Latest CVE Feed
-
4.7
MEDIUMCVE-2021-27862
Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP headers with invalid length and Ethernet to Wifi frame conversion (and optionally VLAN0 headers).... Read more
- Published: Sep. 27, 2022
- Modified: May. 21, 2025
-
4.7
MEDIUMCVE-2021-27861
Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP headers with invalid length (and optionally VLAN0 headers)... Read more
- Published: Sep. 27, 2022
- Modified: May. 21, 2025
-
4.7
MEDIUMCVE-2021-27854
Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using combinations of VLAN 0 headers, LLC/SNAP headers, and converting frames from Ethernet to Wifi and its reverse.... Read more
- Published: Sep. 27, 2022
- Modified: May. 21, 2025
-
4.6
MEDIUMCVE-2025-26091
A Cross Site Scripting (XSS) vulnerability exists in TeamPasswordManager v12.162.284 and before that could allow a remote attacker to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'name' parameter whe... Read more
Affected Products : team_password_manager- Published: Mar. 04, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting
-
8.1
HIGHCVE-2025-33072
Improper access control in Azure allows an unauthorized attacker to disclose information over a network.... Read more
- Published: May. 08, 2025
- Modified: May. 21, 2025
- Vuln Type: Authorization
-
5.7
MEDIUMCVE-2024-44674
D-Link COVR-2600R FW101b05 is vulnerable to Buffer Overflow. In the function sub_24E28, the HTTP_REFERER is obtained through an environment variable, and this field is controllable, allowing it to be used as the value for src.... Read more
- Published: Oct. 07, 2024
- Modified: May. 21, 2025
-
9.8
CRITICALCVE-2025-47732
Microsoft Dataverse Remote Code Execution Vulnerability... Read more
Affected Products : dataverse- Published: May. 08, 2025
- Modified: May. 21, 2025
-
8.8
HIGHCVE-2024-44589
Stack overflow vulnerability in the Login function in the HNAP service in D-Link DCS-960L with firmware 1.09 allows attackers to execute of arbitrary code.... Read more
- Published: Sep. 18, 2024
- Modified: May. 21, 2025
-
9.1
CRITICALCVE-2025-47733
Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over a network... Read more
Affected Products : power_apps- Published: May. 08, 2025
- Modified: May. 21, 2025
- Vuln Type: Server-Side Request Forgery
-
6.5
MEDIUMCVE-2024-33774
A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formWlanSetup_Wizard allows remote authenticated users to trigger a denial of service (DoS) through the parameter "webpage."... Read more
- Published: May. 14, 2024
- Modified: May. 21, 2025
-
6.5
MEDIUMCVE-2024-33773
A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formWlanGuestSetup allows remote authenticated users to trigger a denial of service (DoS) through the parameter "webpage."... Read more
- Published: May. 14, 2024
- Modified: May. 21, 2025
-
5.7
MEDIUMCVE-2024-33772
A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formTcpipSetup allows remote authenticated users to trigger a denial of service (DoS) through the parameter "curTime."... Read more
- Published: May. 14, 2024
- Modified: May. 21, 2025
-
6.5
MEDIUMCVE-2024-33771
A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via goform/formWPS, allows remote authenticated users to trigger a denial of service (DoS) through the parameter "webpage."... Read more
- Published: May. 14, 2024
- Modified: May. 21, 2025
-
9.8
CRITICALCVE-2025-4773
A vulnerability was found in PHPGurukul Online Course Registration 3.1 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/level.php. The manipulation of the argument level leads to sql injection. The attack... Read more
Affected Products : online_course_registration- Published: May. 16, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-4777
A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0. It has been classified as critical. This affects an unknown part of the file /view-foreigner-ticket.php. The manipulation of the argument viewid leads to sql injection. It is po... Read more
Affected Products : park_ticketing_management_system- Published: May. 16, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-39481
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in imithemes Eventer allows Blind SQL Injection. This issue affects Eventer: from n/a through 3.9.6.... Read more
Affected Products : eventer- Published: May. 16, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4771
A vulnerability, which was classified as critical, was found in PHPGurukul Online Course Registration 3.1. Affected is an unknown function of the file /admin/course.php. The manipulation of the argument coursecode leads to sql injection. It is possible to... Read more
Affected Products : online_course_registration- Published: May. 16, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-45746
In ZKT ZKBio CVSecurity 6.4.1_R an unauthenticated attacker can craft JWT token using the hardcoded secret to authenticate to the service console. NOTE: the Supplier disputes the significance of this report because the service console is typically only ac... Read more
Affected Products : zkbio_cvsecurity- Published: May. 13, 2025
- Modified: May. 21, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2022-40890
A vulnerability in /src/amf/amf-context.c in Open5GS 2.4.10 and earlier leads to AMF denial of service.... Read more
Affected Products : open5gs- Published: Sep. 29, 2022
- Modified: May. 21, 2025
-
5.5
MEDIUMCVE-2022-40363
A buffer overflow in the component nfc_device_load_mifare_ul_data of Flipper Devices Inc., Flipper Zero before v0.65.2 allows attackers to cause a Denial of Service (DoS) via a crafted NFC file.... Read more
- Published: Sep. 29, 2022
- Modified: May. 21, 2025