Latest CVE Feed
-
5.4
MEDIUMCVE-2025-5757
A vulnerability was found in code-projects Traffic Offense Reporting System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /save-reported.php. The manipulation of the argument offence_id/vehicle_no/... Read more
Affected Products : traffic_offense_reporting_system- Published: Jun. 06, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-5764
A vulnerability was found in code-projects Laundry System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /data/insert_laundry.php. The manipulation of the argument Customer leads to cross site scripting... Read more
- Published: Jun. 06, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-5765
A vulnerability was found in code-projects Laundry System 1.0. It has been classified as problematic. This affects an unknown part of the file /data/edit_laundry.php. The manipulation of the argument Customer leads to cross site scripting. It is possible ... Read more
- Published: Jun. 06, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2025-5766
A vulnerability was found in code-projects Laundry System 1.0. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been d... Read more
- Published: Jun. 06, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Cross-Site Request Forgery
-
9.8
CRITICALCVE-2025-41646
An unauthorized remote attacker can bypass the authentication of the affected software package by misusing an incorrect type conversion. This leads to full compromise of the device... Read more
Affected Products : revpi_status- Published: Jun. 06, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-5779
A vulnerability has been found in code-projects Patient Record Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /birthing.php. The manipulation of the argument itr_no/comp_id leads to... Read more
- Published: Jun. 06, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-5780
A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /view_dental.php. The manipulation of the argument itr_no leads to sql injection. ... Read more
- Published: Jun. 06, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-25830
F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An unauthenticated, remote attacker can exploit this, by sending a URI that contains the path of the configuration file. A successful exploit... Read more
- Published: Feb. 29, 2024
- Modified: Jun. 10, 2025
-
6.1
MEDIUMCVE-2024-27719
A cross site scripting (XSS) vulnerability in rems FAQ Management System v.1.0 allows a remote attacker to obtain sensitive information via a crafted payload to the Frequently Asked Question field in the Add FAQ function.... Read more
- Published: Mar. 28, 2024
- Modified: Jun. 10, 2025
-
8.3
HIGHCVE-2023-51761
In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could bypass authentication and acquire admin capabilities.... Read more
- Published: Feb. 09, 2024
- Modified: Jun. 10, 2025
-
9.1
CRITICALCVE-2023-43609
In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could obtain access to sensitive information or cause a denial-of-service condition.... Read more
- Published: Feb. 09, 2024
- Modified: Jun. 10, 2025
-
7.2
HIGHCVE-2024-48231
Funadmin 5.0.2 is vulnerable to SQL Injection via the selectFields parameter in the index method of \backend\controller\auth\Auth.php.... Read more
Affected Products : funadmin- Published: Oct. 21, 2024
- Modified: Jun. 10, 2025
-
5.5
MEDIUMCVE-2024-48424
A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp library, specifically during the processing of OpenGEX files.... Read more
Affected Products : assimp- Published: Oct. 24, 2024
- Modified: Jun. 10, 2025
-
5.5
MEDIUMCVE-2024-48425
A segmentation fault (SEGV) was detected in the Assimp::SplitLargeMeshesProcess_Triangle::UpdateNode function within the Assimp library during fuzz testing using AddressSanitizer. The crash occurs due to a read access violation at address 0x000000000460, ... Read more
Affected Products : assimp- Published: Oct. 24, 2024
- Modified: Jun. 10, 2025
-
6.1
MEDIUMCVE-2024-48228
An issue was found in funadmin 5.0.2. The selectfiles method in \backend\controller\sys\Attachh.php directly stores the passed parameters and values into the param parameter without filtering, resulting in Cross Site Scripting (XSS).... Read more
Affected Products : funadmin- Published: Oct. 25, 2024
- Modified: Jun. 10, 2025
-
8.1
HIGHCVE-2024-48178
newbee-mall v1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via the goodsCoverImg parameter.... Read more
Affected Products : newbee-mall- Published: Oct. 28, 2024
- Modified: Jun. 10, 2025
-
6.5
MEDIUMCVE-2024-33809
PingCAP TiDB v7.5.1 was discovered to contain a buffer overflow vulnerability, which could lead to database crashes and denial of service attacks.... Read more
Affected Products : tidb- Published: May. 24, 2024
- Modified: Jun. 10, 2025
-
5.5
MEDIUMCVE-2024-35110
A reflected XSS vulnerability has been found in YzmCMS 7.1. The vulnerability exists in yzmphp/core/class/application.class.php: when logged-in users access a malicious link, their cookies can be captured by an attacker.... Read more
Affected Products : yzmcms- Published: May. 17, 2024
- Modified: Jun. 10, 2025
-
8.8
HIGHCVE-2024-36528
nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before have a Deserialization vulnerability which results in code execution via /admin/extensions/download.php and /admin/extensions/upload.php.... Read more
Affected Products : nukeviet- Published: Jun. 10, 2024
- Modified: Jun. 10, 2025
-
5.7
MEDIUMCVE-2024-36531
nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before are vulnerable to arbitrary code execution via the /admin/extensions/upload.php component.... Read more
Affected Products : nukeviet- Published: Jun. 10, 2024
- Modified: Jun. 10, 2025