Latest CVE Feed
-
9.1
CRITICALCVE-2022-36028
Greenlight is an end-user interface for BigBlueButton servers. Versions prior to 2.13.0 have an open redirect vulnerability in the Login page due to unchecked the value of the `return_to` cookie. Versions 2.13.0 contains a patch for the issue. ... Read more
Affected Products : greenlight- Published: Apr. 25, 2024
- Modified: Apr. 24, 2025
-
5.3
MEDIUMCVE-2025-3691
A vulnerability was found in mirweiye Seven Bears Library CMS 2023. It has been classified as problematic. Affected is an unknown function of the component Add Link Handler. The manipulation leads to server-side request forgery. It is possible to launch t... Read more
Affected Products : seven_bears_library_cms- Published: Apr. 16, 2025
- Modified: Apr. 24, 2025
- Vuln Type: Server-Side Request Forgery
-
8.0
HIGHCVE-2020-11919
An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. There is no CSRF protection.... Read more
- Published: Nov. 07, 2024
- Modified: Apr. 24, 2025
-
5.4
MEDIUMCVE-2020-11918
An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. When a backup file is created through the web interface, information on all users, including passwords, can be found in cleartext in the backup file. An attacker capable of accessing the w... Read more
- Published: Nov. 07, 2024
- Modified: Apr. 24, 2025
-
4.3
MEDIUMCVE-2020-11917
An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. It uses a default SSID value, which makes it easier for remote attackers to discover the physical locations of many Siime Eye devices, violating the privacy of users who do not wish to dis... Read more
- Published: Nov. 07, 2024
- Modified: Apr. 24, 2025
-
6.3
MEDIUMCVE-2020-11916
An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. The password for the root user is hashed using an old and deprecated hashing technique. Because of this deprecated hashing, the success probability of an attacker in an offline cracking at... Read more
- Published: Nov. 07, 2024
- Modified: Apr. 24, 2025
-
9.8
CRITICALCVE-2025-3690
A vulnerability was found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/edit-services.php. The manipulation of the argument cost leads to sql injection. The attack m... Read more
Affected Products : men_salon_management_system- Published: Apr. 16, 2025
- Modified: Apr. 24, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3684
A vulnerability was found in Xianqi Kindergarten Management System 2.0 Bulid 20190808. It has been rated as critical. This issue affects some unknown processing of the file stu_list.php of the component Child Management. The manipulation of the argument s... Read more
Affected Products : kindergarten_management_system- Published: Apr. 16, 2025
- Modified: Apr. 24, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2024-55238
OpenMetadata <=1.4.1 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the WorkflowDAO interface. The workflowtype and status parameters can be used to build a SQL query.... Read more
Affected Products : openmetadata- Published: Apr. 17, 2025
- Modified: Apr. 24, 2025
- Vuln Type: Injection
-
8.4
HIGHCVE-2025-0755
The various bson_append functions in the MongoDB C driver library may be susceptible to buffer overflow when performing operations that could result in a final BSON document which exceeds the maximum allowable size (INT32_MAX), resulting in a segmentation... Read more
- Published: Mar. 18, 2025
- Modified: Apr. 24, 2025
- Vuln Type: Memory Corruption
-
7.2
HIGHCVE-2024-2637
An Uncontrolled Search Path Element vulnerability in B&R Industrial Automation Scene Viewer, B&R Industrial Automation Automation Runtime, B&R Industrial Automation mapp Vision, B&R Industrial Automation mapp View, B&R Industrial Automation mapp Cockpit, ... Read more
Affected Products : automation_runtime- Published: May. 14, 2024
- Modified: Apr. 24, 2025
-
9.8
CRITICALCVE-2025-3378
A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. Affected is an unknown function of the component EPRT Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit ha... Read more
- Published: Apr. 07, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-3374
A vulnerability was found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this issue is some unknown functionality of the component CCC Command Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. The ... Read more
- Published: Apr. 07, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-3162
A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been classified as critical. Affected is the function load_weight_ckpt of the file lmdeploy/lmdeploy/vl/model/utils.py of the component PT File Handler. The manipulation leads to deseriali... Read more
Affected Products : lmdeploy- Published: Apr. 03, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Misconfiguration
-
9.1
CRITICALCVE-2025-2946
pgAdmin <= 9.1 is affected by a security vulnerability with Cross-Site Scripting(XSS). If attackers execute any arbitrary HTML/JavaScript in a user's browser through query result rendering, then HTML/JavaScript runs on the browser.... Read more
- Published: Apr. 03, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Cross-Site Scripting
-
6.8
MEDIUMCVE-2025-32464
HAProxy 2.2 through 3.1.6, in certain uncommon configurations, has a sample_conv_regsub heap-based buffer overflow because of mishandling of the replacement of multiple short patterns with a longer one.... Read more
Affected Products : haproxy- Published: Apr. 09, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2021-36471
Directory Traversal vulnerability in AdminLTE 3.1.0 allows remote attackers to gain escalated privilege and view sensitive information via /admin/index2.html, /admin/index3.html URIs. Note: AdminLTE developers dispute that this a weakness with AdminLTE an... Read more
Affected Products : adminlte- Published: Feb. 07, 2023
- Modified: Apr. 23, 2025
-
5.5
MEDIUMCVE-2024-57672
An issue in floodlight v1.2 allows a local attacker to cause a denial of service via the Topology Manager module, Topologylnstance module, Routing module.... Read more
Affected Products : floodlight- Published: Feb. 06, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2024-57673
An issue in floodlight v1.2 allows a local attacker to cause a denial of service via the Topology Manager module and Linkdiscovery module... Read more
Affected Products : floodlight- Published: Feb. 06, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2025-0881
A vulnerability was found in Codezips Gym Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /dashboard/admin/saveroutine.php. The manipulation of the argument rname leads to sql injection. It is possibl... Read more
- Published: Jan. 30, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Injection