Medium - CVE-2025-1797 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, has been found in Hunan Zhonghe Baiyi Information Technology Baiyiyun Asset Management and Operations System up to 20250217. Affected by this...
Medium - CVE-2025-1799 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, was found in Zorlan SkyCaiji 2.9. This affects the function previewAction of the file vendor/skycaiji/app/admin/controller/Tool.php. The...
Medium - CVE-2025-1800 - A vulnerability has been found in D-Link...
A vulnerability has been found in D-Link DAR-7000 3.2 and classified as critical. This vulnerability affects the function get_ip_addr_details of the file /view/vpn/sxh_vpn/sxh_vpnlic.php of the...
High - CVE-2025-1804 - A vulnerability was found in Blizzard...
A vulnerability was found in Blizzard Battle.Net up to 2.39.0.15212 on Windows and classified as critical. Affected by this issue is some unknown functionality in the library profapi.dll. The...
High - CVE-2024-12811 - The Traveler theme for WordPress is vulnerable...
The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.8 via the 'hotel_alone_slider' shortcode 'style' attribute. This...
Medium - CVE-2025-1681 - The Cardealer theme for WordPress is vulnerable...
The Cardealer theme for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check and missing filename sanitization on the demo theme scheme...
High - CVE-2025-1682 - The Cardealer theme for WordPress is vulnerable...
The Cardealer theme for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.4 due to missing capability check on the 'save_settings' function. This makes...
High - CVE-2025-1687 - The Cardealer theme for WordPress is vulnerable...
The Cardealer theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.4. This is due to missing nonce validation on the 'update_user_profile'...
NA - CVE-2025-25477 - A host header injection vulnerability in...
A host header injection vulnerability in SysPass 3.2x allows an attacker to load malicious JS files from an arbitrary domain which would be executed in the victim's browser.