Medium - CVE-2025-5539 - The Simple Contact Form Plugin for WordPress –...
The Simple Contact Form Plugin for WordPress – WP Easy Contact plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'emd_mb_meta' shortcode in all...
High - CVE-2025-5561 - A vulnerability was found in PHPGurukul Curfew...
A vulnerability was found in PHPGurukul Curfew e-Pass Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file...
High - CVE-2025-5562 - A vulnerability was found in PHPGurukul Curfew...
A vulnerability was found in PHPGurukul Curfew e-Pass Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file...
Medium - CVE-2025-5566 - A vulnerability classified as critical has been...
A vulnerability classified as critical has been found in PHPGurukul Notice Board System 1.0. This affects an unknown part of the file /search-notice.php. The manipulation of the argument searchdata...
NA - CVE-2025-48710 - kro (Kube Resource Orchestrator) 0.1.0 before...
kro (Kube Resource Orchestrator) 0.1.0 before 0.2.1 allows users (with permission to create or modify ResourceGraphDefinition resources) to supply arbitrary container images. This can lead to a...
NA - CVE-2025-4578 - The File Provider WordPress plugin through...
The File Provider WordPress plugin through 1.2.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading...
NA - CVE-2025-4580 - The File Provider WordPress plugin through...
The File Provider WordPress plugin through 1.2.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
Medium - CVE-2025-5569 - A vulnerability was found in IdeaCMS up to 1.7...
A vulnerability was found in IdeaCMS up to 1.7 and classified as critical. This issue affects the function Article/Goods of the file /api/v1.index.article/getList.html. The manipulation of the...
Medium - CVE-2025-5571 - A vulnerability was found in D-Link DCS-932L...
A vulnerability was found in D-Link DCS-932L 2.18.01. It has been classified as critical. Affected is the function setSystemAdmin of the file /setSystemAdmin. The manipulation of the argument...
High - CVE-2025-5572 - A vulnerability was found in D-Link DCS-932L...
A vulnerability was found in D-Link DCS-932L 2.18.01. It has been declared as critical. Affected by this vulnerability is the function setSystemEmail of the file /setSystemEmail. The manipulation...