Latest CVE Feed
-
4.8
MEDIUMCVE-2025-5542
A vulnerability was found in TOTOLINK X2000R 1.0.0-B20230726.1108. It has been classified as problematic. Affected is an unknown function of the file /boafrm/formPortFw of the component Virtual Server Page. The manipulation of the argument service_type le... Read more
- Published: Jun. 03, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Cross-Site Scripting
-
9.1
CRITICALCVE-2025-23097
An issue was discovered in Samsung Mobile Processor Exynos 1380. The lack of a length check leads to out-of-bounds writes.... Read more
- Published: Jun. 03, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-23100
An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400. The absence of a NULL check leads to a Denial of Service.... Read more
- Published: Jun. 03, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Denial of Service
-
7.8
HIGHCVE-2025-23098
An issue was discovered in Samsung Mobile Processor Exynos 980, 990, 1080, 2100, 1280, 2200, 1380. A Use-After-Free in the mobile processor leads to privilege escalation.... Read more
Affected Products : exynos_980_firmware exynos_1080_firmware exynos_2100_firmware exynos_2200_firmware exynos_1280_firmware exynos_1380_firmware exynos_980 exynos_990_firmware exynos_990 exynos_1080 +4 more products- Published: Jun. 03, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-5663
A vulnerability has been found in PHPGurukul Auto Taxi Stand Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/search-autoortaxi.php. The manipulation of the argument searchdata leads to sql injec... Read more
Affected Products : auto\/taxi_stand_management_system- Published: Jun. 05, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-5660
A vulnerability, which was classified as critical, has been found in PHPGurukul Complaint Management System 2.0. Affected by this issue is some unknown functionality of the file /user/register-complaint.php. The manipulation of the argument noc leads to s... Read more
Affected Products : complaint_management_system- Published: Jun. 05, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-5659
A vulnerability classified as critical was found in PHPGurukul Complaint Management System 2.0. Affected by this vulnerability is an unknown functionality of the file /user/profile.php. The manipulation of the argument pincode leads to sql injection. The ... Read more
Affected Products : complaint_management_system- Published: Jun. 05, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-5652
A vulnerability, which was classified as critical, was found in PHPGurukul Complaint Management System 2.0. Affected is an unknown function of the file /admin/between-date-complaintreport.php. The manipulation of the argument fromdate/todate leads to sql ... Read more
Affected Products : complaint_management_system- Published: Jun. 05, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-22533
Before Beetl v3.15.12, the rendering template has a server-side template injection (SSTI) vulnerability. When the incoming template is controllable, it will be filtered by the DefaultNativeSecurityManager blacklist. Because blacklist filtering is not stri... Read more
Affected Products : beetl- Published: Feb. 02, 2024
- Modified: Jun. 06, 2025
-
9.8
CRITICALCVE-2023-51955
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formSetIptv.... Read more
- Published: Jan. 10, 2024
- Modified: Jun. 06, 2025
-
8.8
HIGHCVE-2023-48909
An issue was discovered in Jave2 version 3.3.1, allows attackers to execute arbitrary code via the FFmpeg function.... Read more
Affected Products : jave2- Published: Jan. 12, 2024
- Modified: Jun. 06, 2025
-
6.4
MEDIUMCVE-2022-41545
The administrative web interface of a Netgear C7800 Router running firmware version 6.01.07 (and possibly others) authenticates users via basic authentication, with an HTTP header containing a base64 value of the plaintext username and password. Because t... Read more
- Published: Feb. 18, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-57049
A vulnerability in the TP-Link Archer c20 router with firmware version V6.6_230412 and earlier permits unauthorized individuals to bypass the authentication of some interfaces under the /cgi directory. When adding Referer: http://tplinkwifi.net to the the... Read more
- Published: Feb. 18, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2025-26773
Missing Authorization vulnerability in Adnan Analytify allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Analytify: from n/a through 5.5.0.... Read more
Affected Products : analytify_-_google_analytics_dashboard- Published: Feb. 17, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Authorization
-
5.6
MEDIUMCVE-2025-26158
A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the manage-employee.php page of Kashipara Online Attendance Management System V1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the department parameter.... Read more
Affected Products : online_attendance_management_system- Published: Feb. 14, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Cross-Site Scripting
-
5.9
MEDIUMCVE-2025-26157
A SQL Injection vulnerability was found in /bpms/index.php in Source Code and Project Beauty Parlour Management System V1.1, which allows remote attackers to execute arbitrary code via the name POST request parameter.... Read more
Affected Products : beauty_parlour_management_system- Published: Feb. 14, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-57604
An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the token component.... Read more
Affected Products : ezbookkeeping- Published: Feb. 12, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Authorization
-
6.3
MEDIUMCVE-2024-57603
An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the lack of rate limiting.... Read more
Affected Products : ezbookkeeping- Published: Feb. 12, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Authentication
-
4.8
MEDIUMCVE-2025-5516
A vulnerability, which was classified as problematic, was found in TOTOLINK X2000R 1.0.0-B20230726.1108. This affects an unknown part of the file /boafrm/formFilter of the component URL Filtering Page. The manipulation of the argument URL Address leads to... Read more
- Published: Jun. 03, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-5502
A vulnerability, which was classified as critical, has been found in TOTOLINK X15 1.0.0-B20230714.1105. Affected by this issue is the function formMapReboot of the file /boafrm/formMapReboot. The manipulation of the argument deviceMacAddr leads to command... Read more
- Published: Jun. 03, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Injection