Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2025-60782

    PHP Education Manager v1.0 is vulnerable to Cross Site Scripting (XSS) stored Cross-Site Scripting (XSS) vulnerability in the topics management module (topics.php). Attackers can inject malicious JavaScript payloads into the Titlefield during topic creati... Read more

    Affected Products : php_education_management
    • Published: Oct. 02, 2025
    • Modified: Oct. 07, 2025
    • Vuln Type: Cross-Site Scripting
  • 6.5

    MEDIUM
    CVE-2025-61096

    PHPGurukul Online Shopping Portal Project v2.1 is vulnerable to SQL Injection in /shopping/login.php via the fullname parameter.... Read more

    Affected Products : online_shopping_portal_project
    • Published: Oct. 02, 2025
    • Modified: Oct. 07, 2025
    • Vuln Type: Injection
  • 6.1

    MEDIUM
    CVE-2025-56154

    htmly v3.0.8 is vulnerable to Cross Site Scripting (XSS) in the /author/:name endpoint of the affected application. The name parameter is not properly sanitized before being reflected in the HTML response, allowing attackers to inject arbitrary JavaScript... Read more

    Affected Products : htmly
    • Published: Oct. 02, 2025
    • Modified: Oct. 07, 2025
    • Vuln Type: Cross-Site Scripting
  • 7.5

    HIGH
    CVE-2025-56161

    YOSHOP 2.0 allows unauthenticated information disclosure via comment-list API endpoints in the Goods module. The Comment model eagerly loads the related User model without field filtering; because User.php defines no $hidden or $visible attributes, sensit... Read more

    Affected Products : yoshop2.0
    • Published: Oct. 02, 2025
    • Modified: Oct. 07, 2025
    • Vuln Type: Information Disclosure
  • 6.5

    MEDIUM
    CVE-2025-56162

    YOSHOP 2.0 suffers from an unauthenticated SQL injection in the goodsIds parameter of the /api/goods/listByIds endpoint. The getListByIds function concatenates user input into orderRaw('field(goods_id, ...)'), allowing attackers to: (a) enumerate or modif... Read more

    Affected Products : yoshop2.0
    • Published: Oct. 02, 2025
    • Modified: Oct. 07, 2025
    • Vuln Type: Injection
  • 7.5

    HIGH
    CVE-2025-60660

    Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the mac parameter in the fromAdvSetMacMtuWan function.... Read more

    Affected Products : ac18_firmware ac18
    • Published: Oct. 02, 2025
    • Modified: Oct. 07, 2025
    • Vuln Type: Memory Corruption
  • 7.5

    HIGH
    CVE-2025-60662

    Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanSpeed parameter in the fromAdvSetMacMtuWan function.... Read more

    Affected Products : ac18_firmware ac18
    • Published: Oct. 02, 2025
    • Modified: Oct. 07, 2025
    • Vuln Type: Memory Corruption
  • 7.5

    HIGH
    CVE-2025-60663

    Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanMTU parameter in the fromAdvSetMacMtuWan function.... Read more

    Affected Products : ac18_firmware ac18
    • Published: Oct. 02, 2025
    • Modified: Oct. 07, 2025
    • Vuln Type: Memory Corruption
  • 5.3

    MEDIUM
    CVE-2025-60661

    Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the cloneType parameter in the fromAdvSetMacMtuWan function.... Read more

    Affected Products : ac18_firmware ac18
    • Published: Oct. 02, 2025
    • Modified: Oct. 07, 2025
    • Vuln Type: Memory Corruption
  • 8.8

    HIGH
    CVE-2025-11288

    A security flaw has been discovered in CRMEB up to 5.6. This issue affects some unknown processing of the file /adminapi/product/product of the component GET Parameter Handler. Performing manipulation of the argument cate_id results in sql injection. Remo... Read more

    Affected Products : crmeb
    • Published: Oct. 05, 2025
    • Modified: Oct. 07, 2025
    • Vuln Type: Injection
  • 8.1

    HIGH
    CVE-2025-11290

    A vulnerability was identified in CRMEB up to 5.6.1. This affects an unknown function of the component JWT HMAC Secret Handler. Such manipulation of the argument secret with the input default leads to use of hard-coded cryptographic key . It is possible ... Read more

    Affected Products : crmeb
    • Published: Oct. 05, 2025
    • Modified: Oct. 07, 2025
    • Vuln Type: Cryptography
  • 8.8

