High - CVE-2025-4601 - The "RH - Real Estate WordPress Theme" theme...
The "RH - Real Estate WordPress Theme" theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.4.0. This is due to the theme not properly restricting user...
High - CVE-2025-5912 - A vulnerability was found in D-Link DIR-632...
A vulnerability was found in D-Link DIR-632 FW103B08. It has been declared as critical. This vulnerability affects the function do_file of the component HTTP POST Request Handler. The manipulation...
High - CVE-2025-5913 - A vulnerability was found in PHPGurukul Vehicle...
A vulnerability was found in PHPGurukul Vehicle Record Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/search-vehicle.php. The...
Medium - CVE-2025-5925 - The Bunny’s Print CSS plugin for WordPress is...
The Bunny’s Print CSS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.95. This is due to missing or incorrect nonce validation on the...
High - CVE-2025-5934 - A vulnerability was found in Netgear EX3700 up...
A vulnerability was found in Netgear EX3700 up to 1.0.0.88. It has been classified as critical. Affected is the function sub_41619C of the file /mtd. The manipulation leads to stack-based buffer...
Medium - CVE-2025-3076 - The Elementor Website Builder Pro plugin for...
The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_text’ parameter in all versions up to, and including, 3.29.0 due to insufficient...
Medium - CVE-2025-5935 - A vulnerability was found in Open5GS up to...
A vulnerability was found in Open5GS up to 2.7.3. It has been declared as problematic. Affected by this vulnerability is the function common_register_state of the file src/mme/emm-sm.c of the...
High - CVE-2025-5952 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, has been found in Zend.To up to 6.10-6 Beta. This issue affects the function exec of the file NSSDropoff.php. The manipulation of the argument...
NA - CVE-2025-1041 - An improper input validation discovered in...
An improper input validation discovered in Avaya Call Management System could allow an unauthorized remote command via a specially crafted web request. Affected versions include 18.x, 19.x...
NA - CVE-2025-4840 - The inprosysmedia-likes-dislikes-post WordPress...
The inprosysmedia-likes-dislikes-post WordPress plugin through 1.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to...