Latest CVE Feed
-
9.8
CRITICALCVE-2025-4466
A vulnerability was found in itsourcecode Gym Management System 1.0. It has been classified as critical. This affects an unknown part of the file /ajax.php?action=save_payment. The manipulation of the argument registration_id leads to sql injection. It is... Read more
Affected Products : gym_management_system- Published: May. 09, 2025
- Modified: May. 16, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4191
A vulnerability has been found in PHPGurukul Employee Record Management System 1.3 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /editmyeducation.php. The manipulation of the argument coursepg/yophsc le... Read more
Affected Products : employee_record_management_system- Published: May. 02, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4114
A vulnerability classified as critical has been found in Netgear JWNR2000v2 1.0.0.11. Affected is the function check_language_file. The manipulation of the argument host leads to buffer overflow. It is possible to launch the attack remotely. The vendor wa... Read more
- Published: Apr. 30, 2025
- Modified: May. 28, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4347
A vulnerability was found in D-Link DIR-600L up to 2.07B01. It has been declared as critical. Affected by this vulnerability is the function formWlSiteSurvey. The manipulation of the argument host leads to buffer overflow. The attack can be launched remot... Read more
- Published: May. 06, 2025
- Modified: May. 12, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4181
A vulnerability was found in PCMan FTP Server 2.0.7. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component SEND Command Handler. The manipulation leads to buffer overflow. The attack can be launched ... Read more
- Published: May. 01, 2025
- Modified: May. 13, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4117
A vulnerability, which was classified as critical, was found in Netgear JWNR2000v2 1.0.0.11. This affects the function sub_41A914. The manipulation of the argument host leads to buffer overflow. The vendor was contacted early about this disclosure but did... Read more
- Published: Apr. 30, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4297
A vulnerability was found in PHPGurukul Men Salon Management System 2.0. It has been classified as critical. This affects an unknown part of the file /admin/change-password.php. The manipulation leads to sql injection. It is possible to initiate the attac... Read more
Affected Products : men_salon_management_system- Published: May. 05, 2025
- Modified: May. 16, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4140
A vulnerability, which was classified as critical, has been found in Netgear EX6120 1.0.3.94. Affected by this issue is the function sub_30394. The manipulation of the argument host leads to buffer overflow. The attack may be launched remotely. The vendor... Read more
- Published: Apr. 30, 2025
- Modified: May. 12, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4380
The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.89 via the 'bsa_template' parameter of the `bsa_preview_callback` function. This makes it p... Read more
Affected Products : ads_pro- Published: Jul. 02, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-4359
A vulnerability classified as critical was found in itsourcecode Gym Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=delete_member. The manipulation of the argument ID leads to sql injection. ... Read more
Affected Products : gym_management_system- Published: May. 06, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4238
A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as critical. This affects an unknown part of the component MGET Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exp... Read more
- Published: May. 03, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4066
A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/addpackage.php. The manipulation leads to improper access controls. The attack may be init... Read more
Affected Products : online_traveling_system- Published: Apr. 29, 2025
- Modified: May. 12, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-4079
A vulnerability, which was classified as critical, was found in PCMan FTP Server up to 2.0.7. Affected is an unknown function of the component RENAME Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely.... Read more
- Published: Apr. 29, 2025
- Modified: May. 12, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4309
A vulnerability was found in PHPGurukul Art Gallery Management System 1.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/add-art-type.php. The manipulation of the argument arttype leads to sql injec... Read more
Affected Products : art_gallery_management_system- Published: May. 06, 2025
- Modified: May. 09, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4144
PKCE was implemented in the OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp . However, it was found that an attacker could cause the check to be skipped. Fixed in: https://gith... Read more
Affected Products : workers-oauth-provider- Published: May. 01, 2025
- Modified: May. 12, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-4070
A vulnerability, which was classified as critical, was found in PHPGurukul Rail Pass Management System 1.0. This affects an unknown part of the file /admin/changeimage.php. The manipulation of the argument editid leads to sql injection. It is possible to ... Read more
Affected Products : rail_pass_management_system- Published: Apr. 29, 2025
- Modified: May. 09, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4013
A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/aboutus.php. The manipulation of the argument pagetitle leads to sql injection. It is possibl... Read more
Affected Products : art_gallery_management_system- Published: Apr. 28, 2025
- Modified: May. 12, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4226
A vulnerability classified as critical has been found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. This affects an unknown part of the file /add-computer.php. The manipulation of the argument compname/comploc leads to sql injection. It is pos... Read more
Affected Products : cyber_cafe_management_system- Published: May. 03, 2025
- Modified: May. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-49839
GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe deserialization vulnerability in bsroformer.py. The model_choose variable takes user input (e.g. a path to a model) and passes it to the ... Read more
Affected Products : gpt-sovits-webui- Published: Jul. 15, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-4052
Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a crafted HTML page. (Chromium security severity: ... Read more
- Published: May. 05, 2025
- Modified: May. 28, 2025
- Vuln Type: Authorization