Latest CVE Feed
-
9.8
CRITICALCVE-2025-6863
A vulnerability classified as critical was found in PHPGurukul Local Services Search Engine Management System 2.1. Affected by this vulnerability is an unknown functionality of the file /admin/edit-category-detail.php. The manipulation of the argument edi... Read more
Affected Products : local_services_search_engine_management_system- Published: Jun. 29, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2025-6864
A vulnerability, which was classified as problematic, has been found in SeaCMS up to 13.2. Affected by this issue is some unknown functionality of the file /admin_type.php. The manipulation leads to cross-site request forgery. The attack may be launched r... Read more
Affected Products : seacms- Published: Jun. 29, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.3
MEDIUMCVE-2025-6865
A vulnerability, which was classified as problematic, was found in DaiCuo up to 1.3.13. This affects an unknown part of the file /admin.php/addon/index. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. ... Read more
Affected Products : daicuo- Published: Jun. 29, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.1
MEDIUMCVE-2025-22624
FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry and Carousel 2.4.29 was found to be vulnerable. The web application dynamically generates web content without validating the source of the potentially untrusted data in myapp/extensio... Read more
Affected Products :- Published: Feb. 27, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2025-6866
A vulnerability has been found in code-projects Simple Forum 1.0 and classified as critical. This vulnerability affects unknown code of the file /forum_downloadfile.php. The manipulation of the argument filename leads to path traversal. The attack can be ... Read more
Affected Products : simple_forum- Published: Jun. 29, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Path Traversal
-
7.8
HIGHCVE-2025-53415
Delta Electronics DTM Soft Project File Parsing Deserialization of Untrusted Data Remote Code Execution... Read more
Affected Products :- Published: Jun. 30, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Information Disclosure
-
5.4
MEDIUMCVE-2024-10306
A vulnerability was found in mod_proxy_cluster. The issue is that the <Directory> directive should be replaced by the <Location> directive as the former does not restrict IP/host access as `Require ip IP_ADDRESS` would suggest. This means that anyone with... Read more
- Published: Apr. 23, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-6847
A vulnerability classified as critical was found in code-projects Simple Forum 1.0. This vulnerability affects unknown code of the file /forum_edit.php. The manipulation of the argument iii leads to sql injection. The attack can be initiated remotely. The... Read more
Affected Products : simple_forum- Published: Jun. 29, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6844
A vulnerability was found in code-projects Simple Forum 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /signin.php. The manipulation of the argument User leads to sql injection. The attack can... Read more
Affected Products : simple_forum- Published: Jun. 29, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Injection
-
9.0
HIGHCVE-2025-6824
A vulnerability classified as critical has been found in TOTOLINK X15 up to 1.0.0-B20230714.1105. Affected is an unknown function of the file /boafrm/formParentControl of the component HTTP POST Request Handler. The manipulation of the argument submit-url... Read more
- Published: Jun. 28, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-6846
A vulnerability classified as critical has been found in code-projects Simple Forum 1.0. This affects an unknown part of the file /forum_viewfile.php. The manipulation of the argument Name leads to sql injection. It is possible to initiate the attack remo... Read more
Affected Products : simple_forum- Published: Jun. 29, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6845
A vulnerability was found in code-projects Simple Forum 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /register1.php. The manipulation of the argument User leads to sql injection. The attack may be la... Read more
Affected Products : simple_forum- Published: Jun. 29, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2012-6442
When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP that instructs the product to reset, a DoS can occur. This situation could cause loss of ava... Read more
Affected Products : 1756-enbt 1756-eweb 1768-enbt 1768-eweb ethernet\/ip_firmware compactlogix_firmware flexlogix_firmware flex_i\/o_ethernet\/ip__firmware micrologix_firmware compactlogix_controllers_firmware +12 more products- Published: Jan. 24, 2013
- Modified: Jun. 30, 2025
-
5.0
MEDIUMCVE-2012-6441
An information exposure of confidential information results when the device receives a specially crafted CIP packet to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP. Successful exploitation of this vulnerability could cause loss of confi... Read more
Affected Products : controllogix_controllers guardlogix_controllers micrologix softlogix_controllers 1756-enbt 1756-eweb 1768-enbt 1768-eweb 1794-aentr_flex_i\/o_ethernet\/ip_adapter compactlogix +8 more products- Published: Jan. 24, 2013
- Modified: Jun. 30, 2025
-
9.3
HIGHCVE-2012-6440
The Web server password authentication mechanism used by the products is vulnerable to a MitM and Replay attack. Successful exploitation of this vulnerability will allow unauthorized access of the product’s Web server to view and alter product configurati... Read more
Affected Products : controllogix_controllers guardlogix_controllers micrologix softlogix_controllers 1756-enbt 1756-eweb 1768-enbt 1768-eweb 1794-aentr_flex_i\/o_ethernet\/ip_adapter compactlogix +8 more products- Published: Jan. 24, 2013
- Modified: Jun. 30, 2025
-
8.5
HIGHCVE-2012-6439
When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP that changes the product’s configuration and network parameters, a DoS condition can occ... Read more
Affected Products : controllogix_controllers guardlogix_controllers micrologix softlogix_controllers 1756-enbt 1756-eweb 1768-enbt 1768-eweb 1794-aentr_flex_i\/o_ethernet\/ip_adapter compactlogix +8 more products- Published: Jan. 24, 2013
- Modified: Jun. 30, 2025
-
7.8
HIGHCVE-2012-6438
The device does not properly validate the data being sent to the buffer. An attacker can send a malformed CIP packet to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP, which creates a buffer overflow and causes the NIC to crash. Successfu... Read more
Affected Products : controllogix_controllers guardlogix_controllers micrologix softlogix_controllers 1756-enbt 1756-eweb 1768-enbt 1768-eweb 1794-aentr_flex_i\/o_ethernet\/ip_adapter compactlogix +8 more products- Published: Jan. 24, 2013
- Modified: Jun. 30, 2025
-
10.0
HIGHCVE-2012-6437
The device does not properly authenticate users and the potential exists for a remote user to upload a new firmware image to the Ethernet card, whether it is a corrupt or legitimate firmware image. Successful exploitation of this vulnerability could cause... Read more
Affected Products : controllogix_controllers guardlogix_controllers micrologix softlogix_controllers 1756-enbt 1756-eweb 1768-enbt 1768-eweb 1794-aentr_flex_i\/o_ethernet\/ip_adapter compactlogix +8 more products- Published: Jan. 24, 2013
- Modified: Jun. 30, 2025
-
7.8
HIGHCVE-2012-6436
The device does not properly validate the data being sent to the buffer. An attacker can send a malformed CIP packet to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP, which creates a buffer overflow and causes the CPU to crash. Successfu... Read more
Affected Products : controllogix_controllers guardlogix_controllers micrologix softlogix_controllers 1756-enbt 1756-eweb 1768-enbt 1768-eweb 1794-aentr_flex_i\/o_ethernet\/ip_adapter compactlogix +8 more products- Published: Jan. 24, 2013
- Modified: Jun. 30, 2025
-
7.8
HIGHCVE-2012-6435
When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP that instructs the CPU to stop logic execution and enter a fault state, a DoS can occur. Thi... Read more
Affected Products : controllogix_controllers guardlogix_controllers micrologix softlogix_controllers 1756-enbt 1756-eweb 1768-enbt 1768-eweb 1794-aentr_flex_i\/o_ethernet\/ip_adapter compactlogix +8 more products- Published: Jan. 24, 2013
- Modified: Jun. 30, 2025