Latest CVE Feed
-
9.8
CRITICALCVE-2025-4482
A vulnerability classified as critical was found in Project Worlds Student Project Allocation System 1.0. Affected by this vulnerability is an unknown functionality of the file /change_pass/forgot_password_sql.php. The manipulation of the argument Pat_Blo... Read more
Affected Products : student_project_allocation_system- Published: May. 09, 2025
- Modified: May. 16, 2025
- Vuln Type: Injection
-
9.0
CRITICALCVE-2021-40438
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.... Read more
- Actively Exploited
- EPSS Score: %94.44
- Published: Sep. 16, 2021
- Modified: May. 16, 2025
-
7.5
HIGHCVE-2025-48050
In DOMPurify through 3.2.5 before 6bc6d60, scripts/server.js does not ensure that a pathname is located under the current working directory. NOTE: the Supplier disputes the significance of this report because the "Uncontrolled data used in path expression... Read more
Affected Products : dompurify- Published: May. 15, 2025
- Modified: May. 16, 2025
- Vuln Type: Path Traversal
-
8.1
HIGHCVE-2025-30712
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.1.6. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle... Read more
Affected Products : vm_virtualbox- Published: Apr. 15, 2025
- Modified: May. 16, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2022-2720
In affected versions of Octopus Server it was identified that when a sensitive value is a substring of another value, sensitive value masking will only partially work.... Read more
Affected Products : octopus_server- EPSS Score: %0.29
- Published: Oct. 12, 2022
- Modified: May. 16, 2025
-
9.8
CRITICALCVE-2025-4182
A vulnerability was found in PCMan FTP Server 2.0.7. It has been rated as critical. Affected by this issue is some unknown functionality of the component BELL Command Handler. The manipulation leads to buffer overflow. The attack may be launched remotely.... Read more
- Published: May. 01, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4183
A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. This affects an unknown part of the component RECV Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has... Read more
- Published: May. 01, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4184
A vulnerability classified as critical was found in PCMan FTP Server 2.0.7. This vulnerability affects unknown code of the component QUOTE Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remotely. The exploit has be... Read more
- Published: May. 02, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4236
A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this vulnerability is an unknown functionality of the component MDIR Command Handler. The manipulation leads to buffer overflow. The attack can be launched re... Read more
- Published: May. 03, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4237
A vulnerability was found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this issue is some unknown functionality of the component MDELETE Command Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. ... Read more
- Published: May. 03, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
5.4
MEDIUMCVE-2025-0787
A vulnerability was found in ESAFENET CDG V5. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /appDetail.jsp. The manipulation of the argument curpage leads to cross site scripting. The attack ca... Read more
Affected Products : cdg- Published: Jan. 28, 2025
- Modified: May. 16, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-3371
A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. This issue affects some unknown processing of the component DELETE Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotel... Read more
- Published: Apr. 07, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-3349
A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. This issue affects some unknown processing of the component SYST Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely.... Read more
- Published: Apr. 07, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-0788
A vulnerability was found in ESAFENET CDG V5. It has been rated as critical. Affected by this issue is some unknown functionality of the file /content_top.jsp. The manipulation of the argument id leads to sql injection. The attack may be launched remotely... Read more
Affected Products : cdg- Published: Jan. 28, 2025
- Modified: May. 16, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-0786
A vulnerability was found in ESAFENET CDG V5. It has been classified as critical. Affected is an unknown function of the file /appDetail.jsp. The manipulation of the argument flowId leads to sql injection. It is possible to launch the attack remotely. The... Read more
Affected Products : cdg- Published: Jan. 28, 2025
- Modified: May. 16, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-0785
A vulnerability was found in ESAFENET CDG V5 and classified as problematic. This issue affects some unknown processing of the file /SysConfig.jsp. The manipulation of the argument help leads to cross site scripting. The attack may be initiated remotely. T... Read more
Affected Products : cdg- Published: Jan. 28, 2025
- Modified: May. 16, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2024-9536
A vulnerability was found in ESAFENET CDG V5. It has been rated as critical. Affected by this issue is some unknown functionality of the file /MultiServerBackService?path=1. The manipulation of the argument fileId leads to sql injection. The attack may be... Read more
Affected Products : cdg- Published: Oct. 05, 2024
- Modified: May. 16, 2025
-
9.8
CRITICALCVE-2025-3240
A vulnerability, which was classified as critical, has been found in PHPGurukul Online Fire Reporting System 1.2. Affected by this issue is some unknown functionality of the file /admin/search.php. The manipulation of the argument searchdata leads to sql ... Read more
Affected Products : online_fire_reporting_system- Published: Apr. 04, 2025
- Modified: May. 16, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3377
A vulnerability was found in PCMan FTP Server 2.0.7. It has been rated as critical. This issue affects some unknown processing of the component ENC Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The explo... Read more
- Published: Apr. 07, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-3376
A vulnerability was found in PCMan FTP Server 2.0.7. It has been declared as critical. This vulnerability affects unknown code of the component CONF Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remotely. The expl... Read more
- Published: Apr. 07, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption