Latest CVE Feed
-
9.8
CRITICALCVE-2025-10112
A weakness has been identified in itsourcecode Student Information Management System 1.0. The impacted element is an unknown function of the file /admin/modules/department/index.php. This manipulation of the argument ID causes sql injection. The attack is... Read more
Affected Products : student_information_management_system- Published: Sep. 09, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-10114
A vulnerability was found in PHPGurukul Small CRM 4.0. Affected by this issue is some unknown functionality of the file /profile.php. The manipulation of the argument Name results in sql injection. The attack can be launched remotely. The exploit has been... Read more
Affected Products : small_crm- Published: Sep. 09, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-10113
A security vulnerability has been detected in itsourcecode Student Information Management System 1.0. This affects an unknown function of the file /admin/modules/room/index.php. Such manipulation of the argument ID leads to sql injection. The attack may b... Read more
Affected Products : student_information_management_system- Published: Sep. 09, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2025-10117
A weakness has been identified in SourceCodester Simple To-Do List System 1.0. Impacted is an unknown function of the file /fetch_tasks.php of the component Add New Task. Executing manipulation with the input <script>alert('XSS')</script> can lead to cros... Read more
Affected Products : simple_to-do_list_system- Published: Sep. 09, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-10118
A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. The affected element is an unknown function of the file /login.php. The manipulation of the argument Username leads to sql injection. The ... Read more
Affected Products : e-logbook_with_health_monitoring_system_for_covid-19- Published: Sep. 09, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Injection
-
9.0
HIGHCVE-2025-10120
A vulnerability was detected in Tenda AC20 up to 16.03.08.12. The impacted element is the function strcpy of the file /goform/GetParentControlInfo. The manipulation of the argument mac results in buffer overflow. The attack may be performed from remote. T... Read more
- Published: Sep. 09, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-10109
A vulnerability was determined in Campcodes Online Loan Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=delete_payment. Executing manipulation of the argument ID can lead to sql injection. The attack may be l... Read more
Affected Products : online_loan_management_system- Published: Sep. 08, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-13792
The WooCommerce Food - Restaurant Menu & Food ordering plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.2. This is due to the software allowing users to execute an action that does not properly ... Read more
- Published: Feb. 20, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-10111
A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is an unknown function of the file /admin/modules/instructor/index.php. The manipulation of the argument ID results in sql injection. The a... Read more
Affected Products : student_information_management_system- Published: Sep. 08, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-10110
A vulnerability was identified in ChanCMS up to 3.3.1. Impacted is an unknown function of the file /search/. The manipulation with the input '%20or%201=1%20%23/words.html leads to sql injection. Remote exploitation of the attack is possible. The exploit i... Read more
Affected Products : chancms- Published: Sep. 08, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Injection
-
6.9
MEDIUMCVE-2025-57791
A security vulnerability has been identified that allows remote attackers to inject or manipulate command-line arguments passed to internal components due to insufficient input validation. Successful exploitation results in a valid user session for a low ... Read more
- Published: Aug. 20, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-57790
A security vulnerability has been identified that allows remote attackers to perform unauthorized file system access through a path traversal issue. The vulnerability may lead to remote code execution.... Read more
- Published: Aug. 20, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Path Traversal
-
5.4
MEDIUMCVE-2025-57789
During the brief window between installation and the first administrator login, remote attackers may exploit the default credential to gain admin control. This is limited to the setup phase, before any jobs have been configured.... Read more
- Published: Aug. 20, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Authentication
-
6.9
MEDIUMCVE-2025-57788
A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit the exposure but does not eliminate risk.... Read more
- Published: Aug. 20, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Authentication
-
9.0
CRITICALCVE-2024-38002
The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92 and 7.3 GA through update 36 does not properly check user permissions before updating a wo... Read more
- Published: Oct. 22, 2024
- Modified: Sep. 10, 2025
-
6.5
MEDIUMCVE-2025-6224
Certificate generation in juju/utils using the cert.NewLeaf function could include private information. If this certificate were then transferred over the network in plaintext, an attacker listening on that network could sniff the certificate and triviall... Read more
Affected Products : juju\/utils- Published: Jul. 01, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Information Disclosure
-
4.7
MEDIUMCVE-2025-53791
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.... Read more
Affected Products : edge_chromium- Published: Sep. 05, 2025
- Modified: Sep. 10, 2025
-
8.7
HIGHCVE-2025-22846
When SIP Session and Router ALG profiles are configured on a Message Routing type virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support... Read more
Affected Products : big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_domain_name_system big-ip_fraud_protection_service big-ip_global_traffic_manager big-ip_link_controller big-ip_local_traffic_manager +3 more products- Published: Feb. 05, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Denial of Service
-
6.1
MEDIUMCVE-2025-10027
A vulnerability was determined in itsourcecode POS Point of Sale System 1.0. Affected by this issue is some unknown functionality of the file /inventory/main/vendors/datatables/unit_testing/templates/2512.php. This manipulation of the argument scripts cau... Read more
Affected Products : point_of_sale_system- Published: Sep. 05, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2025-38742
Dell iDRAC Service Module (iSM), versions prior to 6.0.3.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code executio... Read more
Affected Products : emc_idrac_service_module- Published: Aug. 21, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Authorization