Latest CVE Feed
-
9.8
CRITICALCVE-2025-10688
A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file /admin/operation/paid.php. This manipulation of the argument insta_amt causes sql injection. The attack can be initi... Read more
Affected Products : pet_grooming_management_software- Published: Sep. 18, 2025
- Modified: Sep. 19, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-10673
A vulnerability was determined in itsourcecode Student Information Management System 1.0. The impacted element is an unknown function of the file /admin/modules/class/index.php. This manipulation of the argument classId causes sql injection. The attack ma... Read more
Affected Products : student_information_management_system- Published: Sep. 18, 2025
- Modified: Sep. 19, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-10624
A security flaw has been discovered in PHPGurukul User Management System 1.0. This affects an unknown function of the file /login.php. Performing manipulation of the argument emailid results in sql injection. The attack can be initiated remotely. The expl... Read more
Affected Products : user_management_system- Published: Sep. 17, 2025
- Modified: Sep. 19, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-10442
A vulnerability was determined in Tenda AC9 and AC15 15.03.05.14. This affects the function formexeCommand of the file /goform/exeCommand. This manipulation of the argument cmdinput causes os command injection. Remote exploitation of the attack is possibl... Read more
- Published: Sep. 15, 2025
- Modified: Sep. 19, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2023-21468
Improper access control vulnerability in Telephony prior to SMR Apr-2023 Release 1 allows attackers to access files with escalated permission.... Read more
Affected Products : android- Published: Sep. 03, 2025
- Modified: Sep. 19, 2025
- Vuln Type: Authorization
-
4.0
MEDIUMCVE-2023-21469
Improper access control vulnerability in SLocation prior to SMR Apr-2022 Release 1 allows local attackers to get device location information using com.samsung.android.wifi.GEOFENCE action.... Read more
Affected Products : android- Published: Sep. 03, 2025
- Modified: Sep. 19, 2025
- Vuln Type: Authorization
-
4.0
MEDIUMCVE-2023-21470
Improper access control vulnerability in SLocation prior to SMR Apr-2022 Release 1 allows local attackers to get device location information using com.samsung.android.wifi.NETWORK_LOCATION action.... Read more
Affected Products : android- Published: Sep. 03, 2025
- Modified: Sep. 19, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2025-10533
This vulnerability affects Firefox < 143, Firefox ESR < 115.28, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.... Read more
- Published: Sep. 16, 2025
- Modified: Sep. 19, 2025
-
7.1
HIGHCVE-2023-21474
Intent redirection vulnerability in SecSettings prior to SMR Apr-2022 Release 1 allows attackers to access arbitrary file with system privilege.... Read more
Affected Products : android- Published: Sep. 03, 2025
- Modified: Sep. 19, 2025
- Vuln Type: Authorization
-
8.1
HIGH- Published: Sep. 16, 2025
- Modified: Sep. 19, 2025
-
6.0
MEDIUMCVE-2023-21478
Improper input validation vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows local attackers to access protected data.... Read more
Affected Products : android- Published: Sep. 03, 2025
- Modified: Sep. 19, 2025
- Vuln Type: Information Disclosure
-
8.5
HIGHCVE-2023-21480
Improper input validation vulnerability in CertByte prior to SMR Apr-2023 Release 1 allows local attackers to launch privileged activities.... Read more
Affected Products : android- Published: Sep. 03, 2025
- Modified: Sep. 19, 2025
- Vuln Type: Authorization
-
7.5
HIGH- Published: Sep. 16, 2025
- Modified: Sep. 19, 2025
-
9.8
CRITICALCVE-2025-10662
A vulnerability has been found in SeaCMS up to 13.3. The impacted element is an unknown function of the file /admin_members.php?ac=editsave. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has ... Read more
Affected Products : seacms- Published: Sep. 18, 2025
- Modified: Sep. 19, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-10664
A vulnerability was determined in PHPGurukul Small CRM 4.0. This impacts an unknown function of the file /create-ticket.php. Executing manipulation of the argument subject can lead to sql injection. The attack may be launched remotely. The exploit has bee... Read more
Affected Products : small_crm- Published: Sep. 18, 2025
- Modified: Sep. 19, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-26026
An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated... Read more
Affected Products : big-ip_next_central_manager- Published: May. 08, 2024
- Modified: Sep. 19, 2025
-
9.8
CRITICALCVE-2024-21793
An OData injection vulnerability exists in the BIG-IP Next Central Manager API (URI). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.... Read more
Affected Products : big-ip_next_central_manager- Published: May. 08, 2024
- Modified: Sep. 19, 2025
-
7.5
HIGHCVE-2023-40542
When TCP Verified Accept is enabled on a TCP profile that is configured on a Virtual Server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not eva... Read more
Affected Products : big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_domain_name_system big-ip_fraud_protection_service big-ip_global_traffic_manager big-ip_link_controller big-ip_local_traffic_manager +9 more products- Published: Oct. 10, 2023
- Modified: Sep. 19, 2025
-
9.8
CRITICALCVE-2025-10666
A security flaw has been discovered in D-Link DIR-825 up to 2.10. Affected by this vulnerability is the function sub_4106d4 of the file apply.cgi. The manipulation of the argument countdown_time results in buffer overflow. The attack can be executed remot... Read more
- Published: Sep. 18, 2025
- Modified: Sep. 19, 2025
- Vuln Type: Memory Corruption
-
3.1
LOWCVE-2025-9081
Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate access controls which allows any authenticated user to download sensitive files via board file download endpoint using UUID enumeration... Read more
Affected Products : mattermost_server- Published: Sep. 19, 2025
- Modified: Sep. 19, 2025
- Vuln Type: Authorization