Latest CVE Feed
-
6.5
MEDIUMCVE-2025-10326
A security flaw has been discovered in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected is an unknown function of the file /htdocs/api/playlist/single.php. Performing manipulation of the argument playlist results in os command injection. The attack can be ... Read more
Affected Products : phoniebox- Published: Sep. 12, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-52161
Scholl Communications AG Weblication CMS Core v019.004.000.000 was discovered to contain a cross-site scripting (XSS) vulnerability.... Read more
Affected Products : weblication_cms- Published: Sep. 08, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Cross-Site Scripting
-
8.1
HIGHCVE-2025-55998
A cross-site scripting (XSS) vulnerability in Smart Search & Filter Shopify App 1.0 allows a remote attacker to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the color filter parameter.... Read more
Affected Products : smart_search_and_filter- Published: Sep. 08, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-57141
rsbi-os 4.7 is vulnerable to Remote Code Execution (RCE) in sqlite-jdbc.... Read more
Affected Products : ruisibi- Published: Sep. 08, 2025
- Modified: Sep. 12, 2025
-
9.8
CRITICALCVE-2025-10097
A vulnerability was identified in SimStudioAI sim up to 1.0.0. This impacts an unknown function of the file apps/sim/app/api/function/execute/route.ts. The manipulation of the argument code leads to code injection. The attack is possible to be carried out... Read more
Affected Products : sim- Published: Sep. 08, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-10098
A security flaw has been discovered in PHPGurukul User Management System 1.0. Affected is an unknown function of the file /admin/edit-user-profile.php. The manipulation of the argument uid results in sql injection. The attack may be performed from remote.... Read more
Affected Products : user_management_system- Published: Sep. 08, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Injection
-
3.7
LOWCVE-2025-51586
An issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers to gain sensitive information via the reset password feature.... Read more
Affected Products : prestashop- Published: Sep. 08, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-10100
A vulnerability was detected in SourceCodester Simple Forum Discussion System 1.0. This impacts an unknown function of the file /admin_class.php?action=login. Performing manipulation of the argument Username results in sql injection. It is possible to ini... Read more
Affected Products : simple_forum\/discussion_system- Published: Sep. 08, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-56265
An arbitrary file upload vulnerability in the Chat Trigger component of N8N v1.95.3, v1.100.1, and v1.101.1 allows attackers to execute arbitrary code via uploading a crafted HTML file.... Read more
Affected Products : n8n- Published: Sep. 08, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-56266
A Host Header Injection vulnerability in Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via supplying a crafted URL.... Read more
Affected Products : access_control_manager- Published: Sep. 08, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-56267
A CSV injection vulnerability in the /id_profiles endpoint of Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via suuplying a crafted Excel file.... Read more
Affected Products : access_control_manager- Published: Sep. 08, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-57285
codeceptjs 3.7.3 contains a command injection vulnerability in the emptyFolder function (lib/utils.js). The execSync command directly concatenates the user-controlled directoryPath parameter without sanitization or escaping, allowing attackers to execute ... Read more
Affected Products : codeceptjs- Published: Sep. 08, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-9424
A vulnerability was identified in Ruijie WS7204-A 2017.06.15. Affected by this vulnerability is an unknown functionality of the file /itbox_pi/branch_import.php?a=branch_list. Such manipulation of the argument province leads to os command injection. The a... Read more
- Published: Aug. 25, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2025-9422
A vulnerability was found in oitcode samarium up to 0.9.6. This impacts an unknown function of the file /dashboard/team of the component Team Image Handler. The manipulation results in cross site scripting. The attack may be launched remotely. The exploit... Read more
Affected Products : samarium- Published: Aug. 25, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Cross-Site Scripting
-
5.8
MEDIUMCVE-2025-9414
A vulnerability was found in kalcaddle kodbox 1.61. Affected by this vulnerability is an unknown functionality of the file /?explorer/upload/serverDownload of the component Download from Link Handler. Performing manipulation of the argument url results in... Read more
Affected Products : kodbox- Published: Aug. 25, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Server-Side Request Forgery
-
5.1
MEDIUMCVE-2024-46413
Rebuild v3.7.7 was discovered to contain a Server-Side Request Forgery (SSRF) via the type parameter in the com.rebuild.web.admin.rbstore.RBStoreController#loadDataIndex method.... Read more
Affected Products : rebuild- Published: Aug. 25, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Server-Side Request Forgery
-
8.6
HIGHCVE-2025-43960
Adminer 4.8.1, when using Monolog for logging, allows a Denial of Service (memory consumption) via a crafted serialized payload (e.g., using s:1000000000), leading to a PHP Object Injection issue. Remote, unauthenticated attackers can trigger this by send... Read more
Affected Products : adminer- Published: Aug. 25, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Denial of Service
-
7.1
HIGHCVE-2025-43796
Liferay Portal 7.4.0 through 7.4.3.101, and Liferay DXP 2023.Q3.0 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA though update 35 does not limit the number of objects returned from a GraphQL queries, which allows remote attackers to perform denial... Read more
- Published: Sep. 12, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Denial of Service
-
5.1
MEDIUMCVE-2025-43795
Open redirect vulnerability in the System Settings in Liferay Portal 7.1.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4 , 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to redir... Read more
- Published: Sep. 12, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2025-10325
A vulnerability was identified in Wavlink WL-WN578W2 221110. This impacts the function sub_401340/sub_401BA4 of the file /cgi-bin/login.cgi. Such manipulation of the argument ipaddr leads to command injection. It is possible to launch the attack remotely.... Read more
Affected Products :- Published: Sep. 12, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Injection