Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions.
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions.
Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions.
Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions.
Subscriber Broken Access Control in Homlisti <= 3.1.2 versions.
Unauthenticated Broken Access Control in Chaplin <= 2.6.8 versions.
Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.
Unauthenticated Broken Access Control in Koji <= 2.2.1 versions.
Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions.
Subscriber Cross Site Scripting (XSS) in WP BASE Booking <= 6.3.2 versions.
Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions.
Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions.
Unauthenticated Broken Access Control in WP Data Access <= 5.5.80 versions.
A vulnerability was identified in D-Link DIR-842 2.01.B04. This impacts an unknown function of the file /etc/vsftpd.conf of the component vsftpd. Such manipulation leads to incorrect default permissions. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is said to be difficult.
Unauthenticated Cross Site Scripting (XSS) in GeoDirectory <= 2.8.173 versions.
A vulnerability has been found in SpaceX Starlink Router Gen 3 2025.11.14.mr64708.3. This affects the function get_status of the component gRPC Management Interface. The manipulation leads to improper access controls. The attack can only be initiated within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was detected in code-projects Online Food Order System 1.0. The affected element is an unknown function of the file edit_food_items.php. Performing a manipulation of the argument dname results in cross site scripting. Remote exploitation of the attack is possible. The exploit is now public and may be used.
Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions.
A vulnerability was determined in OpenBoxes up to 0.9.7. This affects the function needManager of the file grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy of the component Role Interceptor. Executing a manipulation can lead to improper privilege management. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. Upgrading to version 0.9.8-hotfix1 and 0.9.8 mitigates this issue. This patch is called 788cace0af816aa972a713a4631c57f16f89