NA - CVE-2025-2214 - A vulnerability was found in Microweber 2.0.19....
A vulnerability was found in Microweber 2.0.19. It has been rated as problematic. This issue affects some unknown processing of the file userfiles/modules/settings/group/website_group/index.php of...
Medium - CVE-2025-2215 - A vulnerability classified as critical was...
A vulnerability classified as critical was found in Doufox up to 0.2.0. Affected by this vulnerability is an unknown functionality of the file /?s=doudou&c=file&a=list. The manipulation of the...
Medium - CVE-2025-2216 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, has been found in zzskzy Warehouse Refinement Management System 1.3. Affected by this issue is the function UploadCrash of the file...
Medium - CVE-2025-2217 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, was found in zzskzy Warehouse Refinement Management System 1.3. This affects the function ProcessRequest of the file /getAdyData.ashx. The...
Medium - CVE-2025-2218 - A vulnerability has been found in LoveCards...
A vulnerability has been found in LoveCards LoveCardsV2 up to 2.3.2 and classified as critical. This vulnerability affects unknown code of the file /api/system/other of the component Setting...
High - CVE-2025-2219 - A vulnerability was found in LoveCards...
A vulnerability was found in LoveCards LoveCardsV2 up to 2.3.2 and classified as critical. This issue affects some unknown processing of the file /api/upload/image. The manipulation of the argument...
Low - CVE-2025-2220 - A vulnerability was found in Odyssey CMS up to...
A vulnerability was found in Odyssey CMS up to 10.34. It has been classified as problematic. Affected is an unknown function of the file /modules/odyssey_contact_form/odyssey_contact_form.php of...
Medium - CVE-2025-1508 - The WP Crowdfunding plugin for WordPress is...
The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the download_data action in all versions up to, and including, 2.1.13....
Medium - CVE-2025-2076 - The binlayerpress plugin for WordPress is...
The binlayerpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1 due to insufficient input sanitization and output...
Medium - CVE-2025-2077 - The Simple Amazon Affiliate plugin for...
The Simple Amazon Affiliate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'msg' parameter in all versions up to, and including, 1.0.9 due to insufficient...