A vulnerability classified as problematic has been found in Bharti Airtel Thanks App 4.105.4 on Android. Affected is an unknown function of the file /Android/data/com.myairtelapp/files/. The manipulation leads to cleartext storage in a file or on disk.
This vulnerability is traded as CVE-2025-6748. It is possible to launch the attack on the physical device. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in Osom Blocks Plugin up to 1.2.1 on WordPress. It has been rated as problematic. This issue affects some unknown processing. The manipulation of the argument class_name leads to cross site scripting.
The identification of this vulnerability is CVE-2025-5940. The attack may be initiated remotely. There is no exploit available.
A vulnerability was found in Pack Elementor Addon Plugin up to 2.1.3 on WordPress. It has been declared as problematic. This vulnerability affects unknown code. The manipulation of the argument slider_options leads to cross site scripting.
This vulnerability was named CVE-2025-6550. The attack can be initiated remotely. There is no exploit available.
A vulnerability was found in AB Testing Plugin up to 1.18.2 on WordPress. It has been classified as problematic. This affects an unknown part. The manipulation of the argument ID leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-4587. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in FL3R Accessibility Suite Plugin up to 1.4 on WordPress and classified as problematic. Affected by this issue is the function fl3raccessibilitysuite of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-6689. The attack may be launched remotely. There is no exploit available.
A vulnerability has been found in VR Calendar Plugin up to 2.4.7 on WordPress and classified as problematic. Affected by this vulnerability is the function syncCalendar of the component Calendar Syncinfo. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2025-5936. The attack can be launched remotely. There is no exploit available.
A vulnerability, which was classified as problematic, was found in isMobile Plugin up to 1.1.1 on WordPress. Affected is an unknown function. The manipulation of the argument device leads to cross site scripting.
This vulnerability is traded as CVE-2025-6488. It is possible to launch the attack remotely. There is no exploit available.
A vulnerability, which was classified as problematic, has been found in DWT Directory & Listing WordPress Theme up to 3.3.6 on WordPress. This issue affects the function dwt_listing_reset_password of the component Setting Handler. The manipulation leads to weak password recovery.
The identification of this vulnerability is CVE-2024-12827. The attack may be initiated remotely. There is no exploit available.
A vulnerability classified as critical was found in Simple Payment Plugin up to 2.3.8 on WordPress. This vulnerability affects the function create_user. The manipulation leads to improper authentication.
This vulnerability was named CVE-2025-6688. The attack can be initiated remotely. There is no exploit available.
A vulnerability classified as problematic has been found in Microsoft Edge. This affects an unknown part. The manipulation leads to improper input validation.
This vulnerability is uniquely identified as CVE-2025-47182. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Microsoft Edge. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to Remote Code Execution.
This vulnerability is known as CVE-2025-47964. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in OpenNMS Horizon and Meridian. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to sql injection.
This vulnerability is handled as CVE-2025-53122. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Microsoft Edge. It has been classified as critical. Affected is an unknown function. The manipulation leads to Remote Code Execution.
This vulnerability is traded as CVE-2025-47963. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Northern.tech Mender Server up to 3.7.10/4.0.0 and classified as critical. This issue affects some unknown processing. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2025-49603. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in n8n up to 1.97.x and classified as problematic. This vulnerability affects unknown code of the file /signin of the component Query Parameter Handler. The manipulation leads to open redirect.
This vulnerability was named CVE-2025-49592. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, was found in IROAD Dashcam FX2. This affects an unknown part of the component File Upload Endpoint. The manipulation leads to unrestricted upload.
This vulnerability is uniquely identified as CVE-2025-30131. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability, which was classified as critical, has been found in octo-sts app up to 0.5.2. Affected by this issue is some unknown functionality. The manipulation leads to server-side request forgery.
This vulnerability is handled as CVE-2025-52477. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.