CVE-2025-5763 |
Description: A vulnerability has been found in Tenda CP3 11.10.00.2311090948 and classified as critical. Affected by this vulnerability is the function sub_F3C8C of the file apollo. The manipulation leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. In Tenda CP3 11.10.00.2311090948 wurde eine Schwachstelle gefunden. Sie wurde als kritisch eingestuft. Es geht um die Funktion sub_F3C8C der Datei apollo. Mittels dem Manipulieren mit unbekannten Daten kann eine command injection-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk erfolgen. Der Exploit steht zur öffentlichen Verfügung.
CVSS: MEDIUM (4.7) EPSS Score: 0.43%
June 6th, 2025 (28 days ago)
|
CVE-2025-5762 |
Description: A vulnerability, which was classified as critical, was found in code-projects Patient Record Management System 1.0. Affected is an unknown function of the file view_hematology.php. The manipulation of the argument itr_no leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Es wurde eine Schwachstelle in code-projects Patient Record Management System 1.0 gefunden. Sie wurde als kritisch eingestuft. Betroffen hiervon ist ein unbekannter Ablauf der Datei view_hematology.php. Durch Manipulation des Arguments itr_no mit unbekannten Daten kann eine sql injection-Schwachstelle ausgenutzt werden. Umgesetzt werden kann der Angriff über das Netzwerk. Der Exploit steht zur öffentlichen Verfügung.
CVSS: MEDIUM (5.3) EPSS Score: 0.03%
June 6th, 2025 (28 days ago)
|
CVE-2025-49453 |
Description: Cross-Site Request Forgery (CSRF) vulnerability in Jatinder Pal Singh BP Profile as Homepage allows Stored XSS. This issue affects BP Profile as Homepage: from n/a through 1.1.
CVSS: HIGH (7.1) EPSS Score: 0.02%
June 6th, 2025 (28 days ago)
|
CVE-2025-49450 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mhallmann SEPA Girocode allows Stored XSS. This issue affects SEPA Girocode: from n/a through 0.5.1.
CVSS: MEDIUM (6.5) EPSS Score: 0.03%
June 6th, 2025 (28 days ago)
|
CVE-2025-49449 |
Description: Cross-Site Request Forgery (CSRF) vulnerability in WP Map Plugins Interactive Regional Map of Africa allows Cross Site Request Forgery. This issue affects Interactive Regional Map of Africa: from n/a through 1.0.
CVSS: MEDIUM (4.3) EPSS Score: 0.02%
June 6th, 2025 (28 days ago)
|
CVE-2025-49446 |
Description: Cross-Site Request Forgery (CSRF) vulnerability in minhlaobao Admin Notes allows Cross Site Request Forgery. This issue affects Admin Notes: from n/a through 1.1.
CVSS: MEDIUM (4.3) EPSS Score: 0.02%
June 6th, 2025 (28 days ago)
|
CVE-2025-49445 |
Description: Cross-Site Request Forgery (CSRF) vulnerability in WP Map Plugins Interactive UK Regional Map allows Cross Site Request Forgery. This issue affects Interactive UK Regional Map: from n/a through 2.0.
CVSS: MEDIUM (4.3) EPSS Score: 0.02%
June 6th, 2025 (28 days ago)
|
CVE-2025-49443 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chris McCoy Bacon Ipsum allows Stored XSS. This issue affects Bacon Ipsum: from n/a through 2.4.
CVSS: MEDIUM (6.5) EPSS Score: 0.03%
June 6th, 2025 (28 days ago)
|
CVE-2025-49442 |
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mostafa Shahiri Simple Nested Menu allows Stored XSS. This issue affects Simple Nested Menu: from n/a through 1.0.
CVSS: MEDIUM (6.5) EPSS Score: 0.03%
June 6th, 2025 (28 days ago)
|
CVE-2025-49441 |
Description: Missing Authorization vulnerability in WP Map Plugins Interactive Regional Map of Florida allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Interactive Regional Map of Florida: from n/a through 1.0.
CVSS: MEDIUM (5.3) EPSS Score: 0.04%
June 6th, 2025 (28 days ago)
|