NA - CVE-2025-26412 - The SIMCom SIM7600G modem supports an...
The SIMCom SIM7600G modem supports an undocumented AT command, which allows an attacker to execute system commands with root permission on the modem. An attacker needs either physical access or...
High - CVE-2025-41661 - An unauthenticated remote attacker can execute...
An unauthenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of Cross-Site Request Forgery (CSRF) protection in the Main Web Interface...
High - CVE-2025-41662 - An unauthenticated remote attacker can execute...
An unauthenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of Cross-Site Request Forgery (CSRF) protection in the Main Web Interface...
High - CVE-2025-41663 - An unauthenticated remote attacker in a...
An unauthenticated remote attacker in a man-in-the-middle position can inject arbitrary commands in responses returned by WWH servers and gain arbitrary command execution with elevated privileges.
High - CVE-2025-4315 - The CubeWP – All-in-One Dynamic Content...
The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.23. This is due to the plugin allowing a user...
High - CVE-2025-3302 - The Xagio SEO – AI Powered SEO plugin for...
The Xagio SEO – AI Powered SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘HTTP_REFERER’ parameter in all versions up to, and including, 7.1.0.16 due to insufficient...