Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2025-9011

    A vulnerability was determined in PHPGurukul Online Shopping Portal Project 2.0. Affected by this issue is some unknown functionality of the file /shopping/signup.php. The manipulation of the argument emailid leads to sql injection. The attack may be laun... Read more

    • Published: Aug. 15, 2025
    • Modified: Aug. 21, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-9012

    A vulnerability was identified in PHPGurukul Online Shopping Portal Project 2.0. This affects an unknown part of the file shopping/bill-ship-addresses.php. The manipulation of the argument billingpincode leads to sql injection. It is possible to initiate ... Read more

    • Published: Aug. 15, 2025
    • Modified: Aug. 21, 2025
    • Vuln Type: Injection
  • 10.0

    CRITICAL
    CVE-2025-53187

    Authentication Bypass Using an Alternate Path or Channel vulnerability in ABB ASPECT.This issue affects ASPECT: before <3.08.04-s01.... Read more

    Affected Products :
    • Published: Aug. 11, 2025
    • Modified: Aug. 21, 2025
    • Vuln Type: Authentication
  • 8.8

    HIGH
    CVE-2025-8088

    A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, ... Read more

    Affected Products : windows winrar dtsearch
    • Actively Exploited
    • Published: Aug. 08, 2025
    • Modified: Aug. 21, 2025
    • Vuln Type: Path Traversal
  • 9.8

    CRITICAL
    CVE-2025-55591

    TOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability in the devicemac parameter in the formMapDel endpoint.... Read more

    Affected Products : a3002r_firmware a3002r
    • Published: Aug. 18, 2025
    • Modified: Aug. 21, 2025
    • Vuln Type: Injection
  • 6.5

    MEDIUM
    CVE-2025-55590

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an command injection vulnerability via the component bupload.html.... Read more

    Affected Products : a3002r_firmware a3002r
    • Published: Aug. 18, 2025
    • Modified: Aug. 21, 2025
    • Vuln Type: Injection
  • 6.5

    MEDIUM
    CVE-2025-55589

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain multiple OS command injection vulnerabilities via the macstr, bandstr, and clientoff parameters at /boafrm/formMapDelDevice.... Read more

    Affected Products : a3002r_firmware a3002r
    • Published: Aug. 18, 2025
    • Modified: Aug. 21, 2025
    • Vuln Type: Injection
  • 7.5

    HIGH
    CVE-2025-55588

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the fw_ip parameter at /boafrm/formPortFw. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.... Read more

    Affected Products : a3002r_firmware a3002r
    • Published: Aug. 18, 2025
    • Modified: Aug. 21, 2025
    • Vuln Type: Denial of Service
  • 7.5

    HIGH
    CVE-2025-55587

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the hostname parameter at /boafrm/formMapDelDevice. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.... Read more

    Affected Products : a3002r_firmware a3002r
    • Published: Aug. 18, 2025
    • Modified: Aug. 21, 2025
    • Vuln Type: Denial of Service
  • 7.5

    HIGH
    CVE-2025-55586

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the url parameter at /boafrm/formFilter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.... Read more

    Affected Products : a3002r_firmware a3002r
    • Published: Aug. 18, 2025
    • Modified: Aug. 21, 2025
    • Vuln Type: Denial of Service
  • 6.5

    MEDIUM
    CVE-2025-55585

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an eval injection vulnerability via the eval() function.... Read more

    Affected Products : a3002r_firmware a3002r
    • Published: Aug. 18, 2025
    • Modified: Aug. 21, 2025
    • Vuln Type: Injection
  • 5.3

    MEDIUM
    CVE-2025-55584

    TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain insecure credentials for the telnet service and root account.... Read more

    Affected Products : a3002r_firmware a3002r
    • Published: Aug. 18, 2025
    • Modified: Aug. 21, 2025
    • Vuln Type: Authentication
  • 6.1

    MEDIUM
    CVE-2024-26484

    A stored cross-site scripting (XSS) vulnerability in the Edit Content Layout module of Kirby CMS v4.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Link field. NOTE: the vendor's position is that this ... Read more

    Affected Products : kirby
    • Published: Feb. 22, 2024
    • Modified: Aug. 21, 2025
  • 7.1

    HIGH
    CVE-2024-26482

    An HTML injection vulnerability exists in the Edit Content Layout module of Kirby CMS v4.1.0. NOTE: the vendor disputes the significance of this report because some HTML formatting (such as with an H1 element) is allowed, but there is backend sanitization... Read more

    Affected Products : kirby
    • Published: Feb. 22, 2024
    • Modified: Aug. 21, 2025
  • 9.8

    CRITICAL
    CVE-2025-9013

    A vulnerability has been found in PHPGurukul Online Shopping Portal Project 2.0. This vulnerability affects unknown code of the file /shopping/password-recovery.php. The manipulation of the argument emailid leads to sql injection. The attack can be initia... Read more

    • Published: Aug. 15, 2025
    • Modified: Aug. 21, 2025
    • Vuln Type: Injection
  • 0.0

    NA
    CVE-2023-52656

    In the Linux kernel, the following vulnerability has been resolved: io_uring: drop any code related to SCM_RIGHTS This is dead code after we dropped support for passing io_uring fds over SCM_RIGHTS, get rid of it.... Read more

    Affected Products : linux_kernel
    • Published: May. 14, 2024
    • Modified: Aug. 21, 2025
  • 6.5

    MEDIUM
    CVE-2025-25005

    Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.... Read more

    • Published: Aug. 12, 2025
    • Modified: Aug. 21, 2025
    • Vuln Type: Authentication
  • 5.3

    MEDIUM
    CVE-2024-11176

    Improper access control vulnerability in M-Files Aino in versions before 24.10 allowed an authenticated user to access object information via incorrect evaluation of effective permissions.... Read more

    Affected Products :
    • Published: Nov. 20, 2024
    • Modified: Aug. 21, 2025
  • 9.3

    CRITICAL
    CVE-2025-48757

    An insufficient database Row-Level Security policy in Lovable through 2025-04-15 allows remote unauthenticated attackers to read or write to arbitrary database tables of generated sites. NOTE: this is disputed by the Supplier because each individual custo... Read more

    Affected Products :
    • Published: May. 30, 2025
    • Modified: Aug. 21, 2025
    • Vuln Type: Authorization
  • 6.1

    MEDIUM
    CVE-2024-34449

    Vditor 3.10.3 allows XSS via an attribute of an A element. NOTE: the vendor indicates that a user is supposed to mitigate this via sanitize=true.... Read more

    Affected Products : vditor
    • Published: May. 03, 2024
    • Modified: Aug. 21, 2025
Showing 20 of 291513 Results