Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2025-03-04 CVE-2025-1904 Unspecified vulnerability in Code-Projects Blood Bank System 1.0
A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank System 1.0.
network
low complexity
code-projects
6.1
2025-03-04 CVE-2025-1905 Unspecified vulnerability in Remyandrade Employee Management System 1.0
A vulnerability, which was classified as problematic, was found in SourceCodester Employee Management System 1.0.
network
low complexity
remyandrade
6.1
2025-03-04 CVE-2025-1906 Unspecified vulnerability in PHPgurukul Restaurant Table Booking System 1.0
A vulnerability has been found in PHPGurukul Restaurant Table Booking System 1.0 and classified as critical.
network
low complexity
phpgurukul
critical
9.8
2025-03-04 CVE-2024-13686 The VW Storefront theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vw_storefront_reset_all_settings() function in all versions up to, and including, 0.9.9.
network
low complexity
CWE-862
4.3
2025-03-04 CVE-2025-0587 Integer Overflow or Wraparound vulnerability in Openatom Openharmony
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through integer overflow.
local
low complexity
openatom CWE-190
7.8
2025-03-04 CVE-2025-0912 Deserialization of Untrusted Data vulnerability in Givewp
The Donations Widget plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.19.4 via deserialization of untrusted input from the Donation Form through the 'card_address' parameter.
network
low complexity
givewp CWE-502
critical
9.8
2025-03-04 CVE-2025-1321 SQL Injection vulnerability in Mtrv Teachpress
The teachPress plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tpsearch' shortcode in all versions up to, and including, 9.0.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
mtrv CWE-89
8.8
2025-03-04 CVE-2025-1639 Missing Authorization vulnerability in Crowdytheme Arolax
The Animation Addons for Elementor Pro plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the install_elementor_plugin_handler() function in all versions up to, and including, 1.6.
network
low complexity
crowdytheme CWE-862
8.8
2025-03-04 CVE-2025-1900 Unspecified vulnerability in PHPgurukul Restaurant Table Booking System 1.0
A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0 and classified as critical.
network
low complexity
phpgurukul
critical
9.8
2025-03-04 CVE-2025-1901 Unspecified vulnerability in PHPgurukul Restaurant Table Booking System 1.0
A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0.
network
low complexity
phpgurukul
critical
9.8