Vulnerabilities (CVE)

Total 99438 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-31954 2025-11-05 N/A 5.4 MEDIUM
HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitive information disclosure. An HTTP GET method is used to process a request and includes sensitive information in the query string of that request. An attacker could potentially access information or resources they were not intended to see.
CVE-2025-24203 1 Apple 2 Ipad Os, Macos 2025-11-05 N/A 5.0 MEDIUM
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to modify protected parts of the file system.
CVE-2025-11072 2025-11-05 N/A 5.3 MEDIUM
The MelAbu WP Download Counter Button WordPress plugin through 1.8.6.7 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/download arbitrary files.
CVE-2025-10873 2025-11-05 N/A 5.3 MEDIUM
The ElementInvader Addons for Elementor WordPress plugin before 1.4.1 allows unauthenticated user to send arbitrary e-mails to arbitrary addresses due to missing authorization on the elementinvader_addons_for_elementor_forms_send_form action.
CVE-2025-10567 2025-11-05 N/A 6.3 MEDIUM
The FunnelKit WordPress plugin before 3.12.0.1 does not sanitize user input before echoing it back in some of its checkout-related AJAX actions, allowing attackers to conduct reflected XSS attacks against logged-in users.
CVE-2025-12609 1 Codeastro 1 Gym Management System 2025-11-05 5.8 MEDIUM 4.7 MEDIUM
A vulnerability was found in CodeAstro Gym Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/update-progress.php. Performing manipulation of the argument id/ini_weight results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used.
CVE-2024-39891 1 Twilio 2 Authy, Authy Authenticator 2025-11-05 N/A 5.3 MEDIUM
In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-number data, as exploited in the wild in June 2024. Specifically, the endpoint accepted a stream of requests containing phone numbers, and responded with information about whether each phone number was registered with Authy. (Authy accounts were not compromised, however.)
CVE-2025-63563 1 Summerpearlgroup 1 Vacation Rental Management Platform 2025-11-05 N/A 6.5 MEDIUM
Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 does not properly invalidate active user sessions after a password change. This allows an attacker with a valid session token to maintain access to the account even after the legitimate user changes their password.
CVE-2025-12593 1 Fabian 1 Simple Online Hotel Reservation System 2025-11-05 5.8 MEDIUM 4.7 MEDIUM
A vulnerability was identified in code-projects Simple Online Hotel Reservation System 2.0. The impacted element is an unknown function of the file /admin/edit_room.php of the component Photo Handler. The manipulation leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
CVE-2025-12612 1 Campcodes 1 School Fees Payment Management System 2025-11-05 6.5 MEDIUM 6.3 MEDIUM
A security flaw has been discovered in Campcodes School Fees Payment Management System 1.0. This issue affects some unknown processing of the file /ajax.php. The manipulation results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be exploited.
CVE-2025-12614 1 Mayurik 1 Best House Rental Management System 2025-11-05 5.8 MEDIUM 4.7 MEDIUM
A weakness has been identified in SourceCodester Best House Rental Management System 1.0. Impacted is the function delete_payment of the file /admin_class.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.
CVE-2025-36172 1 Ibm 1 Cloud Pak For Business Automation 2025-11-05 N/A 6.4 MEDIUM
IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 001, 24.0.1 through 24.0.1 Interim Fix 004, 24.0.0 through 24.0.0 Interim Fix 006, and earlier unsupported releases IBM Business Automation Workflow is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVE-2025-27041 1 Qualcomm 126 Ar8035, Ar8035 Firmware, Fastconnect 6900 and 123 more 2025-11-05 N/A 5.5 MEDIUM
Transient DOS while processing video packets received from video firmware.
CVE-2025-27045 1 Qualcomm 36 Fastconnect 6900, Fastconnect 6900 Firmware, Fastconnect 7800 and 33 more 2025-11-05 N/A 6.1 MEDIUM
Information disclosure while processing batch command execution in Video driver.
CVE-2025-27049 1 Qualcomm 62 Fastconnect 6700, Fastconnect 6700 Firmware, Fastconnect 6900 and 59 more 2025-11-05 N/A 5.5 MEDIUM
Transient DOS while processing IOCTL call for image encoding.
CVE-2016-15049 1 Nagios 1 Log Server 2025-11-05 N/A 5.4 MEDIUM
Nagios Log Server versions prior to 1.4.2 are vulnerable to cross-site scripting (XSS) in the Dashboards section when rendering log entries in the Logs table. Untrusted log content was not safely encoded for the output context, allowing attacker-controlled data present in logs to execute script in the victim’s browser within the application origin.
CVE-2016-15051 1 Nagios 1 Nagios Xi 2025-11-05 N/A 5.4 MEDIUM
Nagios XI versions prior to 5.2.4 are vulnerable to cross-site scripting (XSS) via the Reports interface through values from the startdate and enddate fields. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
CVE-2016-15052 1 Nagios 1 Nagios Xi 2025-11-05 N/A 5.4 MEDIUM
Nagios XI versions prior to 5.2.4 are vulnerable to cross-site scripting (XSS) via the Menu System of the web interface. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
CVE-2016-15053 1 Nagios 1 Nagios Xi 2025-11-05 N/A 5.4 MEDIUM
Nagios XI versions prior to 5.2.4 are vulnerable to cross-site scripting (XSS) via the “My Reports” listing of the web interface. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
CVE-2018-25121 1 Nagios 1 Nagios Xi 2025-11-05 N/A 5.4 MEDIUM
Nagios XI versions prior to 5.4.13 are vulnerable to cross-site scripting (XSS) via the Views page of the web interface. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.