Latest CVE Feed
-
7.2
HIGHCVE-2025-3771
A path or symbolic link manipulation vulnerability in SIR 1.0.3 and prior versions allows an authenticated non-admin local user to overwrite system files with SIR backup files, which can potentially cause a system crash. This was achieved by adding a mali... Read more
Affected Products :- Published: Jun. 26, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Path Traversal
-
8.6
HIGHCVE-2025-52477
Octo-STS is a GitHub App that acts like a Security Token Service (STS) for the GitHub API. Octo-STS versions before v0.5.3 are vulnerable to unauthenticated SSRF by abusing fields in OpenID Connect tokens. Malicious tokens were shown to trigger internal n... Read more
Affected Products :- Published: Jun. 26, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Server-Side Request Forgery
-
8.1
HIGHCVE-2025-52480
Registrator is a GitHub app that automates creation of registration pull requests for julia packages to the General registry. Prior to version 1.9.5, if the clone URL returned by GitHub is malicious (or can be injected using upstream vulnerabilities), an ... Read more
Affected Products :- Published: Jun. 25, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection
-
3.4
LOWCVE-2025-52889
Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus version 6.12 and 6.13 generates nftables rules for local services (DHCP, DNS...) that partially bypass security options `security.mac_filte... Read more
Affected Products :- Published: Jun. 25, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-6323
A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0. It has been classified as critical. This affects an unknown part of the file /enrollment.php. The manipulation of the argument fathername leads to sql injection. It is possible to i... Read more
Affected Products : pre-school_enrollment_system- Published: Jun. 20, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6330
A vulnerability classified as critical has been found in PHPGurukul Directory Management System 1.0. Affected is an unknown function of the file /searchdata.php. The manipulation of the argument searchdata leads to sql injection. It is possible to launch ... Read more
Affected Products : directory_management_system- Published: Jun. 20, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-6331
A vulnerability classified as critical was found in PHPGurukul Directory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/search-directory.php. The manipulation of the argument searchdata leads to sql in... Read more
Affected Products : directory_management_system- Published: Jun. 20, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-6332
A vulnerability, which was classified as critical, has been found in PHPGurukul Directory Management System 2.0. Affected by this issue is some unknown functionality of the file /admin/manage-directory.php. The manipulation of the argument del leads to sq... Read more
Affected Products : directory_management_system- Published: Jun. 20, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-6333
A vulnerability, which was classified as critical, was found in PHPGurukul Directory Management System 2.0. This affects an unknown part of the file /admin/admin-profile.php. The manipulation of the argument adminname leads to sql injection. It is possibl... Read more
Affected Products : directory_management_system- Published: Jun. 20, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection
-
9.0
HIGHCVE-2025-6336
A vulnerability was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. It has been classified as critical. Affected is an unknown function of the file /boafrm/formTmultiAP of the component HTTP POST Request Handler. The manipulation of the argument submit-... Read more
- Published: Jun. 20, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Memory Corruption
-
5.4
MEDIUMCVE-2025-6340
A vulnerability classified as problematic has been found in code-projects School Fees Payment System 1.0. This affects an unknown part of the file /branch.php. The manipulation of the argument Branch/Address/Detail leads to cross site scripting. It is pos... Read more
Affected Products : school_fees_payment_system- Published: Jun. 20, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2019-6535
Mitsubishi Electric Q03/04/06/13/26UDVCPU: serial number 20081 and prior, Q04/06/13/26UDPVCPU: serial number 20081 and prior, and Q03UDECPU, Q04/06/10/13/20/26/50/100UDEHCPU: serial number 20101 and prior. A remote attacker can send specific bytes over Po... Read more
Affected Products : q03udecpu_firmware q04udehcpu_firmware q04udpvcpu_firmware q04udvcpu_firmware q100udehcpu_firmware q50udehcpu_firmware q26udehcpu_firmware q26udpvcpu_firmware q26udvcpu_firmware q20udehcpu_firmware +28 more products- Published: Feb. 05, 2019
- Modified: Jun. 26, 2025
-
5.3
MEDIUMCVE-2025-6341
A vulnerability classified as problematic was found in code-projects School Fees Payment System 1.0. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been ... Read more
Affected Products : school_fees_payment_system- Published: Jun. 20, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Cross-Site Request Forgery
-
9.0
HIGHCVE-2025-6292
A vulnerability has been found in D-Link DIR-825 2.03 and classified as critical. This vulnerability affects the function sub_4091AC of the component HTTP POST Request Handler. The manipulation leads to stack-based buffer overflow. The attack can be initi... Read more
- Published: Jun. 20, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-6293
A vulnerability was found in code-projects Hostel Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /contact_manager.php. The manipulation of the argument student_roll_no leads to sql injection. The a... Read more
- Published: Jun. 20, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6294
A vulnerability was found in code-projects Hostel Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /contact.php. The manipulation of the argument hostel_name leads to sql injection. It is possible to l... Read more
- Published: Jun. 20, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6295
A vulnerability was found in code-projects Hostel Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /allocated_rooms.php. The manipulation of the argument search_box leads to sq... Read more
- Published: Jun. 20, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2025-27587
OpenSSL 3.0.0 through 3.3.2 on the PowerPC architecture is vulnerable to a Minerva attack, exploitable by measuring the time of signing of random messages using the EVP_DigestSign API, and then using the private key to extract the K value (nonce) from the... Read more
Affected Products :- Published: Jun. 16, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Cryptography
-
9.8
CRITICALCVE-2010-5305
The potential exists for exposure of the product's password used to restrict unauthorized access to Rockwell PLC5/SLC5/0x/RSLogix 1785-Lx and 1747-L5x controllers. The potential exists for an unauthorized programming and configuration client to gain acces... Read more
Affected Products : rslogix plc5_1785-lx_firmware slc5\/01_1747-l5x_firmware plc5_1785-lx slc5\/01_1747-l5x- Published: Mar. 26, 2019
- Modified: Jun. 26, 2025
-
9.8
CRITICALCVE-2025-6300
A vulnerability classified as critical was found in PHPGurukul Employee Record Management System 1.3. This vulnerability affects unknown code of the file /admin/editempeducation.php. The manipulation of the argument yopgra leads to sql injection. The atta... Read more
Affected Products : employee_record_management_system- Published: Jun. 20, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection