Latest CVE Feed
-
8.8
HIGHCVE-2025-11113
A vulnerability was detected in CodeAstro Online Leave Application 1.0. Affected is an unknown function of the file /signup.php. Performing manipulation of the argument city results in sql injection. The attack may be initiated remotely. The exploit is no... Read more
Affected Products : online_leave_application- Published: Sep. 28, 2025
- Modified: Oct. 02, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-11109
A vulnerability was identified in Campcodes Computer Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/us_edit.php?action=edit. The manipulation of the argument ID leads to sql injection. It is possible to init... Read more
Affected Products : computer_sales_and_inventory_system- Published: Sep. 28, 2025
- Modified: Oct. 02, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-11110
A security flaw has been discovered in Campcodes Online Learning Management System 1.0. The impacted element is an unknown function of the file /admin/school_year.php. The manipulation of the argument school_year results in sql injection. It is possible t... Read more
Affected Products : online_learning_management_system- Published: Sep. 28, 2025
- Modified: Oct. 02, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-11111
A weakness has been identified in Campcodes Advanced Online Voting Management System 1.0. This affects an unknown function of the file /admin/candidates_edit.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remot... Read more
Affected Products : advanced_online_voting_system- Published: Sep. 28, 2025
- Modified: Oct. 02, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-11114
A flaw has been found in CodeAstro Online Leave Application 1.0. Affected by this vulnerability is an unknown functionality of the file /leaveAplicationForm.php. Executing manipulation of the argument absence[] can lead to sql injection. The attack may be... Read more
Affected Products : online_leave_application- Published: Sep. 28, 2025
- Modified: Oct. 02, 2025
- Vuln Type: Injection
-
8.5
HIGHCVE-2025-27262
Ericsson Indoor Connect 8855 contains a command injection vulnerability which if exploited can result in an escalation of privileges.... Read more
- Published: Sep. 25, 2025
- Modified: Oct. 02, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-40836
Ericsson Indoor Connect 8855 contains an improper input validation vulnerability which if exploited can allow an attacker to execute commands with escalated privileges.... Read more
- Published: Sep. 25, 2025
- Modified: Oct. 02, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-40837
Ericsson Indoor Connect 8855 contains a missing authorization vulnerability which if exploited can allow access to the system as a user with higher privileges than intended.... Read more
- Published: Sep. 25, 2025
- Modified: Oct. 02, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-40838
Ericsson Indoor Connect 8855 contains a vulnerability where server-side security can be bypassed in the client which if exploited can lead to unauthorized disclosure of certain information.... Read more
- Published: Sep. 25, 2025
- Modified: Oct. 02, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-27261
Ericsson Indoor Connect 8855 contains an SQL injection vulnerability which if exploited can result in unauthorized disclosure or modification of data.... Read more
- Published: Sep. 25, 2025
- Modified: Oct. 02, 2025
- Vuln Type: Injection
-
4.3
MEDIUMCVE-2025-58457
Improper permission check in ZooKeeper AdminServer lets authorized clients to run snapshot and restore command with insufficient permissions. This issue affects Apache ZooKeeper: from 3.9.0 before 3.9.4. Users are recommended to upgrade to version 3.9.4... Read more
Affected Products : zookeeper- Published: Sep. 24, 2025
- Modified: Oct. 02, 2025
- Vuln Type: Authorization
-
7.6
HIGHCVE-2025-59251
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability... Read more
Affected Products : edge_chromium- Published: Sep. 24, 2025
- Modified: Oct. 02, 2025
-
7.3
HIGHCVE-2025-55322
Binding to an unrestricted ip address in GitHub allows an unauthorized attacker to execute code over a network.... Read more
Affected Products : omniparser- Published: Sep. 24, 2025
- Modified: Oct. 01, 2025
-
7.5
HIGHCVE-2025-54831
Apache Airflow 3 introduced a change to the handling of sensitive information in Connections. The intent was to restrict access to sensitive connection fields to Connection Editing Users, effectively applying a "write-only" model for sensitive values. I... Read more
Affected Products : airflow- Published: Sep. 26, 2025
- Modified: Oct. 01, 2025
- Vuln Type: Information Disclosure
-
0.0
NACVE-2025-57428
Default credentials in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers to gain access to the debug shell exposed via Telnet on Port 23 and execute hardware-level flash and register manipulation commands.... Read more
Affected Products :- Published: Sep. 29, 2025
- Modified: Oct. 01, 2025
- Vuln Type: Authentication
-
8.4
HIGHCVE-2025-56383
Notepad++ v8.8.3 has a DLL hijacking vulnerability, which can replace the original DLL file to execute malicious code. NOTE: this is disputed by multiple parties because the behavior only occurs when a user installs the product into a directory tree that ... Read more
Affected Products :- Published: Sep. 26, 2025
- Modified: Oct. 01, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2025-57197
In the Payeer Android application 2.5.0, an improper access control vulnerability exists in the authentication flow for the PIN change feature. A local attacker with root access to the device can dynamically instrument the app to bypass the current PIN ve... Read more
Affected Products :- Published: Sep. 29, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Authentication
-
7.3
HIGHCVE-2025-35027
Multiple robotic products by Unitree sharing a common firmware, including the Go2, G1, H1, and B2 devices, contain a command injection vulnerability. By setting a malicious string when configuring the on-board WiFi via a BLE module of an affected robot, t... Read more
Affected Products :- Published: Sep. 26, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Injection
-
6.3
MEDIUMCVE-2025-43400
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sonoma 14.8.1, macOS Tahoe 26.0.1, macOS Sequoia 15.7.1, visionOS 26.0.1, iOS 26.0.1 and iPadOS 26.0.1, iOS 18.7.1 and iPadOS 18.7.1. Processing a malic... Read more
- Published: Sep. 29, 2025
- Modified: Sep. 30, 2025
- Vuln Type: Memory Corruption
-
8.5
HIGHCVE-2025-10941
A vulnerability was determined in Topaz SERVCore Teller 2.14.0-RC2/2.14.1. Affected by this issue is some unknown functionality of the file SERVCoreTeller_2.0.40D.msi of the component Installer. Executing manipulation can lead to permission issues. The at... Read more
Affected Products :- Published: Sep. 25, 2025
- Modified: Sep. 30, 2025