Latest CVE Feed
-
9.8
CRITICALCVE-2025-6904
A vulnerability was found in code-projects Car Rental System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/add_cars.php. The manipulation of the argument car_name leads to sql injection. The at... Read more
Affected Products : car_rental_system- Published: Jun. 30, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6903
A vulnerability was found in code-projects Car Rental System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/approve.php. The manipulation of the argument ID leads to sql injection. The ... Read more
Affected Products : car_rental_system- Published: Jun. 30, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-53924
Pycel through 1.0b30, when operating on an untrusted spreadsheet, allows code execution via a crafted formula in a cell, such as one beginning with the =IF(A1=200, eval("__import__('os').system( substring.... Read more
Affected Products : pycel- Published: Apr. 17, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-7211
A vulnerability was found in code-projects LifeStyle Store 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /cart_add.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated re... Read more
Affected Products : lifestyle_store- Published: Jul. 09, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
5.5
MEDIUMCVE-2025-26269
DragonflyDB Dragonfly through 1.28.2 (fixed in 1.29.0) allows authenticated users to cause a denial of service (daemon crash) via a Lua library command that references a large negative integer.... Read more
Affected Products : dragonfly- Published: Apr. 17, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Denial of Service
-
5.1
MEDIUMCVE-2023-49031
Directory Traversal (Local File Inclusion) vulnerability in Tikit (now Advanced) eMarketing platform 6.8.3.0 allows a remote attacker to read arbitrary files and obtain sensitive information via a crafted payload to the filename parameter to the OpenLogFi... Read more
Affected Products : tikit_emarketing- Published: Mar. 03, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Path Traversal
-
7.8
HIGHCVE-2025-25179
Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages.... Read more
Affected Products : ddk- Published: Jun. 02, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-7220
A vulnerability was found in Campcodes Payroll Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=save_deductions. The manipulation of the argument ID leads to s... Read more
Affected Products : payroll_management_system- Published: Jul. 09, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
8.2
HIGHCVE-2025-0467
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.... Read more
Affected Products : ddk- Published: Apr. 18, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-7219
A vulnerability was found in Campcodes Payroll Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /ajax.php?action=delete_allowances. The manipulation of the argument ID leads to sql injection. It is pos... Read more
Affected Products : payroll_management_system- Published: Jul. 09, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-7218
A vulnerability was found in Campcodes Payroll Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /ajax.php?action=delete_position. The manipulation of the argument ID leads to sql injection. The attac... Read more
Affected Products : payroll_management_system- Published: Jul. 09, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2024-38291
In XIQ-SE before 24.2.11, a low-privileged user may be able to access admin passwords, which could lead to privilege escalation.... Read more
Affected Products : xiq-se- Published: Feb. 27, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-7217
A vulnerability has been found in Campcodes Payroll Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /ajax.php?action=save_position. The manipulation of the argument ID leads to sql injection. The attac... Read more
Affected Products : payroll_management_system- Published: Jul. 09, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2024-38290
In XIQ-SE before 24.2.11, a server misconfiguration may allow user enumeration when specific conditions are met.... Read more
Affected Products : xiq-se- Published: Feb. 27, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2024-38292
In Extreme Networks XIQ-SE before 24.2.11, due to a missing access control check, a path traversal is possible, which may lead to privilege escalation.... Read more
Affected Products : xiq-se- Published: Feb. 27, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-6826
A vulnerability, which was classified as critical, has been found in code-projects Payroll Management System 1.0. Affected by this issue is some unknown functionality of the file /Payroll_Management_System/ajax.php?action=save_department. The manipulation... Read more
- Published: Jun. 28, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
6.3
MEDIUMCVE-2024-52290
LF Edge eKuiper is a lightweight internet of things (IoT) data analytics and stream processing engine. Prior to version 2.1.0 user with rights to modificate the service (e.g. kuiperUser role) can inject a cross-site scripting payload into Connection Confi... Read more
Affected Products : ekuiper- Published: May. 14, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-26795
Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in Apache IoTDB JDBC driver. This issue affects iotdb-jdbc: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2. Users are rec... Read more
Affected Products : iotdb- Published: May. 14, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Information Disclosure
-
8.6
HIGHCVE-2025-47775
Bullfrog is a GithHb Action to block unauthorized outbound traffic in GitHub workflows. Prior to version 0.8.4, using tcp breaks blocking and allows DNS exfiltration. This can result in sandbox bypass. Version 0.8.4 fixes the issue.... Read more
Affected Products : bullfrog- Published: May. 14, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-47781
Rallly is an open-source scheduling and collaboration tool. Versions up to and including 3.22.1 of the application features token based authentication. When a user attempts to login to the application, they insert their email and a 6 digit code is sent to... Read more
Affected Products : rally- Published: May. 14, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Authentication