Latest CVE Feed
-
9.8
CRITICALCVE-2025-6482
A vulnerability, which was classified as critical, was found in code-projects Simple Pizza Ordering System 1.0. Affected is an unknown function of the file /edituser-exec.php. The manipulation of the argument userid leads to sql injection. It is possible ... Read more
Affected Products : simple_pizza_ordering_system- Published: Jun. 22, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2025-6218
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerability in that the ... Read more
- Published: Jun. 21, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-6483
A vulnerability has been found in code-projects Simple Pizza Ordering System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /edituser.php. The manipulation of the argument ID leads to sql injection. ... Read more
Affected Products : simple_pizza_ordering_system- Published: Jun. 22, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2025-3686
A vulnerability classified as problematic was found in misstt123 oasys 1.0. Affected by this vulnerability is the function image of the file /show. The manipulation leads to path traversal. The attack can be launched remotely. The exploit has been disclos... Read more
Affected Products : oasys- Published: Apr. 16, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Path Traversal
-
5.3
MEDIUMCVE-2025-3687
A vulnerability, which was classified as problematic, has been found in misstt123 oasys 1.0. Affected by this issue is some unknown functionality of the component Sticky Notes Handler. The manipulation leads to cross-site request forgery. The attack may b... Read more
Affected Products : oasys- Published: Apr. 16, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.4
MEDIUMCVE-2024-40124
Pydio Core <= 8.2.5 is vulnerable to Cross Site Scripting (XSS) via the New URL Bookmark feature.... Read more
Affected Products : pydio- Published: Apr. 17, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Cross-Site Scripting
-
5.5
MEDIUMCVE-2024-57493
An issue in redoxOS relibc before commit 98aa4ea5 allows a local attacker to cause a denial of service via the setsockopt function.... Read more
Affected Products : redox- Published: Apr. 18, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Denial of Service
-
3.4
LOWCVE-2025-25983
An issue in Macro-video Technologies Co.,Ltd V380 Pro android application 2.1.44 and V380 Pro android application 2.1.64 allows an attacker to obtain sensitive information via the QE code based sharing component.... Read more
Affected Products : v380_pro- Published: Apr. 18, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Information Disclosure
-
6.8
MEDIUMCVE-2025-25984
An issue in Macro-video Technologies Co.,Ltd V380E6_C1 IP camera (Hw_HsAKPIQp_WF_XHR) 1020302 allows a physically proximate attacker to execute arbitrary code via UART component.... Read more
- Published: Apr. 18, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Memory Corruption
-
2.6
LOWCVE-2025-25985
An issue in Macro-video Technologies Co.,Ltd V380E6_C1 IP camera (Hw_HsAKPIQp_WF_XHR) 1020302 allows a physically proximate attacker to execute arbitrary code via the /mnt/mtd/mvconf/wifi.ini and /mnt/mtd/mvconf/user_info.ini components.... Read more
- Published: Apr. 18, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Authentication
-
2.9
LOWCVE-2023-26819
cJSON 1.7.15 might allow a denial of service via a crafted JSON document such as {"a": true, "b": [ null,9999999999999999999999999999999999999999999999912345678901234567]}.... Read more
Affected Products : cjson- Published: Apr. 19, 2025
- Modified: Jun. 25, 2025
-
9.8
CRITICALCVE-2025-5441
A vulnerability classified as critical was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This vulnerability affects the function setDeviceURL of the file /goform/setDeviceURL. T... Read more
Affected Products : re6500_firmware re6300_firmware re6300 re6500 re9000_firmware re9000 re6250_firmware re6250 re6350_firmware re6350 +2 more products- Published: Jun. 02, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5442
A vulnerability, which was classified as critical, has been found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This issue affects the function RP_pingGatewayByBBS of the file /goform... Read more
Affected Products : re6500_firmware re6300_firmware re6300 re6500 re9000_firmware re9000 re6250_firmware re6250 re6350_firmware re6350 +2 more products- Published: Jun. 02, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-48957
AstrBot is a large language model chatbot and development framework. A path traversal vulnerability present in versions 3.4.4 through 3.5.12 may lead to information disclosure, such as API keys for LLM providers, account passwords, and other sensitive dat... Read more
Affected Products : astrbot- Published: Jun. 02, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Path Traversal
-
5.5
MEDIUMCVE-2025-48958
Froxlor is open source server administration software. Prior to version 2.2.6, an HTML Injection vulnerability in the customer account portal allows an attacker to inject malicious HTML payloads in the email section. This can lead to phishing attacks, cre... Read more
Affected Products : froxlor- Published: Jun. 02, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-5446
A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been classified as critical. This affects the function RP_checkCredentialsByBBS of the file /goform/RP_c... Read more
Affected Products : re6500_firmware re6300_firmware re6300 re6500 re9000_firmware re9000 re6250_firmware re6250 re6350_firmware re6350 +2 more products- Published: Jun. 02, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Injection
-
10.0
HIGHCVE-2009-2466
The JavaScript engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsDOMClassInfo.cpp, (2) JS_... Read more
- Published: Jul. 22, 2009
- Modified: Jun. 25, 2025
-
10.0
HIGHCVE-2010-1233
Multiple integer overflows in Google Chrome before 4.1.249.1036 allow remote attackers to have an unspecified impact via vectors involving WebKit JavaScript objects.... Read more
Affected Products : chrome- Published: Apr. 01, 2010
- Modified: Jun. 25, 2025
-
9.8
CRITICALCVE-2021-32292
An issue was discovered in json-c from 20200420 (post 0.14 unreleased code) through 0.15-20200726. A stack-buffer-overflow exists in the auxiliary sample program json_parse which is located in the function parseit.... Read more
- Published: Aug. 22, 2023
- Modified: Jun. 25, 2025
-
7.8
HIGHCVE-2025-0289
Various Paragon Software products contain an insecure kernel resource access vulnerability facilitated by the driver not validating the MappedSystemVa pointer before passing it to HalReturnToFirmware, which can allows an attacker the ability to compromise... Read more
- Published: Mar. 03, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Authorization