordPress...
The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate their value to bypass the...
NA - CVE-2024-47259 - Girishunawane, member of the AXIS OS Bug Bounty...
Girishunawane, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API dynamicoverlay.cgi did not have a sufficient input validation allowing for a possible command injection leading...
NA - CVE-2024-47260 - 51l3nc3, member of the AXIS OS Bug Bounty...
51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API mediaclip.cgi did not have a sufficient input validation allowing for uploading more audio clips then designed...
NA - CVE-2024-47262 - Dzmitry Lukyanenka, member of the AXIS OS Bug...
Dzmitry Lukyanenka, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API param.cgi was vulnerable to a race condition attack allowing for an attacker to block access to the web...