Latest CVE Feed
-
8.6
HIGHCVE-2023-36052
Azure CLI REST Command Information Disclosure Vulnerability... Read more
Affected Products : azure_command-line_interface azure_cli azure_webapp_config_appsettings_set azure_logicapp_config_appsettings_set azure_staticwebapp_appsettings_delete azure_functionapp_config_appsettings_set azure_staticwebapp_appsettings_set azure_functionapp_config_appsettings_delete azure_webapp_config_appsettings_delete azure_logicapp_config_appsettings_delete- Published: Nov. 14, 2023
- Modified: Jul. 02, 2025
-
7.8
HIGHCVE-2025-24046
Use after free in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.... Read more
Affected Products : windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 windows_10_1507 windows +5 more products- Published: Mar. 11, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-6604
A vulnerability classified as critical has been found in SourceCodester Best Salon Management System 1.0. This affects an unknown part of the file /panel/add-staff.php. The manipulation of the argument Name leads to sql injection. It is possible to initia... Read more
Affected Products : best_salon_management_system- Published: Jun. 25, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-30719
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.1.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle ... Read more
Affected Products : vm_virtualbox- Published: Apr. 15, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Denial of Service
-
8.8
HIGHCVE-2025-6605
A vulnerability classified as critical was found in SourceCodester Best Salon Management System 1.0. This vulnerability affects unknown code of the file /panel/edit-staff.php. The manipulation of the argument editid leads to sql injection. The attack can ... Read more
Affected Products : best_salon_management_system- Published: Jun. 25, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2025-21532
Vulnerability in the Oracle Analytics Desktop product of Oracle Analytics (component: Install). Supported versions that are affected are Prior to 8.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure wher... Read more
Affected Products : analytics_desktop- Published: Jan. 21, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-49851
ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to an Improper Authentication vulnerability which could allow an attacker to bypass authentication and gain permissions in the product.... Read more
Affected Products : control_id_idsecure- Published: Jun. 24, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Authentication
-
8.7
HIGHCVE-2025-49852
ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to a server-side request forgery vulnerability which could allow an unauthenticated attacker to retrieve information from other servers.... Read more
Affected Products : control_id_idsecure- Published: Jun. 24, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Server-Side Request Forgery
-
9.3
CRITICALCVE-2025-49853
ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to SQL injections which could allow an attacker to leak arbitrary information and insert arbitrary SQL syntax into SQL queries.... Read more
Affected Products : control_id_idsecure- Published: Jun. 24, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-30717
Vulnerability in the Oracle Teleservice product of Oracle E-Business Suite (component: Service Diagnostics Scripts). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network acc... Read more
Affected Products : teleservice- Published: Apr. 15, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Authentication
-
5.4
MEDIUMCVE-2025-30718
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Attachments, File Upload). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with net... Read more
Affected Products : applications_framework- Published: Apr. 15, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Authorization
-
10.0
CRITICALCVE-2025-46828
WeGIA is a web manager for charitable institutions. An unauthenticated SQL Injection vulnerability was identified in versions up to and including 3.3.0 in the endpoint `/html/socio/sistema/get_socios.php`, specifically in the query parameter. This issue ... Read more
Affected Products : wegia- Published: May. 07, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Injection
-
9.1
CRITICALCVE-2024-43591
Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability... Read more
- Published: Oct. 08, 2024
- Modified: Jul. 02, 2025
-
8.8
HIGHCVE-2025-6606
A vulnerability, which was classified as critical, has been found in SourceCodester Best Salon Management System 1.0. This issue affects some unknown processing of the file /panel/add-services.php. The manipulation of the argument Type leads to sql inject... Read more
Affected Products : best_salon_management_system- Published: Jun. 25, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-50201
WeGIA is a web manager for charitable institutions. Prior to version 3.4.2, an OS Command Injection vulnerability was identified in the /html/configuracao/debug_info.php endpoint. The branch parameter is not properly sanitized before being concatenated an... Read more
Affected Products : wegia- Published: Jun. 19, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-6607
A vulnerability, which was classified as critical, was found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the file /panel/stock.php. The manipulation of the argument ID leads to sql injection. It is possible to la... Read more
Affected Products : best_salon_management_system- Published: Jun. 25, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-52474
WeGIA is a web manager for charitable institutions. Prior to version 3.4.2, a SQL Injection vulnerability was identified in the id parameter of the /WeGIA/controle/control.php endpoint. This vulnerability allows attacker to manipulate SQL queries and acce... Read more
Affected Products : wegia- Published: Jun. 19, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2024-27685
SQL Injection vulnerability in Student Record system Using PHP and MySQL v.3.20 allows a remote attacker to obtain sensitive information via a crafted payload to the $cshortname, $cfullname, and $cdate variables.... Read more
Affected Products : student_record_system- Published: Jun. 25, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-4840
The inprosysmedia-likes-dislikes-post WordPress plugin through 1.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection... Read more
Affected Products : likes_and_dislikes- Published: Jun. 10, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-4954
The Axle Demo Importer WordPress plugin through 1.0.3 does not validate files to be uploaded, which could allow authenticated users (author and above) to upload arbitrary files such as PHP on the server... Read more
Affected Products : axle_demo_importer- Published: Jun. 10, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Authentication