Latest CVE Feed
-
9.8
CRITICALCVE-2025-4079
A vulnerability, which was classified as critical, was found in PCMan FTP Server up to 2.0.7. Affected is an unknown function of the component RENAME Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely.... Read more
- Published: Apr. 29, 2025
- Modified: May. 12, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4309
A vulnerability was found in PHPGurukul Art Gallery Management System 1.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/add-art-type.php. The manipulation of the argument arttype leads to sql injec... Read more
Affected Products : art_gallery_management_system- Published: May. 06, 2025
- Modified: May. 09, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4144
PKCE was implemented in the OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp . However, it was found that an attacker could cause the check to be skipped. Fixed in: https://gith... Read more
Affected Products : workers-oauth-provider- Published: May. 01, 2025
- Modified: May. 12, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-4070
A vulnerability, which was classified as critical, was found in PHPGurukul Rail Pass Management System 1.0. This affects an unknown part of the file /admin/changeimage.php. The manipulation of the argument editid leads to sql injection. It is possible to ... Read more
Affected Products : rail_pass_management_system- Published: Apr. 29, 2025
- Modified: May. 09, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4013
A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/aboutus.php. The manipulation of the argument pagetitle leads to sql injection. It is possibl... Read more
Affected Products : art_gallery_management_system- Published: Apr. 28, 2025
- Modified: May. 12, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4226
A vulnerability classified as critical has been found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. This affects an unknown part of the file /add-computer.php. The manipulation of the argument compname/comploc leads to sql injection. It is pos... Read more
Affected Products : cyber_cafe_management_system- Published: May. 03, 2025
- Modified: May. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-49839
GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe deserialization vulnerability in bsroformer.py. The model_choose variable takes user input (e.g. a path to a model) and passes it to the ... Read more
Affected Products : gpt-sovits-webui- Published: Jul. 15, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-4052
Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a crafted HTML page. (Chromium security severity: ... Read more
- Published: May. 05, 2025
- Modified: May. 28, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-4033
A vulnerability classified as critical has been found in PHPGurukul Nipah Virus Testing Management System 1.0. Affected is an unknown function of the file /patient-search-report.php. The manipulation of the argument searchdata leads to sql injection. It i... Read more
Affected Products : nipah_virus_testing_management_system- Published: Apr. 28, 2025
- Modified: May. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4263
A vulnerability was found in PHPGurukul Online DJ Booking Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/booking-search.php. The manipulation of the argument searchdata leads to sql inje... Read more
Affected Products : online_dj_booking_management_system- Published: May. 05, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-49710
An integer overflow was present in `OrderedHashTable` used by the JavaScript engine This vulnerability affects Firefox < 139.0.4.... Read more
Affected Products : firefox- Published: Jun. 11, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-49840
GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe deserialization vulnerability in inference_webui.py. The GPT_dropdown variable takes user input and passes it to the change_gpt_weights f... Read more
Affected Products : gpt-sovits-webui- Published: Jul. 15, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-49841
GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe deserialization vulnerability in process_ckpt.py. The SoVITS_dropdown variable takes user input and passes it to the load_sovits_new func... Read more
Affected Products : gpt-sovits-webui- Published: Jul. 15, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-49709
Certain canvas operations could have lead to memory corruption. This vulnerability affects Firefox < 139.0.4.... Read more
Affected Products : firefox- Published: Jun. 11, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-49216
An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as an admin user and modify product configurations on affected installations.... Read more
Affected Products : endpoint_encryption_policy_server- Published: Jun. 17, 2025
- Modified: Jun. 18, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-49223
billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.... Read more
Affected Products : billboard.js- Published: Jun. 04, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-49219
An insecure deserialization operation in Trend Micro Apex Central below versions 8.0.7007 could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49220 but is in a different m... Read more
Affected Products : apex_central- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-49212
An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49220 but is in a different m... Read more
Affected Products : endpoint_encryption_policy_server- Published: Jun. 17, 2025
- Modified: Jun. 18, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-49072
Deserialization of Untrusted Data vulnerability in AncoraThemes Mr. Murphy allows Object Injection.This issue affects Mr. Murphy: from n/a before 1.2.12.1.... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-48949
Navidrome is an open source web-based music collection server and streamer. Versions 0.55.0 through 0.55.2 have a vulnerability due to improper input validation on the `role` parameter within the API endpoint `/api/artist`. Attackers can exploit this flaw... Read more
Affected Products : navidrome- Published: May. 30, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Injection