Latest CVE Feed
-
5.1
MEDIUMCVE-2025-6695
A vulnerability was found in LabRedesCefetRJ WeGIA 3.4.0 and classified as problematic. This issue affects some unknown processing of the file /html/matPat/adicionar_categoria.php of the component Additional Categoria. The manipulation of the argument Ins... Read more
Affected Products : wegia- Published: Jun. 26, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Cross-Site Scripting
-
6.3
MEDIUMCVE-2025-45729
D-Link DIR-823-Pro 1.02 has improper permission control, allowing unauthorized users to turn on and access Telnet services.... Read more
- Published: Jun. 27, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Authentication
-
4.3
MEDIUMCVE-2025-46708
Software installed and running inside a Guest VM may conduct improper GPU system calls to prevent other Guests from running work on the GPU.... Read more
Affected Products : ddk- Published: Jun. 27, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Denial of Service
-
4.7
MEDIUMCVE-2024-6288
The Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tiktok_user_id’ parameter in all versions up to, and including, 7.1.0 due to ... Read more
Affected Products :- Published: Jun. 28, 2024
- Modified: Jul. 01, 2025
-
7.2
HIGHCVE-2024-13914
The File Manager Advanced Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.5.4 (file-manager-advanced-shortcode) and 2.5.6 (advanced-file-manager-pro-premium), via the 'file_manager_advanced' sho... Read more
Affected Products :- Published: May. 15, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Path Traversal
-
9.1
CRITICALCVE-2019-20444
HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an "invalid fold."... Read more
- Published: Jan. 29, 2020
- Modified: Jul. 01, 2025
-
7.3
HIGHCVE-2025-50528
A buffer overflow vulnerability exists in the fromNatStaticSetting function of Tenda AC6 <=V15.03.05.19 via the page parameter.... Read more
- Published: Jun. 27, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Memory Corruption
-
6.1
MEDIUMCVE-2025-50367
A stored blind XSS vulnerability exists in the Contact Page of the Phpgurukul Medical Card Generation System 1.0 mcgs/contact.php. The name field fails to properly sanitize user input, allowing an attacker to inject malicious JavaScript.... Read more
Affected Products : medical_card_generation_system- Published: Jun. 27, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-50369
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Manage Card functionality (/mcgs/admin/manage-card.php) of PHPGurukul Medical Card Generation System 1.0. The vulnerable endpoint allows an authorized admin to delete medical card records by ... Read more
Affected Products : medical_card_generation_system- Published: Jun. 27, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.5
MEDIUMCVE-2025-50370
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Inquiry Management functionality /mcgs/admin/readenq.php of the Phpgurukul Medical Card Generation System 1.0. The vulnerable endpoint allows an authenticated admin to delete inquiry records ... Read more
Affected Products : medical_card_generation_system- Published: Jun. 27, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.4
MEDIUMCVE-2024-52900
IBM Cognos Analytics 11.2.0 through 12.2.4 Fix Pack 5 and 12.0.0 through 12.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functio... Read more
Affected Products : cognos_analytics- Published: Jun. 28, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Cross-Site Scripting
-
8.0
HIGHCVE-2025-51672
A time-based blind SQL injection vulnerability was identified in the PHPGurukul Dairy Farm Shop Management System 1.3. The vulnerability exists in the manage-companies.php file and allows remote attackers to execute arbitrary SQL code via the companyname ... Read more
Affected Products : dairy_farm_shop_management_system- Published: Jun. 26, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Injection
-
5.1
MEDIUMCVE-2025-6696
A vulnerability was found in LabRedesCefetRJ WeGIA 3.4.0. It has been classified as problematic. Affected is an unknown function of the file /html/atendido/Cadastro_Atendido.php of the component Cadastro de Atendio. The manipulation of the argument Nome/S... Read more
Affected Products : wegia- Published: Jun. 26, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Cross-Site Scripting
-
5.1
MEDIUMCVE-2025-6697
A vulnerability was found in LabRedesCefetRJ WeGIA 3.4.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /html/matPat/adicionar_tipoEntrada.php of the component Adicionar tipo. The manipulation ... Read more
Affected Products : wegia- Published: Jun. 26, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Cross-Site Scripting
-
5.1
MEDIUMCVE-2025-6698
A vulnerability was found in LabRedesCefetRJ WeGIA 3.4.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /html/matPat/adicionar_tipoSaida.php of the component Adicionar tipo. The manipulation of the argu... Read more
Affected Products : wegia- Published: Jun. 26, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-6750
A vulnerability, which was classified as problematic, has been found in HDF5 1.14.6. Affected by this issue is the function H5O__mtime_new_encode of the file src/H5Omtime.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requ... Read more
Affected Products : hdf5- Published: Jun. 27, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Memory Corruption
-
5.4
MEDIUMCVE-2025-5035
The Firelight Lightbox WordPress plugin before 2.3.16 does not sanitise and escape title attributes before outputting them in the page, which could allow users with a role as low as contributors to perform stored Cross-Site Scripting attacks.... Read more
Affected Products : firelight_lightbox- Published: Jun. 27, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-5093
The Responsive Lightbox & Gallery WordPress plugin before 2.5.2 use the Swipebox library which does not validate and escape title attributes before outputting them back in a page/post where used, which could allow users with the contributor role and above... Read more
Affected Products : responsive_lightbox- Published: Jun. 27, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-6816
A vulnerability classified as problematic was found in HDF5 1.14.6. This vulnerability affects the function H5O__fsinfo_encode of the file /src/H5Ofsinfo.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the l... Read more
Affected Products : hdf5- Published: Jun. 28, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Memory Corruption
-
4.8
MEDIUMCVE-2025-6817
A vulnerability, which was classified as problematic, has been found in HDF5 1.14.6. This issue affects the function H5C__load_entry of the file /src/H5Centry.c. The manipulation leads to resource consumption. The attack needs to be approached locally. Th... Read more
Affected Products : hdf5- Published: Jun. 28, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Denial of Service