    HIGH
    CVE-2025-11292

    A weakness has been identified in Belkin F9K1015 1.00.10. Affected is an unknown function of the file /goform/formBSSetSitesurvey. Executing manipulation of the argument wan_ipaddr can lead to command injection. The attack can be launched remotely. The ex... Read more

    Affected Products : f9k1015_firmware f9k1015
    • Published: Oct. 05, 2025
    • Modified: Oct. 07, 2025
    • Vuln Type: Injection
  • 9.0

    HIGH
    CVE-2025-11293

    A security vulnerability has been detected in Belkin F9K1015 1.00.10. Affected by this vulnerability is an unknown functionality of the file /goform/formConnectionSetting. The manipulation of the argument max_Conn leads to buffer overflow. The attack may ... Read more

    Affected Products : f9k1015_firmware f9k1015
    • Published: Oct. 05, 2025
    • Modified: Oct. 07, 2025
    • Vuln Type: Memory Corruption
  • 9.0

    HIGH
    CVE-2025-11294

    A vulnerability was detected in Belkin F9K1015 1.00.10. Affected by this issue is some unknown functionality of the file /goform/formL2TPSetup. The manipulation of the argument L2TPUserName results in buffer overflow. The attack may be launched remotely. ... Read more

    Affected Products : f9k1015_firmware f9k1015
    • Published: Oct. 05, 2025
    • Modified: Oct. 07, 2025
    • Vuln Type: Memory Corruption
  • 9.0

    HIGH
    CVE-2025-11295

    A flaw has been found in Belkin F9K1015 1.00.10. This affects an unknown part of the file /goform/formPPPoESetup. This manipulation of the argument pppUserName causes buffer overflow. Remote exploitation of the attack is possible. The exploit has been pub... Read more

    Affected Products : f9k1015_firmware f9k1015
    • Published: Oct. 05, 2025
    • Modified: Oct. 07, 2025
    • Vuln Type: Memory Corruption
  • 9.0

    HIGH
    CVE-2025-11296

    A vulnerability has been found in Belkin F9K1015 1.00.10. This vulnerability affects unknown code of the file /goform/formPPTPSetup. Such manipulation of the argument pptpUserName leads to buffer overflow. The attack can be executed remotely. The exploit ... Read more

    Affected Products : f9k1015_firmware f9k1015
    • Published: Oct. 05, 2025
    • Modified: Oct. 07, 2025
    • Vuln Type: Memory Corruption
  • 9.0

    HIGH
    CVE-2025-11297

    A vulnerability was found in Belkin F9K1015 1.00.10. This issue affects some unknown processing of the file /goform/formSetLanguage. Performing manipulation of the argument webpage results in buffer overflow. The attack is possible to be carried out remot... Read more

    Affected Products : f9k1015_firmware f9k1015
    • Published: Oct. 05, 2025
    • Modified: Oct. 07, 2025
    • Vuln Type: Memory Corruption
  • 8.8

    HIGH
    CVE-2025-11298

    A vulnerability was determined in Belkin F9K1015 1.00.10. Impacted is an unknown function of the file /goform/formSetWanStatic. Executing manipulation of the argument m_wan_ipaddr can lead to command injection. The attack may be performed from remote. The... Read more

    Affected Products : f9k1015_firmware f9k1015
    • Published: Oct. 05, 2025
    • Modified: Oct. 07, 2025
    • Vuln Type: Injection
  • 9.0

    HIGH
    CVE-2025-11299

    A vulnerability was identified in Belkin F9K1015 1.00.10. The affected element is an unknown function of the file /goform/formWanTcpipSetup. The manipulation of the argument pppUserName leads to buffer overflow. It is possible to initiate the attack remot... Read more

    Affected Products : f9k1015_firmware f9k1015
    • Published: Oct. 05, 2025
    • Modified: Oct. 07, 2025
    • Vuln Type: Memory Corruption
  • 9.0

    HIGH
    CVE-2025-11300

    A security flaw has been discovered in Belkin F9K1015 1.00.10. The impacted element is an unknown function of the file /goform/formWlanMP. The manipulation of the argument ateFunc results in buffer overflow. It is possible to launch the attack remotely. T... Read more

    Affected Products : f9k1015_firmware f9k1015
    • Published: Oct. 05, 2025
    • Modified: Oct. 07, 2025
    • Vuln Type: Memory Corruption
Showing 20 of 4034 Results