Latest CVE Feed
-
7.1
HIGHCVE-2025-44007
An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from a... Read more
Affected Products : qsync_central- Published: Oct. 03, 2025
- Modified: Oct. 08, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2025-46817
Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to cause an integer overflow and potentially lead to remote code execution The problem exists in ... Read more
Affected Products : redis- Published: Oct. 03, 2025
- Modified: Oct. 08, 2025
- Vuln Type: Injection
-
5.1
MEDIUMCVE-2025-49641
A regular Zabbix user with no permission to the Monitoring -> Problems view is still able to call the problem.view.refresh action and therefore still retrieve a list of active problems.... Read more
Affected Products : zabbix- Published: Oct. 03, 2025
- Modified: Oct. 08, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-27236
A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have access to view. This allows data-mining some field values the user does not have access to.... Read more
Affected Products : zabbix- Published: Oct. 03, 2025
- Modified: Oct. 08, 2025
- Vuln Type: Authorization
-
4.9
MEDIUMCVE-2025-27231
The LDAP 'Bind password' value cannot be read after saving, but a Super Admin account can leak it by changing LDAP 'Host' to a rogue LDAP server. To mitigate this, the 'Bind password' value is now reset on 'Host' change.... Read more
Affected Products : zabbix- Published: Oct. 03, 2025
- Modified: Oct. 08, 2025
- Vuln Type: Misconfiguration
-
6.1
MEDIUMCVE-2025-11282
A vulnerability was found in Frappe LMS 2.34.x/2.35.0. The impacted element is an unknown function of the component Incomplete Fix CVE-2025-55006. Performing manipulation results in cross site scripting. Remote exploitation of the attack is possible. The ... Read more
Affected Products : learning- Published: Oct. 05, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-11283
A vulnerability was determined in Frappe LMS 2.35.0. This affects an unknown function of the component Course Handler. Executing manipulation of the argument Description can lead to cross site scripting. The attack can be executed remotely. The exploit ha... Read more
Affected Products : learning- Published: Oct. 05, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Cross-Site Scripting
-
5.0
MEDIUMCVE-2025-11281
A vulnerability has been found in Frappe LMS 2.35.0. The affected element is an unknown function of the file /courses/ of the component Unpublished Course Handler. Such manipulation leads to improper access controls. The attack may be launched remotely. T... Read more
Affected Products : learning- Published: Oct. 05, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Authorization
-
6.3
MEDIUMCVE-2025-11280
A flaw has been found in Frappe LMS 2.35.0. Impacted is an unknown function of the file /files/ of the component Assignment Picture Handler. This manipulation causes direct request. The attack may be initiated remotely. The attack's complexity is rated as... Read more
Affected Products : learning- Published: Oct. 05, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Server-Side Request Forgery
-
7.5
HIGHCVE-2025-11284
A vulnerability has been found in Zytec Dalian Zhuoyun Technology Central Authentication Service 3. Affected by this vulnerability is an unknown functionality of the file /index.php/auth/Ops/git of the component HTTP Header Handler. The manipulation of th... Read more
Affected Products :- Published: Oct. 05, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2025-61087
SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross Site Scripting (XSS) via the Customer Name field under Customer Management Section.... Read more
Affected Products : pet_grooming_management_software- Published: Oct. 02, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-60782
PHP Education Manager v1.0 is vulnerable to Cross Site Scripting (XSS) stored Cross-Site Scripting (XSS) vulnerability in the topics management module (topics.php). Attackers can inject malicious JavaScript payloads into the Titlefield during topic creati... Read more
Affected Products : php_education_management- Published: Oct. 02, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-61096
PHPGurukul Online Shopping Portal Project v2.1 is vulnerable to SQL Injection in /shopping/login.php via the fullname parameter.... Read more
Affected Products : online_shopping_portal_project- Published: Oct. 02, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-56154
htmly v3.0.8 is vulnerable to Cross Site Scripting (XSS) in the /author/:name endpoint of the affected application. The name parameter is not properly sanitized before being reflected in the HTML response, allowing attackers to inject arbitrary JavaScript... Read more
Affected Products : htmly- Published: Oct. 02, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-60660
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the mac parameter in the fromAdvSetMacMtuWan function.... Read more
- Published: Oct. 02, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-60662
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanSpeed parameter in the fromAdvSetMacMtuWan function.... Read more
- Published: Oct. 02, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-60663
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the wanMTU parameter in the fromAdvSetMacMtuWan function.... Read more
- Published: Oct. 02, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2025-60661
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the cloneType parameter in the fromAdvSetMacMtuWan function.... Read more
- Published: Oct. 02, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-11288
A security flaw has been discovered in CRMEB up to 5.6. This issue affects some unknown processing of the file /adminapi/product/product of the component GET Parameter Handler. Performing manipulation of the argument cate_id results in sql injection. Remo... Read more
Affected Products : crmeb- Published: Oct. 05, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Injection
-
8.1
HIGHCVE-2025-11290
A vulnerability was identified in CRMEB up to 5.6.1. This affects an unknown function of the component JWT HMAC Secret Handler. Such manipulation of the argument secret with the input default leads to use of hard-coded cryptographic key . It is possible ... Read more
Affected Products : crmeb- Published: Oct. 05, 2025
- Modified: Oct. 07, 2025
- Vuln Type: Cryptography