Latest CVE Feed
-
7.5
HIGHCVE-2024-37767
Insecure permissions in the component /api/admin/user of 14Finger v1.1 allows attackers to access all user information via a crafted GET request.... Read more
Affected Products : 14finger- Published: Jul. 05, 2024
- Modified: Jul. 01, 2025
-
4.3
MEDIUMCVE-2024-23937
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the debug interface. ... Read more
Affected Products : gecko_os- Published: Jan. 31, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Information Disclosure
-
7.3
HIGHCVE-2024-23929
This vulnerability allows network-adjacent attackers to create arbitrary files on affected installations of Pioneer DMH-WT7600NEX devices. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypa... Read more
- Published: Jan. 31, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Path Traversal
-
8.8
HIGHCVE-2024-23921
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the wlanapp... Read more
- Published: Jan. 31, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2024-23920
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the onboard... Read more
- Published: Jan. 31, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Authentication
-
8.1
HIGHCVE-2023-4428
Out of bounds memory access in CSS in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Aug. 23, 2023
- Modified: Jul. 01, 2025
-
9.8
CRITICALCVE-2023-40890
A stack-based buffer overflow vulnerability exists in the lookup_sequence function of ZBar 0.23.90. Specially crafted QR codes may lead to information disclosure and/or arbitrary code execution. To trigger this vulnerability, an attacker can digitally inp... Read more
Affected Products : zbar- Published: Aug. 29, 2023
- Modified: Jul. 01, 2025
-
5.4
MEDIUMCVE-2023-40282
Improper authentication vulnerability in Rakuten WiFi Pocket all versions allows a network-adjacent attacker to log in to the product's Management Screen. As a result, sensitive information may be obtained and/or the settings may be changed.... Read more
- Published: Aug. 23, 2023
- Modified: Jul. 01, 2025
-
7.5
HIGHCVE-2023-32559
A privilege escalation vulnerability exists in the experimental policy mechanism in all active release lines: 16.x, 18.x and, 20.x. The use of the deprecated API `process.binding()` can bypass the policy mechanism by requiring internal modules and eventua... Read more
Affected Products : node.js- Published: Aug. 24, 2023
- Modified: Jul. 01, 2025
-
8.8
HIGHCVE-2024-50930
An issue in Silicon Labs Z-Wave Series 500 v6.84.0 allows attackers to execute arbitrary code.... Read more
- Published: Dec. 10, 2024
- Modified: Jul. 01, 2025
-
9.8
CRITICALCVE-2025-6822
A vulnerability was found in code-projects Inventory Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /php_action/removeProduct.php. The manipulation of the argument productId leads to sql inject... Read more
Affected Products : inventory_management_system- Published: Jun. 28, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Injection
-
4.6
MEDIUMCVE-2024-50931
Silicon Labs Z-Wave Series 500 v6.84.0 was discovered to contain insecure permissions.... Read more
- Published: Dec. 10, 2024
- Modified: Jul. 01, 2025
-
5.9
MEDIUMCVE-2024-30192
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GS Plugins GS Pins for Pinterest allows Stored XSS.This issue affects GS Pins for Pinterest: from n/a through 1.8.2. ... Read more
Affected Products : gs_pinterest_portfolio- Published: Mar. 27, 2024
- Modified: Jul. 01, 2025
-
9.8
CRITICALCVE-2025-6823
A vulnerability was found in code-projects Inventory Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /php_action/editProduct.php. The manipulation of the argument editProductName leads to sql in... Read more
Affected Products : inventory_management_system- Published: Jun. 28, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6835
A vulnerability was found in code-projects Library System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /student-issue-book.php. The manipulation of the argument reg leads to sql injection. The attack may be in... Read more
Affected Products : library_system- Published: Jun. 29, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-6848
A vulnerability, which was classified as critical, has been found in code-projects Simple Forum 1.0. This issue affects some unknown processing of the file /forum1.php. The manipulation of the argument File leads to unrestricted upload. The attack may be ... Read more
Affected Products : simple_forum- Published: Jun. 29, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Authentication
-
5.5
MEDIUMCVE-2024-46657
Artifex Software mupdf v1.24.9 was discovered to contain a segmentation fault via the component /tools/pdfextract.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.... Read more
Affected Products : mupdf- Published: Dec. 10, 2024
- Modified: Jul. 01, 2025
-
8.8
HIGHCVE-2025-6860
A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /panel/staff_commision.php. The manipulation of the argument fromdate/todate leads to sql i... Read more
Affected Products : best_salon_management_system- Published: Jun. 29, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-6861
A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /panel/add_plan.php. The manipulation of the argument plan_name/description/duration_days/p... Read more
Affected Products : best_salon_management_system- Published: Jun. 29, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-6862
A vulnerability classified as critical has been found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the file /panel/edit_plan.php. The manipulation of the argument editid leads to sql injection. It is possible to l... Read more
Affected Products : best_salon_management_system- Published: Jun. 29, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Injection