Post

2025-12-24 Daily Vulns

NEW:

CVEvendor-productdescriptionmetricReferenceurltitleGithubURL 
CVE-2021-47720Orangescrum - orangescrumOrangescrum 1.8.0 contains an authenticated SQL injection vulnerability that allows authorized users to manipulate database queries through multiple vulnerable parameters. Attackers can inject malicious SQL code into parameters like old_project_id, project_id, uuid, and uniqid to potentially extract or modify database information.CVSS4.0: 8.7 - HIGH CVSS3.1: 7.1 - HIGH0 1 2Exploitation: pocAutomatable: noTechnical Impact: partialOrangescrum 1.8.0 Authenticated SQL Injection via Multiple Parametersgithub
CVE-2025-25364n/a - n/aA command injection vulnerability in the me.connectify.SMJobBlessHelper XPC service of Speedify VPN up to v15.0.0 allows attackers to execute arbitrary commands with root-level privileges.CNA n/a CVSS3.1: 8.4 - HIGH0 1 2Exploitation: noneAutomatable: noTechnical Impact: totalundefinedgithub
CVE-2023-52210Tyche softwares - Product Delivery Date for WooCommerce – LiteVulnerability in Tyche softwares Product Delivery Date for WooCommerce – Lite.This issue affects Product Delivery Date for WooCommerce – Lite: from n/a through 2.7.0.CVSS3.1: 5.3 - MEDIUM0Exploitation: noneAutomatable: yesTechnical Impact: partialWordPress Product Delivery Date for WooCommerce – Lite plugin <= 2.7.0 - Broken Access Control vulnerabilitygithub
This post is licensed under CC BY 4.0 by the author.