High - CVE-2025-6043 - The Malcure Malware Scanner — #1 Toolset for...
The Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal plugin for WordPress is vulnerable to Arbitrary File Deletion due to a missing capability check on the wpmr_delete_file()...
Medium - CVE-2025-6747 - The Avada (Fusion) Builder plugin for WordPress...
The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fusion_map' shortcode in all versions up to, and including, 3.12.1 due...
High - CVE-2025-7359 - The Counter live visitors for WooCommerce...
The Counter live visitors for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the wcvisitor_get_block function in all versions...
Critical - CVE-2025-7673 - A buffer overflow vulnerability in the URL...
A buffer overflow vulnerability in the URL parser of the zhttpd web server in Zyxel VMG8825-T50K firmware versions prior to V5.50(ABOM.5)C0 could allow an unauthenticated attacker to cause...
NA - CVE-2025-27465 - Certain instructions need intercepting and...
Certain instructions need intercepting and emulating by Xen. In some cases Xen emulates the instruction by replaying it, using an executable stub. Some instructions may raise an exception, which...
NA - CVE-2025-22227 - In some specific scenarios with chained...
In some specific scenarios with chained redirects, Reactor Netty HTTP client leaks credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects.
NA - CVE-2025-40724 - Stored Cross-Site Scripting (XSS) vulnerability...
Stored Cross-Site Scripting (XSS) vulnerability in Pharmacy POS PHP Script. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a...
NA - CVE-2025-40985 - SQL injection vulnerability in SCATI Vision Web...
SQL injection vulnerability in SCATI Vision Web of SCATI Labs from version 4.8 to 7.2. This vulnerability allows an attacker to exfiltrate some data from the database via the ‘login’ parameter in...
Medium - CVE-2025-5284 - The Master Addons – Elementor Addons with White...
The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom JS...