Latest CVE Feed
-
6.2
MEDIUMCVE-2023-39804
In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.... Read more
Affected Products : tar- Published: Mar. 27, 2024
- Modified: Jul. 29, 2025
-
6.3
MEDIUMCVE-2023-47252
An issue was discovered in PnpSmm in Insyde InsydeH2O with kernel 5.0 through 5.6. There is a possible out-of-bounds access in the SMM communication buffer, leading to tampering. The PNP-related SMI sub-functions do not verify data size before getting it ... Read more
Affected Products : kernel- Published: Apr. 26, 2024
- Modified: Jul. 29, 2025
-
9.3
CRITICALCVE-2024-10044
A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API endpoint of the Controller API Server in lm-sys/fastchat, as of commit e208d5677c6837d590b81cb03847c0b9de100765. This vulnerability allows attackers to explo... Read more
Affected Products : fastchat- Published: Dec. 30, 2024
- Modified: Jul. 29, 2025
-
6.4
MEDIUMCVE-2024-11180
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Timer Widget ekit_countdown_timer_title parameter in all versions up to, and including, 3.4.7 due to insufficient input sanitization and o... Read more
Affected Products : elementskit_elementor_addons- Published: Mar. 29, 2025
- Modified: Jul. 29, 2025
-
7.5
HIGHCVE-2025-50492
Improper session invalidation in the component /edms/change-password.php of PHPGurukul e-Diary Management System v1 allows attackers to execute a session hijacking attack.... Read more
Affected Products : e-diary_management_system- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
-
7.1
HIGHCVE-2025-50491
Improper session invalidation in the component /banker/change-password.php of PHPGurukul Bank Locker Management System v1 allows attackers to execute a session hijacking attack.... Read more
Affected Products : bank_locker_management_system- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
-
7.5
HIGHCVE-2025-50489
Improper session invalidation in the component /srms/change-password.php of PHPGurukul Student Result Management System v2.0 allows attackers to execute a session hijacking attack.... Read more
Affected Products : student_result_management_system- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
-
7.1
HIGHCVE-2025-50488
Improper session invalidation in the component /library/change-password.php of PHPGurukul Online Library Management System v3.0 allows attackers to execute a session hijacking attack.... Read more
Affected Products : online_library_management_system- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
-
7.5
HIGHCVE-2025-50494
Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Car Washing Management System v1.0 allows attackers to execute a session hijacking attack.... Read more
Affected Products : car_washing_management_system- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
-
7.5
HIGHCVE-2025-50493
Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Doctor Appointment Management System v1 allows attackers to execute a session hijacking attack.... Read more
Affected Products : doctor_appointment_management_system- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
-
7.5
HIGHCVE-2025-50490
Improper session invalidation in the component /elms/emp-changepassword.php of PHPGurukul Student Result Management System v2.0 allows attackers to execute a session hijacking attack.... Read more
Affected Products : student_result_management_system- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
-
7.1
HIGHCVE-2025-50486
Improper session invalidation in the component /carrental/update-password.php of PHPGurukul Car Rental Project v3.0 allows attackers to execute a session hijacking attack.... Read more
Affected Products : e-diary_management_system- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
-
7.1
HIGHCVE-2025-50485
Improper session invalidation in the component /crm/change-password.php of PHPGurukul Online Course Registration v3.1 allows attackers to execute a session hijacking attack.... Read more
Affected Products : online_course_registration- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
-
7.1
HIGHCVE-2025-50487
Improper session invalidation in the component /bbdms/change-password.php of PHPGurukul Blood Bank & Donor Management System v2.4 allows attackers to execute a session hijacking attack.... Read more
Affected Products : blood_bank_\&_donor_management_system- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
-
9.0
HIGHCVE-2025-8242
A vulnerability has been found in TOTOLINK X15 1.0.0-B20230714.1105 and classified as critical. This vulnerability affects unknown code of the file /boafrm/formFilter of the component HTTP POST Request Handler. The manipulation of the argument ip6addr/url... Read more
- Published: Jul. 27, 2025
- Modified: Jul. 29, 2025
-
9.0
HIGHCVE-2025-8246
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been rated as critical. Affected by this issue is some unknown functionality of the file /boafrm/formRoute of the component HTTP POST Request Handler. The manipulation of the argument ... Read more
- Published: Jul. 27, 2025
- Modified: Jul. 29, 2025
-
9.0
HIGHCVE-2025-8245
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formMultiAPVLAN of the component HTTP POST Request Handler. The manipulation o... Read more
- Published: Jul. 27, 2025
- Modified: Jul. 29, 2025
-
9.8
CRITICALCVE-2025-8244
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been classified as critical. Affected is an unknown function of the file /boafrm/formMapDelDevice of the component HTTP POST Request Handler. The manipulation of the argument macstr le... Read more
- Published: Jul. 27, 2025
- Modified: Jul. 29, 2025
-
9.0
HIGHCVE-2025-8243
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105 and classified as critical. This issue affects some unknown processing of the file /boafrm/formMapDel of the component HTTP POST Request Handler. The manipulation of the argument devicemac1 le... Read more
- Published: Jul. 27, 2025
- Modified: Jul. 29, 2025
-
8.8
HIGHCVE-2025-8018
A vulnerability was found in code-projects Food Ordering Review System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /user/reservation_page.php. The manipulation of the argument reg_Id leads ... Read more
Affected Products : food_ordering_review_system- Published: Jul. 22, 2025
- Modified: Jul. 29, 2025