Latest CVE Feed
-
9.8
CRITICALCVE-2025-7409
A vulnerability was found in code-projects Mobile Shop 1.0 and classified as critical. This issue affects some unknown processing of the file /LoginAsAdmin.php. The manipulation of the argument email leads to sql injection. The attack may be initiated rem... Read more
Affected Products : mobile_shop- Published: Jul. 10, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-7410
A vulnerability was found in code-projects LifeStyle Store 1.0. It has been classified as critical. Affected is an unknown function of the file /cart_remove.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the atta... Read more
Affected Products : lifestyle_store- Published: Jul. 10, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-7411
A vulnerability was found in code-projects LifeStyle Store 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /success.php. The manipulation of the argument ID leads to sql injection. The attack c... Read more
Affected Products : lifestyle_store- Published: Jul. 10, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-7412
A vulnerability was found in code-projects Library System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /user/student/profile.php. The manipulation of the argument image leads to unrestricted upload. ... Read more
Affected Products : library_system- Published: Jul. 10, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2025-7413
A vulnerability classified as critical has been found in code-projects Library System 1.0. This affects an unknown part of the file /user/teacher/profile.php. The manipulation of the argument image leads to unrestricted upload. It is possible to initiate ... Read more
Affected Products : library_system- Published: Jul. 10, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2025-7414
A vulnerability classified as critical was found in Tenda O3V2 1.0.0.12(3880). This vulnerability affects the function fromNetToolGet of the file /goform/setPingInfo of the component httpd. The manipulation of the argument domain leads to os command injec... Read more
- Published: Jul. 10, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-7415
A vulnerability, which was classified as critical, has been found in Tenda O3V2 1.0.0.12(3880). This issue affects the function fromTraceroutGet of the file /goform/getTraceroute of the component httpd. The manipulation of the argument dest leads to comma... Read more
- Published: Jul. 10, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Injection
-
9.0
HIGHCVE-2025-7416
A vulnerability, which was classified as critical, was found in Tenda O3V2 1.0.0.12(3880). Affected is the function fromSysToolTime of the file /goform/setSysTimeInfo of the component httpd. The manipulation of the argument Time leads to stack-based buffe... Read more
- Published: Jul. 10, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-7454
A vulnerability classified as critical has been found in Campcodes Online Movie Theater Seat Reservation System 1.0. Affected is an unknown function of the file /admin/manage_theater.php. The manipulation of the argument ID leads to sql injection. It is p... Read more
Affected Products : online_movie_theater_seat_reservation_system- Published: Jul. 11, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Injection
-
9.1
CRITICALCVE-2025-49827
Conjur provides secrets management and application identity for infrastructure. Conjur OSS versions 1.19.5 through 1.22.0 and Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) 13.1 through 13.5 and 13.6 are vulnerable to bypass of the IAM... Read more
Affected Products :- Published: Jul. 15, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Authentication
-
6.0
MEDIUMCVE-2025-49829
Conjur provides secrets management and application identity for infrastructure. Missing validations in Secrets Manager, Self-Hosted allows authenticated attackers to inject resources into the database and to bypass permission checks. This issue affects Se... Read more
Affected Products :- Published: Jul. 15, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Injection
-
8.6
HIGHCVE-2025-49828
Conjur provides secrets management and application identity for infrastructure. Conjur OSS versions 1.19.5 through 1.21.1 and Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) 13.1 through 13.4.1 are vulnerable to remote code execution An... Read more
Affected Products :- Published: Jul. 15, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Misconfiguration
-
7.1
HIGHCVE-2025-49830
Conjur provides secrets management and application identity for infrastructure. An authenticated attacker who is able to load policy can use the policy yaml parser to reference files on the Secrets Manager, Self-Hosted server. These references may be used... Read more
Affected Products :- Published: Jul. 15, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-7455
A vulnerability classified as critical was found in Campcodes Online Movie Theater Seat Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file /manage_reserve.php. The manipulation of the argument mid leads to sql i... Read more
Affected Products : online_movie_theater_seat_reservation_system- Published: Jul. 11, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-7456
A vulnerability, which was classified as critical, has been found in Campcodes Online Movie Theater Seat Reservation System 1.0. Affected by this issue is some unknown functionality of the file /reserve.php. The manipulation of the argument ID leads to sq... Read more
Affected Products : online_movie_theater_seat_reservation_system- Published: Jul. 11, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Injection
-
6.4
MEDIUMCVE-2025-5843
The Brandfolder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 5.0.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated atta... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-54047
Missing Authorization vulnerability in QuanticaLabs Cost Calculator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Cost Calculator: from n/a through 7.4.... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Authorization
-
8.5
HIGHCVE-2025-54026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuanticaLabs GymBase Theme Classes allows SQL Injection. This issue affects GymBase Theme Classes: from n/a through 1.4.... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Injection
-
6.8
MEDIUMCVE-2025-53842
Use of hard-coded credentials issue exists in ZWX-2000CSW2-HN prior to 0.3.19 and ZWX-2000CS2-HN firmware all versions. If this vulnerability is exploited, an attacker may tamper with the settings of the device by obtaining the credentials. This vulnerabi... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Authentication
-
4.3
MEDIUMCVE-2025-48150
Missing Authorization vulnerability in Bill Minozzi Real Estate Property 2024 Create Your Own Fields and Search Bar WP Plugin allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Real Estate Property 2024 Create Your... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Authorization