Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2025-03-04 CVE-2025-1321 SQL Injection vulnerability in Mtrv Teachpress
The teachPress plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tpsearch' shortcode in all versions up to, and including, 9.0.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
mtrv CWE-89
8.8
2025-03-04 CVE-2025-1639 Missing Authorization vulnerability in Crowdytheme Arolax
The Animation Addons for Elementor Pro plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the install_elementor_plugin_handler() function in all versions up to, and including, 1.6.
network
low complexity
crowdytheme CWE-862
8.8
2025-03-04 CVE-2025-1900 Unspecified vulnerability in PHPgurukul Restaurant Table Booking System 1.0
A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0 and classified as critical.
network
low complexity
phpgurukul
critical
9.8
2025-03-04 CVE-2025-1901 Unspecified vulnerability in PHPgurukul Restaurant Table Booking System 1.0
A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0.
network
low complexity
phpgurukul
critical
9.8
2025-03-04 CVE-2025-1902 Unspecified vulnerability in PHPgurukul Student Record System 3.2
A vulnerability was found in PHPGurukul Student Record System 3.2.
network
low complexity
phpgurukul
critical
9.8
2025-03-04 CVE-2025-1903 Unspecified vulnerability in Codezips Online Shopping Website 1.0
A vulnerability was found in Codezips Online Shopping Website 1.0.
network
low complexity
codezips
critical
9.8
2025-03-04 CVE-2025-20011 Memory Leak vulnerability in Openatom Openharmony
in OpenHarmony v5.0.2 and prior versions allow a local attacker case DOS through missing release of memory.
local
low complexity
openatom CWE-401
5.5
2025-03-04 CVE-2025-20021 Out-of-bounds Read vulnerability in Openatom Openharmony
in OpenHarmony v5.0.2 and prior versions allow a local attacker cause DOS through out-of-bounds read.
local
low complexity
openatom CWE-125
5.5
2025-03-04 CVE-2025-20024 Integer Overflow or Wraparound vulnerability in Openatom Openharmony
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through integer overflow.
local
low complexity
openatom CWE-190
5.3
2025-03-04 CVE-2025-20042 Out-of-bounds Read vulnerability in Openatom Openharmony
in OpenHarmony v5.0.2 and prior versions allow a local attacker cause information leak through out-of-bounds read.
local
low complexity
openatom CWE-125
5.5