A vulnerability labeled as critical has been found in code-projects Student File Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/login_query.php. Executing manipulation of the argument Username can lead to sql injection.
The identification of this vulnerability is CVE-2025-14620. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability identified as critical has been detected in code-projects Student File Management System 1.0. Affected by this vulnerability is an unknown functionality of the file login_query.php. Performing manipulation of the argument stud_no results in sql injection.
This vulnerability was named CVE-2025-14619. The attack may be initiated remotely. In addition, an exploit is available.
A vulnerability categorized as problematic has been discovered in Jehovahs Witnesses JW Library App up to 15.5.1 on Android. Affected is an unknown function of the component org.jw.jwlibrary.mobile.activity.SiloContainer. Such manipulation leads to path traversal.
This vulnerability is uniquely identified as CVE-2025-14617. Local access is required to approach this attack. Moreover, an exploit is present.
A vulnerability was found in CISA Software Acquisition Guide Tool. It has been rated as problematic. This impacts an unknown function of the component JSON File Parser. This manipulation causes cross site scripting.
This vulnerability is handled as CVE-2025-67634. It is possible to launch the attack on the local host. There is not any exploit available.
This product is a managed service. It is not possible for users to maintain vulnerability countermeasures themselves. Upgrading the affected component is advised.
A vulnerability was found in MarqueeAddons Plugin up to 2.4.3 on WordPress. It has been declared as problematic. This affects an unknown function of the component Testimonial Marquee Widget. The manipulation results in cross site scripting.
This vulnerability is known as CVE-2025-8199. It is possible to launch the attack remotely. No exploit is available.
A vulnerability was found in Brizy Plugin up to 2.7.16 on WordPress. It has been classified as problematic. The impacted element is the function get_users. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2025-0969. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in KingAddons King Addons for Elementor Plugin up to 51.1.39 on WordPress and classified as problematic. The affected element is an unknown function of the component Widget. Executing manipulation can lead to cross site scripting.
This vulnerability appears as CVE-2025-7960. The attack may be performed from remote. There is no available exploit.
A vulnerability has been found in Enter Addons Plugin up to 2.2.7 on WordPress and classified as problematic. Impacted is an unknown function of the component Image Comparison Widget. Performing manipulation results in cross site scripting.
This vulnerability is reported as CVE-2025-8687. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability, which was classified as problematic, was found in Popup Builder Plugin up to 4.4.1 on WordPress. This issue affects the function sg_popup of the component Shortcode Handler. Such manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2025-9856. The attack can be executed remotely. There is not any exploit available.
A vulnerability, which was classified as problematic, has been found in Livemesh SiteOrigin Widgets Plugin up to 3.9.1 on WordPress. This vulnerability affects unknown code of the component Pricing Table Widget. This manipulation causes cross site scripting.
This vulnerability is registered as CVE-2025-8780. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability classified as problematic was found in JetWidgets for Elementor Plugin up to 1.0.20 on WordPress. This affects an unknown part of the component Subscribe Widget. The manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2025-8195. The attack may be launched remotely. There is no exploit available.