Latest CVE Feed
-
9.8
CRITICALCVE-2025-7540
A vulnerability, which was classified as critical, was found in code-projects Online Appointment Booking System 1.0. Affected is an unknown function of the file /getclinic.php. The manipulation of the argument townid leads to sql injection. It is possible... Read more
Affected Products : online_appointment_booking_system- Published: Jul. 13, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-4699
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DAR-8000-10 up to 20230922. This issue affects some unknown processing of the file /importhtml.php. The manipulation of the argument sql leads to d... Read more
- Published: May. 14, 2024
- Modified: Jul. 16, 2025
-
6.5
MEDIUMCVE-2025-46392
Uncontrolled Resource Consumption vulnerability in Apache Commons Configuration 1.x. There are a number of issues in Apache Commons Configuration 1.x that allow excessive resource consumption when loading untrusted configurations or using unexpected usag... Read more
Affected Products : commons_configuration- Published: May. 09, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2025-27820
A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release... Read more
- Published: Apr. 24, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2025-25069
A Cross-Protocol Scripting vulnerability is found in Apache Kvrocks. Since Kvrocks didn't detect if "Host:" or "POST" appears in RESP requests, a valid HTTP request can also be sent to Kvrocks as a valid RESP request and trigger some database operations... Read more
Affected Products : kvrocks- Published: Feb. 07, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Cross-Site Scripting
-
6.9
MEDIUMCVE-2025-27017
Apache NiFi 1.13.0 through 2.2.0 includes the username and password used to authenticate with MongoDB in the NiFi provenance events that MongoDB components generate during processing. An authorized user with read access to the provenance events of those p... Read more
Affected Products : nifi- Published: Mar. 12, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Information Disclosure
-
8.8
HIGHCVE-2025-27696
Improper Authorization vulnerability in Apache Superset allows ownership takeover of dashboards, charts or datasets by authenticated users with read permissions. This issue affects Apache Superset: through 4.1.1. Users are recommended to upgrade to vers... Read more
Affected Products : superset- Published: May. 13, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-53005
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, there is a bypass vulnerability in Dataease's PostgreSQL Data Source JDBC Connection Parameters. The sslfactory and sslfactoryarg parameters could trig... Read more
Affected Products : dataease- Published: Jul. 01, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2024-4960
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in D-Link DAR-7000-40 V31R02B1413C. Affected is an unknown function of the file interface/sysmanage/licenseauthorization.php. The manipulation of the argument file_uploa... Read more
- Published: May. 16, 2024
- Modified: Jul. 16, 2025
-
9.8
CRITICALCVE-2025-7541
A vulnerability has been found in code-projects Online Appointment Booking System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /get_town.php. The manipulation of the argument countryid leads to sql... Read more
Affected Products : online_appointment_booking_system- Published: Jul. 13, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-7542
A vulnerability was found in PHPGurukul User Registration & Login and User Management System 3.3 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/user-profile.php. The manipulation of the argument uid lea... Read more
Affected Products : user_registration_\&_login_and_user_management_system- Published: Jul. 13, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-7543
A vulnerability was found in PHPGurukul User Registration & Login and User Management System 3.3. It has been classified as critical. This affects an unknown part of the file /admin/manage-users.php. The manipulation of the argument ID leads to sql inject... Read more
Affected Products : user_registration_\&_login_and_user_management_system- Published: Jul. 13, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Injection
-
9.0
HIGHCVE-2025-7544
A vulnerability was found in Tenda AC1206 15.03.06.23. It has been rated as critical. This issue affects the function formSetMacFilterCfg of the file /goform/setMacFilterCfg. The manipulation of the argument deviceList leads to stack-based buffer overflow... Read more
- Published: Jul. 13, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-7547
A vulnerability, which was classified as critical, was found in Campcodes Online Movie Theater Seat Reservation System 1.0. This affects the function save_movie of the file /admin/admin_class.php. The manipulation of the argument cover leads to unrestrict... Read more
Affected Products : online_movie_theater_seat_reservation_system- Published: Jul. 13, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2025-7555
A vulnerability, which was classified as critical, has been found in code-projects Voting System 1.0. This issue affects some unknown processing of the file /admin/voters_add.php. The manipulation of the argument firstname/lastname leads to sql injection.... Read more
- Published: Jul. 14, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-7556
A vulnerability, which was classified as critical, was found in code-projects Voting System 1.0. Affected is an unknown function of the file /admin/voters_edit.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the a... Read more
- Published: Jul. 14, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2025-49134
Weblate is a web based localization tool. Prior to version 5.12, the audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as SMTP relays, or spam filters. This issue has been patched i... Read more
Affected Products : weblate- Published: Jun. 16, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Information Disclosure
-
8.8
HIGHCVE-2025-7557
A vulnerability has been found in code-projects Voting System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/voters_row.php. The manipulation of the argument ID leads to sql injection. The att... Read more
- Published: Jul. 14, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-7558
A vulnerability was found in code-projects Voting System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/positions_add.php. The manipulation of the argument description leads to sql injection. The at... Read more
- Published: Jul. 14, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-7560
A vulnerability was found in PHPGurukul Online Fire Reporting System 1.2. It has been declared as critical. This vulnerability affects unknown code of the file /admin/workin-progress-requests.php. The manipulation of the argument teamid leads to sql injec... Read more
Affected Products : online_fire_reporting_system- Published: Jul. 14, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Injection