Latest CVE Feed
-
9.8
CRITICALCVE-2025-47732
Microsoft Dataverse Remote Code Execution Vulnerability... Read more
Affected Products : dataverse- Published: May. 08, 2025
- Modified: May. 21, 2025
-
8.8
HIGHCVE-2024-44589
Stack overflow vulnerability in the Login function in the HNAP service in D-Link DCS-960L with firmware 1.09 allows attackers to execute of arbitrary code.... Read more
- Published: Sep. 18, 2024
- Modified: May. 21, 2025
-
9.1
CRITICALCVE-2025-47733
Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over a network... Read more
Affected Products : power_apps- Published: May. 08, 2025
- Modified: May. 21, 2025
- Vuln Type: Server-Side Request Forgery
-
6.5
MEDIUMCVE-2024-33774
A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formWlanSetup_Wizard allows remote authenticated users to trigger a denial of service (DoS) through the parameter "webpage."... Read more
- Published: May. 14, 2024
- Modified: May. 21, 2025
-
6.5
MEDIUMCVE-2024-33773
A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formWlanGuestSetup allows remote authenticated users to trigger a denial of service (DoS) through the parameter "webpage."... Read more
- Published: May. 14, 2024
- Modified: May. 21, 2025
-
5.7
MEDIUMCVE-2024-33772
A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formTcpipSetup allows remote authenticated users to trigger a denial of service (DoS) through the parameter "curTime."... Read more
- Published: May. 14, 2024
- Modified: May. 21, 2025
-
6.5
MEDIUMCVE-2024-33771
A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via goform/formWPS, allows remote authenticated users to trigger a denial of service (DoS) through the parameter "webpage."... Read more
- Published: May. 14, 2024
- Modified: May. 21, 2025
-
9.8
CRITICALCVE-2025-4773
A vulnerability was found in PHPGurukul Online Course Registration 3.1 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/level.php. The manipulation of the argument level leads to sql injection. The attack... Read more
Affected Products : online_course_registration- Published: May. 16, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-4777
A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0. It has been classified as critical. This affects an unknown part of the file /view-foreigner-ticket.php. The manipulation of the argument viewid leads to sql injection. It is po... Read more
Affected Products : park_ticketing_management_system- Published: May. 16, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-39481
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in imithemes Eventer allows Blind SQL Injection. This issue affects Eventer: from n/a through 3.9.6.... Read more
Affected Products : eventer- Published: May. 16, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4771
A vulnerability, which was classified as critical, was found in PHPGurukul Online Course Registration 3.1. Affected is an unknown function of the file /admin/course.php. The manipulation of the argument coursecode leads to sql injection. It is possible to... Read more
Affected Products : online_course_registration- Published: May. 16, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-45746
In ZKT ZKBio CVSecurity 6.4.1_R an unauthenticated attacker can craft JWT token using the hardcoded secret to authenticate to the service console. NOTE: the Supplier disputes the significance of this report because the service console is typically only ac... Read more
Affected Products : zkbio_cvsecurity- Published: May. 13, 2025
- Modified: May. 21, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2022-40890
A vulnerability in /src/amf/amf-context.c in Open5GS 2.4.10 and earlier leads to AMF denial of service.... Read more
Affected Products : open5gs- Published: Sep. 29, 2022
- Modified: May. 21, 2025
-
5.5
MEDIUMCVE-2022-40363
A buffer overflow in the component nfc_device_load_mifare_ul_data of Flipper Devices Inc., Flipper Zero before v0.65.2 allows attackers to cause a Denial of Service (DoS) via a crafted NFC file.... Read more
- Published: Sep. 29, 2022
- Modified: May. 21, 2025
-
4.3
MEDIUMCVE-2022-32170
The “Bytebase” application does not restrict low privilege user to access admin “projects“ for which an unauthorized user can view the “projects“ created by “Admin” and the affected endpoint is “/api/project?user=${userId}”.... Read more
Affected Products : bytebase- Published: Sep. 28, 2022
- Modified: May. 21, 2025
-
4.3
MEDIUMCVE-2022-32169
The “Bytebase” application does not restrict low privilege user to access “admin issues“ for which an unauthorized user can view the “OPEN” and “CLOSED” issues by “Admin” and the affected endpoint is “/issue”.... Read more
Affected Products : bytebase- Published: Sep. 28, 2022
- Modified: May. 21, 2025
-
9.1
CRITICALCVE-2022-30935
An authorization bypass in b2evolution allows remote, unauthenticated attackers to predict password reset tokens for any user through the use of a bad randomness function. This allows the attacker to get valid sessions for arbitrary users, and optionally ... Read more
Affected Products : b2evolution- Published: Sep. 28, 2022
- Modified: May. 21, 2025
-
6.5
MEDIUMCVE-2025-4901
A vulnerability classified as problematic was found in D-Link DI-7003GV2 24.04.18D1 R(68125). Affected by this vulnerability is the function sub_41E304 of the file /H5/state_view.data of the component HTTP Endpoint. The manipulation leads to information d... Read more
- Published: May. 19, 2025
- Modified: May. 21, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2025-4756
A vulnerability was found in D-Link DI-7003GV2 24.04.18D1 R(68125). It has been declared as problematic. This vulnerability affects unknown code of the file /H5/restart.asp. The manipulation leads to denial of service. The attack can be initiated remotely... Read more
- Published: May. 16, 2025
- Modified: May. 21, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2025-4902
A vulnerability, which was classified as problematic, has been found in D-Link DI-7003GV2 24.04.18D1 R(68125). Affected by this issue is the function sub_48F4F0 of the file /H5/versionupdate.data. The manipulation leads to information disclosure. The atta... Read more
- Published: May. 19, 2025
- Modified: May. 21, 2025
- Vuln Type: Information Disclosure