Latest CVE Feed
-
7.3
HIGHCVE-2023-7231
The illi Link Party! WordPress plugin through 1.0 lacks proper access controls, allowing unauthenticated visitors to delete links.... Read more
- Published: May. 15, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Authorization
-
6.1
MEDIUMCVE-2024-34067
Pterodactyl is a free, open-source game server management panel built with PHP, React, and Go. Importing a malicious egg or gaining access to wings instance could lead to cross site scripting (XSS) on the panel, which could be used to gain an administrato... Read more
Affected Products : panel- Published: May. 03, 2024
- Modified: Jun. 06, 2025
-
7.5
HIGHCVE-2024-6236
Denial of Service in NetScaler Console (formerly NetScaler ADM), NetScaler Agent, and NetScaler SDX... Read more
- Published: Jul. 10, 2024
- Modified: Jun. 06, 2025
-
6.1
MEDIUMCVE-2024-20382
A vulnerability in the VPN web client services feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack aga... Read more
- Published: Oct. 23, 2024
- Modified: Jun. 06, 2025
-
8.6
HIGHCVE-2025-23103
An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bounds writes.... Read more
- Published: Jun. 03, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Memory Corruption
-
8.6
HIGHCVE-2025-23107
An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bounds writes.... Read more
- Published: Jun. 03, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-5573
A vulnerability was found in D-Link DCS-932L 2.18.01. It has been rated as critical. Affected by this issue is the function setSystemWizard/setSystemControl of the file /setSystemWizard. The manipulation of the argument AdminID leads to os command injecti... Read more
- Published: Jun. 04, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Injection
-
9.0
HIGHCVE-2025-5572
A vulnerability was found in D-Link DCS-932L 2.18.01. It has been declared as critical. Affected by this vulnerability is the function setSystemEmail of the file /setSystemEmail. The manipulation of the argument EmailSMTPPortNumber leads to stack-based bu... Read more
- Published: Jun. 04, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Memory Corruption
-
4.8
MEDIUMCVE-2025-5543
A vulnerability was found in TOTOLINK X2000R 1.0.0-B20230726.1108. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Parent Controls Page. The manipulation of the argument Device Name leads to... Read more
- Published: Jun. 03, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-5542
A vulnerability was found in TOTOLINK X2000R 1.0.0-B20230726.1108. It has been classified as problematic. Affected is an unknown function of the file /boafrm/formPortFw of the component Virtual Server Page. The manipulation of the argument service_type le... Read more
- Published: Jun. 03, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Cross-Site Scripting
-
9.1
CRITICALCVE-2025-23097
An issue was discovered in Samsung Mobile Processor Exynos 1380. The lack of a length check leads to out-of-bounds writes.... Read more
- Published: Jun. 03, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-23100
An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400. The absence of a NULL check leads to a Denial of Service.... Read more
- Published: Jun. 03, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Denial of Service
-
7.8
HIGHCVE-2025-23098
An issue was discovered in Samsung Mobile Processor Exynos 980, 990, 1080, 2100, 1280, 2200, 1380. A Use-After-Free in the mobile processor leads to privilege escalation.... Read more
Affected Products : exynos_980_firmware exynos_1080_firmware exynos_2100_firmware exynos_2200_firmware exynos_1280_firmware exynos_1380_firmware exynos_980 exynos_990_firmware exynos_990 exynos_1080 +4 more products- Published: Jun. 03, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-5663
A vulnerability has been found in PHPGurukul Auto Taxi Stand Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/search-autoortaxi.php. The manipulation of the argument searchdata leads to sql injec... Read more
Affected Products : auto\/taxi_stand_management_system- Published: Jun. 05, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-5660
A vulnerability, which was classified as critical, has been found in PHPGurukul Complaint Management System 2.0. Affected by this issue is some unknown functionality of the file /user/register-complaint.php. The manipulation of the argument noc leads to s... Read more
Affected Products : complaint_management_system- Published: Jun. 05, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-5659
A vulnerability classified as critical was found in PHPGurukul Complaint Management System 2.0. Affected by this vulnerability is an unknown functionality of the file /user/profile.php. The manipulation of the argument pincode leads to sql injection. The ... Read more
Affected Products : complaint_management_system- Published: Jun. 05, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-5652
A vulnerability, which was classified as critical, was found in PHPGurukul Complaint Management System 2.0. Affected is an unknown function of the file /admin/between-date-complaintreport.php. The manipulation of the argument fromdate/todate leads to sql ... Read more
Affected Products : complaint_management_system- Published: Jun. 05, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-22533
Before Beetl v3.15.12, the rendering template has a server-side template injection (SSTI) vulnerability. When the incoming template is controllable, it will be filtered by the DefaultNativeSecurityManager blacklist. Because blacklist filtering is not stri... Read more
Affected Products : beetl- Published: Feb. 02, 2024
- Modified: Jun. 06, 2025
-
9.8
CRITICALCVE-2023-51955
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formSetIptv.... Read more
- Published: Jan. 10, 2024
- Modified: Jun. 06, 2025
-
8.8
HIGHCVE-2023-48909
An issue was discovered in Jave2 version 3.3.1, allows attackers to execute arbitrary code via the FFmpeg function.... Read more
Affected Products : jave2- Published: Jan. 12, 2024
- Modified: Jun. 06, 2025