Latest CVE Feed
-
9.8
CVSS31CVE-2025-29660
A vulnerability exists in the daemon process of the Yi IOT XY-3820 v6.0.24.10, which exposes a TCP service on port 6789. This service lacks proper input validation, allowing attackers to execute arbitrary scripts present on the device by sending specially... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 21, 2025
-
9.8
CVSS31CVE-2025-29287
An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file.... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 21, 2025
-
9.8
CVSS31CVE-2025-29659
Yi IOT XY-3820 6.0.24.10 is vulnerable to Remote Command Execution via the "cmd_listen" function located in the "cmd" binary.... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 21, 2025
-
8.8
CVSS31CVE-2025-3820
A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644) and classified as critical. Affected by this issue is the function cgiSysUplinkCheckSet of the file /bin/httpd. The manipulation of the argument hostIp1/hostIp2 leads to stack-base... Read more
Affected Products :- Published: Apr. 19, 2025
- Modified: Apr. 21, 2025
-
8.6
CVSS31CVE-2025-43971
An issue was discovered in GoBGP before 3.35.0. pkg/packet/bgp/bgp.go allows attackers to cause a panic via a zero value for softwareVersionLen.... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 21, 2025
-
8.1
CVSS31CVE-2025-43922
The FileWave Windows client before 16.0.0, in some non-default configurations, allows an unprivileged local user to escalate privileges to SYSTEM.... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 21, 2025
-
7.5
CVSS31CVE-2025-3857
When reading binary Ion data through Amazon.IonDotnet using the RawBinaryReader class, Amazon.IonDotnet does not check the number of bytes read from the underlying stream while deserializing the binary format. If the Ion data is malformed or truncated, th... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 21, 2025
-
7.5
CVSS31CVE-2025-23174
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 21, 2025
-
7.3
CVSS31CVE-2025-3828
A vulnerability was found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/view-appointment.php?viewid=11. The manipulation of the argument remark leads to sql injectio... Read more
Affected Products : men_salon_management_system- Published: Apr. 20, 2025
- Modified: Apr. 21, 2025
-
7.3
CVSS31CVE-2025-3819
A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/search-appointment.php. The manipulation of the argument searchdata lead... Read more
Affected Products : men_salon_management_system- Published: Apr. 19, 2025
- Modified: Apr. 21, 2025
-
7.3
CVSS31CVE-2025-3827
A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/forgot-password.php. The manipulation of the argument email leads to sql injection. The att... Read more
Affected Products : men_salon_management_system- Published: Apr. 20, 2025
- Modified: Apr. 21, 2025
-
7.3
CVSS31CVE-2025-3829
A vulnerability was found in PHPGurukul Men Salon Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/sales-reports-detail.php. The manipulation of the argument fromdate/todate leads to sql injecti... Read more
Affected Products : men_salon_management_system- Published: Apr. 20, 2025
- Modified: Apr. 21, 2025
-
6.8
CVSS31CVE-2025-43973
An issue was discovered in GoBGP before 3.35.0. pkg/packet/rtr/rtr.go does not verify that the input length corresponds to a situation in which all bytes are available for an RTR message.... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 21, 2025
-
6.8
CVSS31CVE-2025-43972
An issue was discovered in GoBGP before 3.35.0. An attacker can cause a crash in the pkg/packet/bgp/bgp.go flowspec parser by sending fewer than 20 bytes in a certain context.... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 21, 2025
-
6.5
CVSS31CVE-2025-28367
mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller - ImageHandler Action. An attacker can exploit this vulnerability to access the Web.Config file and obtain the MachineKey.... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 21, 2025
-
6.5
CVSS31CVE-2024-42699
Cross Site Scripting vulnerability in Create/Modify article function in Alkacon OpenCMS 17.0 allows remote attacker to inject javascript payload via image title sub-field in the image field... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 21, 2025
-
6.4
CVSS31CVE-2025-43918
SSL.com before 2025-04-19, when domain validation method 3.2.2.4.14 is used, processes certificate requests such that a trusted TLS certificate may be issued for the domain name of a requester's email address, even when the requester does not otherwise es... Read more
Affected Products :- Published: Apr. 19, 2025
- Modified: Apr. 21, 2025
-
6.3
CVSS31CVE-2025-3818
A vulnerability, which was classified as critical, was found in webpy web.py 0.70. Affected is the function PostgresDB._process_insert_query of the file web/db.py. The manipulation of the argument seqname leads to sql injection. It is possible to launch t... Read more
Affected Products :- Published: Apr. 19, 2025
- Modified: Apr. 21, 2025
-
6.3
CVSS31CVE-2025-3830
A vulnerability was found in kuangstudy KuangSimpleBBS 1.0. It has been declared as critical. Affected by this vulnerability is the function fileUpload of the file src/main/java/com/kuang/controller/QuestionController.java. The manipulation of the argumen... Read more
Affected Products :- Published: Apr. 20, 2025
- Modified: Apr. 21, 2025
-
6.1
CVSS31CVE-2025-28121
code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) in feedback.php via the "q" parameter allowing remote attackers to execute arbitrary code.... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 21, 2025