Latest CVE Feed
-
9.8
CRITICALCVE-2025-48471
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, the application does not check or performs insufficient checking of files uploaded to the application. This allows files to be uploaded with the phtml and phar extensi... Read more
Affected Products : freescout- Published: May. 29, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-5371
A vulnerability, which was classified as critical, has been found in SourceCodester Health Center Patient Record Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/admin.php. The manipulation of the argument Use... Read more
- Published: May. 31, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5430
A vulnerability, which was classified as critical, has been found in AssamLook CMS 1.0. This issue affects some unknown processing of the file /product.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. ... Read more
Affected Products : assamlook_cms- Published: Jun. 02, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5441
A vulnerability classified as critical was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This vulnerability affects the function setDeviceURL of the file /goform/setDeviceURL. T... Read more
Affected Products : re6500_firmware re6300_firmware re6300 re6500 re9000_firmware re9000 re6250_firmware re6250 re6350_firmware re6350 +2 more products- Published: Jun. 02, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-37090
A server-side request forgery vulnerability exists in HPE StoreOnce Software.... Read more
Affected Products : storeonce_system- Published: Jun. 02, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Server-Side Request Forgery
-
9.8
CRITICALCVE-2025-5447
A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been declared as critical. This vulnerability affects the function ssid1MACFilter of the file /goform/ss... Read more
Affected Products : re6500_firmware re6300_firmware re6300 re6500 re9000_firmware re9000 re6250_firmware re6250 re6350_firmware re6350 +2 more products- Published: Jun. 02, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5493
A vulnerability was found in Baison Channel Middleware Product 2.0.1 and classified as critical. Affected by this issue is some unknown functionality of the file /e3api/api/main/ToJsonByControlName. The manipulation of the argument data leads to sql injec... Read more
Affected Products : channel_middleware_product- Published: Jun. 03, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-49001
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.10, secret verification does not take effect successfully, so a user can use any secret to forge a JWT token. The vulnerability has been fixed in v2.10.10.... Read more
Affected Products : dataease- Published: Jun. 03, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-5551
A vulnerability was found in FreeFloat FTP Server 1.0. It has been classified as critical. This affects an unknown part of the component SYSTEM Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The... Read more
- Published: Jun. 04, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-5553
A vulnerability classified as critical was found in PHPGurukul Rail Pass Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /download-pass.php. The manipulation of the argument searchdata leads to sql injection. ... Read more
Affected Products : rail_pass_management_system- Published: Jun. 04, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5561
A vulnerability was found in PHPGurukul Curfew e-Pass Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/view-pass-detail.php. The manipulation of the argument viewid lead... Read more
Affected Products : curfew_e-pass_management_system- Published: Jun. 04, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5583
A vulnerability classified as critical has been found in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the file /register.php. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exp... Read more
- Published: Jun. 04, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5592
A vulnerability, which was classified as critical, has been found in FreeFloat FTP Server 1.0. Affected by this issue is some unknown functionality of the component PASSIVE Command Handler. The manipulation leads to buffer overflow. The attack may be laun... Read more
- Published: Jun. 04, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-5593
A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. This affects an unknown part of the component HOST Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The ex... Read more
- Published: Jun. 04, 2025
- Modified: Jun. 13, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-5603
A vulnerability has been found in Campcodes Hospital Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /registration.php. The manipulation of the argument full_name/username leads to s... Read more
- Published: Jun. 04, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5620
A vulnerability, which was classified as critical, was found in D-Link DIR-816 1.10CNB05. Affected is the function setipsec_config of the file /goform/setipsec_config. The manipulation of the argument localIP/remoteIP leads to os command injection. It is ... Read more
- Published: Jun. 05, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5626
A vulnerability classified as critical has been found in Campcodes Online Teacher Record Management System 1.0. Affected is an unknown function of the file /admin/edit-subjects-detail.php. The manipulation of the argument editid leads to sql injection. It... Read more
Affected Products : online_teacher_record_management_system- Published: Jun. 05, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5635
A vulnerability classified as critical was found in PCMan FTP Server 2.0.7. This vulnerability affects unknown code of the component PLS Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remotely. The exploit has been... Read more
- Published: Jun. 05, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-5667
A vulnerability was found in FreeFloat FTP Server 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the component REIN Command Handler. The manipulation leads to buffer overflow. The attack may be launched remotel... Read more
- Published: Jun. 05, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-5685
A vulnerability, which was classified as critical, was found in Tenda CH22 1.0.0.1. This affects the function formNatlimit of the file /goform/Natlimit. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to initiate... Read more
- Published: Jun. 05, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Memory Corruption