Latest CVE Feed
- 
                                
                                8.8HIGHCVE-2025-11303A vulnerability was detected in Belkin F9K1015 1.00.10. Affected is an unknown function of the file /goform/mp. Performing manipulation of the argument command results in command injection. The attack may be initiated remotely. The exploit is now public a... Read more - Published: Oct. 05, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Injection
 
- 
                                
                                6.1MEDIUMCVE-2025-11306A vulnerability was found in qianfox FoxCMS up to 1.2. This affects an unknown part of the file /index.php/Search of the component Search Page. The manipulation of the argument keyword results in cross site scripting. The attack can be executed remotely. ... Read more Affected Products : foxcms- Published: Oct. 05, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Cross-Site Scripting
 
- 
                                
                                8.2HIGHCVE-2025-29192Flowise before 3.0.5 allows XSS via a FORM element and an INPUT element when an admin views the chat log.... Read more Affected Products : flowise- Published: Oct. 06, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Cross-Site Scripting
 
- 
                                
                                8.2HIGHCVE-2025-50538Flowise before 3.0.5 allows XSS via an IFRAME element when an admin views the chat log.... Read more Affected Products : flowise- Published: Oct. 06, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Cross-Site Scripting
 
- 
                                
                                9.0HIGHCVE-2025-11324A vulnerability was identified in Tenda AC18 15.03.05.19(6318). Affected by this vulnerability is an unknown functionality of the file /goform/setNotUpgrade. Such manipulation of the argument newVersion leads to stack-based buffer overflow. The attack can... Read more - Published: Oct. 06, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Memory Corruption
 
- 
                                
                                9.0HIGHCVE-2025-11325A security flaw has been discovered in Tenda AC18 15.03.05.19(6318). Affected by this issue is some unknown functionality of the file /goform/fast_setting_pppoe_set. Performing manipulation of the argument Username results in stack-based buffer overflow. ... Read more - Published: Oct. 06, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Memory Corruption
 
- 
                                
                                9.0HIGHCVE-2025-11326A weakness has been identified in Tenda AC18 15.03.05.19(6318). This affects an unknown part of the file /goform/WifiMacFilterSet. Executing manipulation of the argument wifi_chkHz can lead to stack-based buffer overflow. The attack may be performed from ... Read more - Published: Oct. 06, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Memory Corruption
 
- 
                                
                                9.0HIGHCVE-2025-11327A security vulnerability has been detected in Tenda AC18 15.03.05.19(6318). This vulnerability affects unknown code of the file /goform/SetUpnpCfg. The manipulation of the argument upnpEn leads to stack-based buffer overflow. It is possible to initiate th... Read more - Published: Oct. 06, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Memory Corruption
 
- 
                                
                                9.0HIGHCVE-2025-11328A vulnerability was detected in Tenda AC18 15.03.05.19(6318). This issue affects some unknown processing of the file /goform/SetDDNSCfg. The manipulation of the argument ddnsEn results in stack-based buffer overflow. It is possible to launch the attack re... Read more - Published: Oct. 06, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Memory Corruption
 
- 
                                
                                9.8CRITICALCVE-2025-11329A flaw has been found in code-projects Online Course Registration 1.0. Impacted is an unknown function of the file /admin/manage-students.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has... Read more Affected Products : online_course_registration_site- Published: Oct. 06, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Injection
 
- 
                                
                                8.8HIGHCVE-2025-11330A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. The affected element is an unknown function of the file /admin/sales-reports-detail.php. Such manipulation of the argument fromdate/todate leads to sql injection. The attac... Read more Affected Products : beauty_parlour_management_system- Published: Oct. 06, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Injection
 
- 
                                
                                7.2HIGHCVE-2025-11331A vulnerability was found in IdeaCMS up to 1.8. The impacted element is an unknown function of the file app/common/logic/admin/Config.php of the component Website Name Handler. Performing manipulation of the argument 网站名称 results in command injection. The... Read more Affected Products : ideacms- Published: Oct. 06, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-11334A security flaw has been discovered in Campcodes Online Apartment Visitor Management System 1.0. Affected is an unknown function of the file /visitor-detail.php. The manipulation of the argument editid results in sql injection. The attack can be executed ... Read more Affected Products : online_apartment_visitor_management_system- Published: Oct. 06, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-61603WeGIA is a Web manager for charitable institutions. Versions 3.4.12 and below include an SQL Injection vulnerability which was identified in the /controle/control.php endpoint, specifically in the descricao parameter. This vulnerability allows attackers t... Read more Affected Products : wegia- Published: Oct. 02, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Injection
 
- 
                                
                                7.1HIGHCVE-2025-61604WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain a Cross-Site Request Forgery (CSRF) vulnerability. The delete operation for the Almoxarifado entity is exposed via HTTP GET without CSRF protect... Read more Affected Products : wegia- Published: Oct. 02, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Cross-Site Request Forgery
 
- 
                                
                                9.8CRITICALCVE-2025-61605WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain an SQL Injection vulnerability which was identified in the /pet/profile_pet.php endpoint, specifically in the id_pet parameter. This vulnerabili... Read more Affected Products : wegia- Published: Oct. 02, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Injection
 
- 
                                
                                6.1MEDIUMCVE-2025-61606WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain an Open Redirect vulnerability, identified in the control.php endpoint, specifically in the nextPage parameter (metodo=listarUmnomeClasse=Funcio... Read more Affected Products : wegia- Published: Oct. 02, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Misconfiguration
 
- 
                                
                                8.7HIGHCVE-2025-61665WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain a Broken Access Control vulnerability, identified in the get_relatorios_socios.php endpoint. This vulnerability allows unauthenticated attackers... Read more Affected Products : wegia- Published: Oct. 02, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Authorization
 
- 
                                
                                6.1MEDIUMCVE-2025-60450A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists due to insufficient validation and sanitization of SVG file uploads in the app\system\include\module\editor\Uploader.class.php compo... Read more Affected Products : metinfo- Published: Oct. 03, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Cross-Site Scripting
 
- 
                                
                                6.1MEDIUMCVE-2025-60451A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists due to insufficient validation and sanitization of SVG file uploads in the app\system\include\module\uploadify.class.php component, ... Read more Affected Products : metinfo- Published: Oct. 03, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Cross-Site Scripting
 
 
                         
                         
                         
                                             
                                            