Latest CVE Feed
-
8.8
HIGHCVE-2025-8230
A vulnerability classified as critical was found in Campcodes Courier Management System 1.0. This vulnerability affects unknown code of the file /manage_user.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remo... Read more
Affected Products : courier_management_system- Published: Jul. 27, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Injection
-
7.4
HIGHCVE-2025-4366
A request smuggling vulnerability identified within Pingora’s proxying framework, pingora-proxy, allows malicious HTTP requests to be injected via manipulated request bodies on cache HITs, leading to unauthorized request execution and potential cache pois... Read more
Affected Products : pingora- Published: May. 22, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Misconfiguration
-
4.8
MEDIUMCVE-2024-20257
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface.r This vulnerability is due to insuffic... Read more
- Published: May. 15, 2024
- Modified: Aug. 06, 2025
-
6.5
MEDIUMCVE-2025-52284
Totolink X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_4184C0 function via the tz parameter. This vulnerability allows unauthenticated attackers to execute arbitrary commands via a crafted request.... Read more
- Published: Jul. 29, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-8334
A vulnerability was found in Campcodes Online Recruitment Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/ajax.php?action=delete_recruitment_status. The manipulation of the argu... Read more
Affected Products : online_recruitment_management_system- Published: Jul. 30, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-36039
IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms,... Read more
Affected Products : aspera_faspex- Published: Jul. 31, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Authorization
-
6.7
MEDIUMCVE-2025-20185
A vulnerability in the implementation of the remote access functionality of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Cisco Secure Email Gateway, and Cisco Secure Web Appliance could allow an authenticated, local attacker to elevate p... Read more
Affected Products : secure_email_and_web_manager asyncos secure_email_gateway secure_email_and_web_manager_virtual_appliance_m100v secure_email_and_web_manager_virtual_appliance_m300v secure_email_and_web_manager_virtual_appliance_m600v secure_email_and_web_manager_m170 secure_email_and_web_manager_m190 secure_email_and_web_manager_m195 secure_email_and_web_manager_m380 +7 more products- Published: Feb. 05, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-8336
A vulnerability classified as critical was found in Campcodes Online Recruitment Management System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=save_user. The manipulation of the argument ID leads to sql injection. The a... Read more
Affected Products : online_recruitment_management_system- Published: Jul. 30, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-36040
IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms.... Read more
Affected Products : aspera_faspex- Published: Jul. 31, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-8338
A vulnerability was found in projectworlds Online Admission System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /adminac.php. The manipulation of the argument ID leads to sql injection. The attack may be... Read more
Affected Products : online_admission_system- Published: Jul. 31, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-36563
Reflected cross-site scripting vulnerability exists in multiple versions of PowerCMS. If a product administrator accesses a crafted URL, an arbitrary script may be executed on the browser.... Read more
Affected Products : powercms- Published: Jul. 31, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-41391
Stored cross-site scripting vulnerability exists in multiple versions of PowerCMS. If a product user accesses a malicious page, an arbitrary script may be executed on the browser.... Read more
Affected Products : powercms- Published: Jul. 31, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-41396
A path traversal issue exists in file uploading feature of multiple versions of PowerCMS. Arbitrary files may be overwritten by a product user.... Read more
Affected Products : powercms- Published: Jul. 31, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Path Traversal
-
6.1
MEDIUMCVE-2025-50866
CloudClassroom-PHP-Project 1.0 contains a reflected Cross-site Scripting (XSS) vulnerability in the email parameter of the postquerypublic endpoint. Improper sanitization allows an attacker to inject arbitrary JavaScript code that executes in the context ... Read more
Affected Products : cloudclassroom- Published: Jul. 31, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Cross-Site Scripting
-
9.4
CRITICALCVE-2025-8426
Marvell QConvergeConsole compressConfigFiles Directory Traversal Information Disclosure and Denial-of-Service Vulnerability. This vulnerability allows remote attackers to disclose sensitive information or to create a denial-of-service condition on affecte... Read more
Affected Products : qconvergeconsole- Published: Jul. 31, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Path Traversal
-
5.8
MEDIUMCVE-2025-5921
The SureForms WordPress plugin before 1.7.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against both authenticated and unauthenticated users.... Read more
Affected Products : sureforms- Published: Aug. 01, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-8436
A vulnerability was found in projectworlds Online Admission System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /viewdoc.php. The manipulation of the argument ID leads to sql injection. The attack ma... Read more
Affected Products : online_admission_system- Published: Aug. 01, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2024-20392
A vulnerability in the web-based management API of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. This vulnerability is due to insufficient input vali... Read more
- Published: May. 15, 2024
- Modified: Aug. 06, 2025
-
8.6
HIGHCVE-2025-46359
A path traversal issue exists in backup and restore feature of multiple versions of PowerCMS. A product administrator may execute arbitrary code by restoring a crafted backup file.... Read more
Affected Products : powercms- Published: Jul. 31, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Path Traversal
-
8.0
HIGHCVE-2025-54752
Multiple versions of PowerCMS improperly neutralize formula elements in a CSV file. If a product user creates a malformed entry and a victim user downloads it as a CSV file and opens it in the user's environment, the embedded code may be executed.... Read more
Affected Products : powercms- Published: Jul. 31, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Misconfiguration