Latest CVE Feed
-
4.8
MEDIUMCVE-2024-11847
The wp-svg-upload WordPress plugin through 1.0.0 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.... Read more
Affected Products : _wp_svg_upload- Published: Mar. 26, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-5729
A vulnerability, which was classified as critical, was found in code-projects Health Center Patient Record Management System 1.0. Affected is an unknown function of the file /birthing_record.php. The manipulation of the argument itr_no leads to sql inject... Read more
Affected Products : patient_record_management_system- Published: Jun. 06, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5881
A vulnerability was found in code-projects Chat System up to 1.0 and classified as critical. This issue affects some unknown processing of the file /user/confirm_password.php. The manipulation of the argument cid leads to sql injection. The attack may be ... Read more
- Published: Jun. 09, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2025-45055
Silverpeas 6.4.2 contains a stored cross-site scripting (XSS) vulnerability in the event management module. An authenticated user can upload a malicious SVG file as an event attachment, which, when viewed by an administrator, executes embedded JavaScript ... Read more
Affected Products : silverpeas- Published: Jun. 09, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2024-3566
A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.... Read more
- Published: Apr. 10, 2024
- Modified: Jun. 25, 2025
-
9.8
CRITICALCVE-2025-6420
A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/add_room.php. The manipulation of the argument room_type leads to sql injec... Read more
- Published: Jun. 21, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6419
A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/edit_room.php. The manipulation of the argument room_type leads to sql injection. It... Read more
- Published: Jun. 21, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Injection
-
9.0
HIGHCVE-2025-6402
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been declared as critical. This vulnerability affects unknown code of the file /boafrm/formIpv6Setup of the component HTTP POST Request Handler. The manipulation of the argument submit... Read more
- Published: Jun. 21, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Memory Corruption
-
5.1
MEDIUMCVE-2025-6401
A vulnerability was found in TOTOLINK N300RH 6.1c.1390_B20191101. It has been classified as problematic. This affects an unknown part of the file /boafrm/formFilter of the component HTTP POST Message Handler. The manipulation of the argument url leads to ... Read more
- Published: Jun. 21, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Denial of Service
-
9.0
HIGHCVE-2025-6400
A vulnerability was found in TOTOLINK N300RH 6.1c.1390_B20191101 and classified as critical. Affected by this issue is some unknown functionality of the file /boafrm/formPortFw of the component HTTP POST Message Handler. The manipulation of the argument s... Read more
- Published: Jun. 21, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-6399
A vulnerability, which was classified as critical, was found in TOTOLINK X15 1.0.0-B20230714.1105. Affected is an unknown function of the file /boafrm/formIPv6Addr of the component HTTP POST Request Handler. The manipulation of the argument submit-url lea... Read more
- Published: Jun. 21, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-6394
A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /add_reserve.php. The manipulation of the argument firstname le... Read more
- Published: Jun. 21, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Injection
-
9.0
HIGHCVE-2025-6374
A vulnerability was found in D-Link DIR-619L 2.06B01 and classified as critical. This issue affects the function formSetACLFilter of the file /goform/formSetACLFilter. The manipulation of the argument curTime leads to stack-based buffer overflow. The atta... Read more
- Published: Jun. 21, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-6373
A vulnerability has been found in D-Link DIR-619L 2.06B01 and classified as critical. This vulnerability affects the function formSetWizard1 of the file /goform/formWlSiteSurvey. The manipulation of the argument curTime leads to stack-based buffer overflo... Read more
- Published: Jun. 21, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-6372
A vulnerability, which was classified as critical, was found in D-Link DIR-619L 2.06B01. This affects the function formSetWizard1 of the file /goform/formSetWizard1. The manipulation of the argument curTime leads to stack-based buffer overflow. It is poss... Read more
- Published: Jun. 20, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-6371
A vulnerability, which was classified as critical, has been found in D-Link DIR-619L 2.06B01. Affected by this issue is the function formSetEnableWizard of the file /goform/formSetEnableWizard. The manipulation of the argument curTime leads to stack-based... Read more
- Published: Jun. 20, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-6370
A vulnerability classified as critical was found in D-Link DIR-619L 2.06B01. Affected by this vulnerability is the function formWlanGuestSetup of the file /goform/formWlanGuestSetup. The manipulation of the argument curTime leads to stack-based buffer ove... Read more
- Published: Jun. 20, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-6369
A vulnerability classified as critical has been found in D-Link DIR-619L 2.06B01. Affected is the function formdumpeasysetup of the file /goform/formdumpeasysetup. The manipulation of the argument curTime/config.save_network_enabled leads to stack-based b... Read more
- Published: Jun. 20, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-6368
A vulnerability was found in D-Link DIR-619L 2.06B01. It has been rated as critical. This issue affects the function formSetEmail of the file /goform/formSetEmail. The manipulation of the argument curTime/config.smtp_email_subject leads to stack-based buf... Read more
- Published: Jun. 20, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-6367
A vulnerability was found in D-Link DIR-619L 2.06B01. It has been declared as critical. This vulnerability affects unknown code of the file /goform/formSetDomainFilter. The manipulation of the argument curTime/sched_name_%d/url_%d leads to stack-based buf... Read more
- Published: Jun. 20, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Memory Corruption