Latest CVE Feed
-
7.2
HIGHCVE-2025-6007
A vulnerability, which was classified as critical, was found in kiCode111 like-girl 5.2.0. Affected is an unknown function of the file /admin/CopyadminPost.php. The manipulation of the argument icp/Copyright leads to sql injection. It is possible to launc... Read more
Affected Products : like-girl- Published: Jun. 12, 2025
- Modified: Jun. 19, 2025
- Vuln Type: Injection
-
7.2
HIGHCVE-2025-6008
A vulnerability has been found in kiCode111 like-girl 5.2.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/ImgAddPost.php. The manipulation of the argument imgDatd/imgText/imgUrl leads to sql inje... Read more
Affected Products : like-girl- Published: Jun. 12, 2025
- Modified: Jun. 19, 2025
- Vuln Type: Injection
-
7.2
HIGHCVE-2025-6009
A vulnerability was found in kiCode111 like-girl 5.2.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/ipAddPost.php. The manipulation of the argument bz/ipdz leads to sql injection. The attack may be la... Read more
Affected Products : like-girl- Published: Jun. 12, 2025
- Modified: Jun. 19, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2025-44906
jhead v3.08 was discovered to contain a heap-use-after-free via the ProcessFile function at jhead.c.... Read more
Affected Products : jhead- Published: May. 30, 2025
- Modified: Jun. 19, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2025-48887
vLLM, an inference and serving engine for large language models (LLMs), has a Regular Expression Denial of Service (ReDoS) vulnerability in the file `vllm/entrypoints/openai/tool_parsers/pythonic_tool_parser.py` of versions 0.6.4 up to but excluding 0.9.0... Read more
Affected Products : vllm- Published: May. 30, 2025
- Modified: Jun. 19, 2025
- Vuln Type: Denial of Service
-
7.3
HIGHCVE-2025-45474
maccms10 v2025.1000.4047 is vulnerable to Server-side request forgery (SSRF) in Email Settings.... Read more
Affected Products : maccms- Published: May. 29, 2025
- Modified: Jun. 19, 2025
- Vuln Type: Server-Side Request Forgery
-
6.3
MEDIUMCVE-2025-5136
A vulnerability, which was classified as problematic, was found in Tmall Demo up to 20250505. This affects an unknown part of the file /tmall/order/pay/ of the component Payment Identifier Handler. The manipulation leads to insufficiently random values. I... Read more
Affected Products : tmall_demo- Published: May. 25, 2025
- Modified: Jun. 19, 2025
- Vuln Type: Cryptography
-
6.3
MEDIUMCVE-2025-32790
Dify is an open-source LLM app development platform. In versions 0.6.8 and prior, a vulnerability was identified in the DIFY AI where normal users are improperly granted permissions to export APP DSL. The feature in '/export' should only allow administrat... Read more
Affected Products : dify- Published: Apr. 18, 2025
- Modified: Jun. 19, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-32795
Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY where normal users are improperly granted permissions to edit APP names, descriptions and icons. This access control flaw allows non-a... Read more
Affected Products : dify- Published: Apr. 18, 2025
- Modified: Jun. 19, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-29058
An issue in Qimou CMS v.3.34.0 allows a remote attacker to execute arbitrary code via the upgrade.php component.... Read more
Affected Products : qimou_cms- Published: Apr. 18, 2025
- Modified: Jun. 19, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-29339
An issue in UPF in Open5GS UPF versions up to v2.7.2 results an assertion failure vulnerability in PFCP session parameter validation. When processing a PFCP Session Establishment Request with PDN Type=0, the UPF fails to handle the invalid value propagate... Read more
Affected Products : open5gs- Published: Apr. 22, 2025
- Modified: Jun. 19, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2023-44755
Sacco Management system v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /sacco/ajax.php.... Read more
Affected Products : sacco_management_system- Published: Apr. 22, 2025
- Modified: Jun. 19, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-25580
yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the listNameBySql() method at /xml/UserMapper.xml.... Read more
Affected Products : yimioa- Published: Mar. 18, 2025
- Modified: Jun. 19, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-25590
yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the component /mapper/xml/AddressDao.xml.... Read more
Affected Products : yimioa- Published: Mar. 18, 2025
- Modified: Jun. 19, 2025
- Vuln Type: Injection
-
7.3
HIGHCVE-2025-25585
Incorrect access control in the component /config/WebSecurityConfig.java of yimioa before v2024.07.04 allows unauthorized attackers to arbitrarily modify Administrator passwords.... Read more
Affected Products : yimioa- Published: Mar. 18, 2025
- Modified: Jun. 19, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-27913
Passbolt API before 5, if the server is misconfigured (with an incorrect installation process and disregarding of Health Check results), can send email messages with a domain name taken from an attacker-controlled HTTP Host header.... Read more
Affected Products : passbolt_api- Published: Mar. 10, 2025
- Modified: Jun. 19, 2025
- Vuln Type: Misconfiguration
-
5.3
MEDIUMCVE-2023-43052
IBM Control Center 6.2.1 through 6.3.1 is vulnerable to an external service interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-side DNS l... Read more
Affected Products : control_center- Published: Mar. 07, 2025
- Modified: Jun. 19, 2025
- Vuln Type: Server-Side Request Forgery
-
5.3
MEDIUMCVE-2025-47748
Netwrix Directory Manager v.11.0.0.0 and before & after v.11.1.25134.03 contains a hardcoded password.... Read more
Affected Products : directory_manager- Published: May. 28, 2025
- Modified: Jun. 19, 2025
- Vuln Type: Cryptography
-
5.0
MEDIUMCVE-2025-48747
Netwrix Directory Manager (formerly Imanami GroupID) before and including v.11.0.0.0 and after v.11.1.25134.03 has Incorrect Permission Assignment for a Critical Resource.... Read more
Affected Products : directory_manager- Published: May. 28, 2025
- Modified: Jun. 19, 2025
- Vuln Type: Authorization
-
9.1
CRITICALCVE-2025-48749
Netwrix Directory Manager (formerly Imanami GroupID) v11.0.0.0 and before & after v.11.1.25134.03 inserts Sensitive Information into Sent Data.... Read more
Affected Products : directory_manager- Published: May. 28, 2025
- Modified: Jun. 18, 2025
- Vuln Type: Information Disclosure