NA - CVE-2025-26700 - Authentication bypass using an alternate path...
Authentication bypass using an alternate path or channel issue exists in ”RoboForm Password Manager" App for Android versions prior to 9.7.4, which may allow an attacker with access to a device...
Low - CVE-2025-1373 - A vulnerability was found in FFmpeg up to 7.1....
A vulnerability was found in FFmpeg up to 7.1. It has been rated as problematic. Affected by this issue is the function mov_read_trak of the file libavformat/mov.c of the component MOV Parser. The...
Medium - CVE-2025-1374 - A vulnerability classified as critical has been...
A vulnerability classified as critical has been found in code-projects Real Estate Property Management System 1.0. This affects an unknown part of the file /search.php. The manipulation of the...
Critical - CVE-2025-1387 - Orca HCM from LEARNING DIGITAL has an Improper...
Orca HCM from LEARNING DIGITAL has an Improper Authentication vulnerability, allowing unauthenticated remote attackers to log in to the system as any user.
High - CVE-2025-1388 - Orca HCM from LEARNING DIGITAL has an Arbitrary...
Orca HCM from LEARNING DIGITAL has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privileges to upload and run web shells
High - CVE-2025-0924 - The WP Activity Log plugin for WordPress is...
The WP Activity Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in all versions up to, and including, 5.2.2 due to insufficient input sanitization...
Low - CVE-2025-1376 - A vulnerability classified as problematic was...
A vulnerability classified as problematic was found in GNU elfutils 0.192. This vulnerability affects the function elf_strptr in the library /libelf/elf_strptr.c of the component eu-strip. The...
Low - CVE-2025-1377 - A vulnerability, which was classified as...
A vulnerability, which was classified as problematic, has been found in GNU elfutils 0.192. This issue affects the function gelf_getsymshndx of the file strip.c of the component eu-strip. The...
High - CVE-2025-1389 - Orca HCM from Learning Digital has a SQL...
Orca HCM from Learning Digital has a SQL Injection vulnerability, allowing attackers with regular privileges to inject arbitrary SQL commands to read, modify, and delete database contents.
NA - CVE-2024-13603 - The Wise Forms WordPress plugin through 1.2.0...
The Wise Forms WordPress plugin through 1.2.0 does not sanitise and escape some of its settings, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks via malicious...