Aggregator
CVE-2025-63455 | Tenda AX-3 16.03.12.10_CN fromSetWifiGusetBasic shareSpeed stack-based overflow
3 months ago
A vulnerability marked as critical has been reported in Tenda AX-3 16.03.12.10_CN. The affected element is the function fromSetWifiGusetBasic. Performing manipulation of the argument shareSpeed results in stack-based buffer overflow.
This vulnerability is known as CVE-2025-63455. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2025-63497 | rickxy Hospital Management System 1.0 GET Parameter his_doc_view_single_patient.php pat_number sql injection
3 months ago
A vulnerability labeled as critical has been found in rickxy Hospital Management System 1.0. Impacted is an unknown function of the file his_doc_view_single_patient.php of the component GET Parameter Handler. Such manipulation of the argument pat_number leads to sql injection.
This vulnerability is traded as CVE-2025-63497. The attack may be launched remotely. There is no exploit available.
vuldb.com
OpenAI计划推出三大核心版本:GPT-5.1、GPT-5.1 Reasoning与GPT-5.1 Pro
3 months ago
安全客
CVE-2025-12589 | WP-Walla Plugin up to 0.5.3.5 on WordPress Setting cross-site request forgery
3 months ago
A vulnerability identified as problematic has been detected in WP-Walla Plugin up to 0.5.3.5 on WordPress. This issue affects some unknown processing of the component Setting Handler. This manipulation causes cross-site request forgery.
This vulnerability appears as CVE-2025-12589. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2025-12590 | YSlider Plugin up to 1.1 on WordPress Configuration cross-site request forgery
3 months ago
A vulnerability categorized as problematic has been discovered in YSlider Plugin up to 1.1 on WordPress. This vulnerability affects unknown code of the component Configuration Handler. The manipulation results in cross-site request forgery.
This vulnerability is reported as CVE-2025-12590. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2025-12672 | Flickr Show Plugin up to 1.5 on WordPress Shortcode flickrshow div_height cross site scripting
3 months ago
A vulnerability was found in Flickr Show Plugin up to 1.5 on WordPress. It has been rated as problematic. This affects the function flickrshow of the component Shortcode Handler. The manipulation of the argument div_height leads to cross site scripting.
This vulnerability is documented as CVE-2025-12672. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2025-12880 | Progress Bar Blocks for Gutenberg Plugin up to 1.0.0 on WordPress SVG File Parser cross site scripting
3 months ago
A vulnerability was found in Progress Bar Blocks for Gutenberg Plugin up to 1.0.0 on WordPress. It has been declared as problematic. Affected by this issue is some unknown functionality of the component SVG File Parser. Executing manipulation can lead to cross site scripting.
This vulnerability is registered as CVE-2025-12880. It is possible to launch the attack remotely. No exploit is available.
vuldb.com
CVE-2025-11829 | Five9 Live Chat Plugin up to 1.1.2 on WordPress Shortcode cross site scripting
3 months ago
A vulnerability was found in Five9 Live Chat Plugin up to 1.1.2 on WordPress. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the component Shortcode Handler. Performing manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2025-11829. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-12652 | Ungapped Widgets Plugin on WordPress prefillvalues cross site scripting
3 months ago
A vulnerability was found in Ungapped Widgets Plugin on WordPress and classified as problematic. Affected is an unknown function. Such manipulation of the argument prefillvalues leads to cross site scripting.
This vulnerability is listed as CVE-2025-12652. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2025-12644 | Nonaki Plugin up to 1.0.11 on WordPress Shortcode nonaki cross site scripting
3 months ago
A vulnerability has been found in Nonaki Plugin up to 1.0.11 on WordPress and classified as problematic. This impacts the function nonaki of the component Shortcode Handler. This manipulation causes cross site scripting.
This vulnerability is tracked as CVE-2025-12644. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
CVE-2025-38477
3 months ago
Currently trending CVE - Hype Score: 1 - In the Linux kernel, the following vulnerability has been resolved:
net/sched: sch_qfq: Fix race condition on qfq_aggregate
A race condition can occur when 'agg' is modified in qfq_change_agg
(called during qfq_enqueue) while other threads access it
concurrently. For example, ...
CVE-2025-11873 | WP BBCode Plugin up to 1.8.1 on WordPress Shortcode url cross site scripting
3 months ago
A vulnerability, which was classified as problematic, was found in WP BBCode Plugin up to 1.8.1 on WordPress. This affects the function url of the component Shortcode Handler. The manipulation results in cross site scripting.
This vulnerability is identified as CVE-2025-11873. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2025-11874 | Slippy Slider Plugin up to 2.0 on WordPress Shortcode slippy-slider cross site scripting
3 months ago
A vulnerability, which was classified as problematic, has been found in Slippy Slider Plugin up to 2.0 on WordPress. The impacted element is the function slippy-slider of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is referenced as CVE-2025-11874. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2025-12667 | GitHub Gist Shortcode Plugin up to 0.2 on WordPress gist ID cross site scripting
3 months ago
A vulnerability classified as problematic was found in GitHub Gist Shortcode Plugin up to 0.2 on WordPress. The affected element is the function gist of the component Shortcode Handler. Executing manipulation of the argument ID can lead to cross site scripting.
The identification of this vulnerability is CVE-2025-12667. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-12754 | Geopost Plugin up to 1.2 on WordPress Shortcode geopost height cross site scripting
3 months ago
A vulnerability classified as problematic has been found in Geopost Plugin up to 1.2 on WordPress. Impacted is the function geopost of the component Shortcode Handler. Performing manipulation of the argument height results in cross site scripting.
This vulnerability was named CVE-2025-12754. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2025-11860 | Twitter Feed Plugin up to 1.3.1 on WordPress Shortcode ottwitter_feed width/height cross site scripting
3 months ago
A vulnerability described as problematic has been identified in Twitter Feed Plugin up to 1.3.1 on WordPress. This issue affects the function ottwitter_feed of the component Shortcode Handler. Such manipulation of the argument width/height leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-11860. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2025-11129 | Alexander Böhm Include Fussball.de Widgets Plugin up to 4.0.0 on WordPress api/type cross site scripting
3 months ago
A vulnerability marked as problematic has been reported in Alexander Böhm Include Fussball.de Widgets Plugin up to 4.0.0 on WordPress. This vulnerability affects unknown code. This manipulation of the argument api/type causes cross site scripting.
This vulnerability is handled as CVE-2025-11129. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2025-12671 | WP-Iconics Plugin up to 0.0.4 on WordPress Shortcode wp_iconics cross site scripting
3 months ago
A vulnerability labeled as problematic has been found in WP-Iconics Plugin up to 0.0.4 on WordPress. This affects the function wp_iconics of the component Shortcode Handler. The manipulation results in cross site scripting.
This vulnerability is known as CVE-2025-12671. It is possible to launch the attack remotely. No exploit is available.
vuldb.com
CVE-2025-12753 | Chart Expert Plugin up to 1.0 on WordPress Shortcode pmzez_chart cross site scripting
3 months ago
A vulnerability identified as problematic has been detected in Chart Expert Plugin up to 1.0 on WordPress. Affected by this issue is the function pmzez_chart of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-12753. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com