Common Vulnerabilities and Exposures (CVE)

CVE-2025-7634

Oct 9, 2025 05:23:53 UTC

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 6.6.7 via the mode parameter. This makes it possible for unauthenticated at...

CVE-2025-7526

Oct 9, 2025 05:23:52 UTC

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to arbitrary file deletion (via renaming) due to insufficient file path validation in the set_user_profile_image function in all versions...

CVE-2021-43798

Oct 9, 2025 03:55:39 UTC

Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is:...

CVE-2025-11530

Oct 9, 2025 03:32:05 UTC

A weakness has been identified in code-projects Online Complaint Site 1.0. Affected is an unknown function of the file /cms/admin/state.php. This manipulation of the argument state causes sql injection. The attack is possible to be carried ...

CVE-2025-6038

Oct 9, 2025 03:23:30 UTC

The Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme plugin for WordPress is vulnerable to privilege escalation via password update in all versions up to, and including, 1.4.0. This is due to the plugin not p...

CVE-2025-47355

Oct 9, 2025 03:18:16 UTC

Memory corruption while invoking remote procedure IOCTL calls.

CVE-2025-47354

Oct 9, 2025 03:18:15 UTC

Memory corruption while allocating buffers in DSP service.

CVE-2025-47351

Oct 9, 2025 03:18:14 UTC

Memory corruption while processing user buffers.

CVE-2025-47349

Oct 9, 2025 03:18:13 UTC

Memory corruption while processing an escape call.

CVE-2025-47347

Oct 9, 2025 03:18:11 UTC

Memory corruption while processing control commands in the virtual memory management interface.

CVE-2025-47342

Oct 9, 2025 03:18:10 UTC

Transient DOS may occur when multi-profile concurrency arises with QHS enabled.

CVE-2025-47341

Oct 9, 2025 03:18:09 UTC

memory corruption while processing an image encoding completion event.

CVE-2025-47340

Oct 9, 2025 03:18:08 UTC

Memory corruption while processing IOCTL call to get the mapping.

CVE-2025-47338

Oct 9, 2025 03:18:07 UTC

Memory corruption while processing escape commands from userspace.

CVE-2025-27060

Oct 9, 2025 03:18:06 UTC

Memory corruption while performing SCM call with malformed inputs.