Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2025-6450

    A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/confirm_reserve.php. The manipulation of the argument transaction_id leads to sql in... Read more

    • Published: Jun. 22, 2025
    • Modified: Jun. 27, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-6449

    A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/checkout_query.php. The manipulation of the argument transaction_id l... Read more

    • Published: Jun. 22, 2025
    • Modified: Jun. 27, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-6448

    A vulnerability has been found in code-projects Simple Online Hotel Reservation System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/delete_room.php. The manipulation of the argument room_id ... Read more

    • Published: Jun. 22, 2025
    • Modified: Jun. 27, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-6500

    A vulnerability, which was classified as critical, has been found in code-projects Inventory Management System 1.0. Affected by this issue is some unknown functionality of the file /php_action/editCategories.php. The manipulation of the argument editCateg... Read more

    Affected Products : inventory_management_system
    • Published: Jun. 23, 2025
    • Modified: Jun. 27, 2025
    • Vuln Type: Injection
  • 10.0

    CRITICAL
    CVE-2024-54085

    AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.... Read more

    • Actively Exploited
    • Published: Mar. 11, 2025
    • Modified: Jun. 27, 2025
    • Vuln Type: Authentication
  • 9.8

    CRITICAL
    CVE-2025-6501

    A vulnerability, which was classified as critical, was found in code-projects Inventory Management System 1.0. This affects an unknown part of the file /php_action/createCategories.php. The manipulation of the argument categoriesStatus leads to sql inject... Read more

    Affected Products : inventory_management_system
    • Published: Jun. 23, 2025
    • Modified: Jun. 27, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-6472

    A vulnerability, which was classified as critical, has been found in code-projects Online Bidding System 1.0. Affected by this issue is some unknown functionality of the file /showprod.php. The manipulation of the argument ID leads to sql injection. The a... Read more

    Affected Products : online_bidding_system
    • Published: Jun. 22, 2025
    • Modified: Jun. 27, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-6502

    A vulnerability has been found in code-projects Inventory Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /php_action/changePassword.php. The manipulation of the argument user_id leads to sql injection... Read more

    Affected Products : inventory_management_system
    • Published: Jun. 23, 2025
    • Modified: Jun. 27, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-6471

    A vulnerability classified as critical was found in code-projects Online Bidding System 1.0. Affected by this vulnerability is an unknown functionality of the file /administrator. The manipulation of the argument aduser leads to sql injection. The attack ... Read more

    Affected Products : online_bidding_system
    • Published: Jun. 22, 2025
    • Modified: Jun. 27, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-6503

    A vulnerability was found in code-projects Inventory Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /php_action/fetchSelectedCategories.php. The manipulation of the argument categoriesId leads to s... Read more

    Affected Products : inventory_management_system
    • Published: Jun. 23, 2025
    • Modified: Jun. 27, 2025
    • Vuln Type: Injection
  • 8.8

    HIGH
    CVE-2024-5921

    An insufficient certification validation issue in the Palo Alto Networks GlobalProtect app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable a local non-administrative operating system user or an attacker on the same... Read more

    Affected Products : globalprotect globalprotect_app
    • Published: Nov. 27, 2024
    • Modified: Jun. 27, 2025
  • 9.8

    CRITICAL
    CVE-2025-6470

    A vulnerability classified as critical has been found in code-projects Online Bidding System 1.0. Affected is an unknown function of the file /bidlog.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remo... Read more

    Affected Products : online_bidding_system
    • Published: Jun. 22, 2025
    • Modified: Jun. 27, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2024-54280

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design WPBookit allows SQL Injection.This issue affects WPBookit: from n/a through 1.6.0.... Read more

    Affected Products : wpbookit wpbookit
    • Published: Dec. 16, 2024
    • Modified: Jun. 27, 2025
  • 9.8

    CRITICAL
    CVE-2025-6469

    A vulnerability was found in code-projects Online Bidding System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /details.php. The manipulation of the argument ID leads to sql injection. The attack may be initiat... Read more

    Affected Products : online_bidding_system
    • Published: Jun. 22, 2025
    • Modified: Jun. 27, 2025
    • Vuln Type: Injection
  • 8.0

    HIGH
    CVE-2025-0118

    A vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a remote attacker to run ActiveX controls within the context of an authenticated Windows user. This enables the attacker to run commands as if they are a legitimate authenticate... Read more

    Affected Products : globalprotect globalprotect_app
    • Published: Mar. 12, 2025
    • Modified: Jun. 27, 2025
    • Vuln Type: Misconfiguration
  • 7.1

    HIGH
    CVE-2025-0120

    A vulnerability with a privilege management mechanism in the Palo Alto Networks GlobalProtect™ app on Windows devices allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM. However, execution re... Read more

    Affected Products : globalprotect globalprotect_app
    • Published: Apr. 11, 2025
    • Modified: Jun. 27, 2025
    • Vuln Type: Authorization
  • 8.8

    HIGH
    CVE-2024-36538

    Insecure permissions in chaos-mesh v2.6.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.... Read more

    Affected Products : chaos-mesh
    • Published: Jul. 24, 2024
    • Modified: Jun. 27, 2025
  • 7.2

    HIGH
    CVE-2024-36537

    Insecure permissions in cert-manager v1.14.4 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.... Read more

    Affected Products : cert-manager
    • Published: Jul. 24, 2024
    • Modified: Jun. 27, 2025
  • 5.2

    MEDIUM
    CVE-2025-0135

    An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a locally authenticated non administrative user to disable the app. The GlobalProtect app on Windows, Linux, iOS, Android, Chrome OS and... Read more

    Affected Products : globalprotect globalprotect_app
    • Published: May. 14, 2025
    • Modified: Jun. 27, 2025
    • Vuln Type: Authorization
  • 9.8

    CRITICAL
    CVE-2024-36536

    Insecure permissions in fabedge v0.8.1 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.... Read more

    Affected Products : fabedge
    • Published: Jul. 24, 2024
    • Modified: Jun. 27, 2025
Showing 20 of 293983 Results