Latest CVE Feed
-
3.1
CVSS31CVE-2025-6107
A vulnerability was found in comfyanonymous comfyui 0.3.40. It has been classified as problematic. Affected is the function set_attr of the file /comfy/utils.py. The manipulation leads to dynamically-determined object attributes. It is possible to launch ... Read more
Affected Products :- Published: Jun. 16, 2025
- Modified: Jun. 16, 2025
-
4.3
CVSS31CVE-2025-6106
A vulnerability was found in WuKongOpenSource WukongCRM 9.0 and classified as problematic. This issue affects some unknown processing of the file AdminRoleController.java. The manipulation leads to cross-site request forgery. The attack may be initiated r... Read more
Affected Products :- Published: Jun. 16, 2025
- Modified: Jun. 16, 2025
-
4.3
CVSS31CVE-2025-6105
A vulnerability has been found in jflyfox jfinal_cms 5.0.1 and classified as problematic. This vulnerability affects unknown code of the file HOME.java. The manipulation of the argument Logout leads to cross-site request forgery. The attack can be initiat... Read more
Affected Products :- Published: Jun. 16, 2025
- Modified: Jun. 16, 2025
-
8.8
CVSS31CVE-2025-6104
A vulnerability, which was classified as critical, was found in Wifi-soft UniBox Controller up to 20250506. This affects an unknown part of the file /billing/pms_check.php. The manipulation of the argument ipaddress leads to os command injection. It is po... Read more
Affected Products :- Published: Jun. 16, 2025
- Modified: Jun. 16, 2025
-
8.8
CVSS31CVE-2025-6103
A vulnerability, which was classified as critical, has been found in Wifi-soft UniBox Controller up to 20250506. Affected by this issue is some unknown functionality of the file /billing/test_accesscodelogin.php. The manipulation of the argument Password ... Read more
Affected Products :- Published: Jun. 16, 2025
- Modified: Jun. 16, 2025
-
8.8
CVSS31CVE-2025-6102
A vulnerability classified as critical was found in Wifi-soft UniBox Controller up to 20250506. Affected by this vulnerability is an unknown functionality of the file /authentication/logout.php. The manipulation of the argument mac_address leads to os com... Read more
Affected Products :- Published: Jun. 16, 2025
- Modified: Jun. 16, 2025
-
5.5
CVSS31CVE-2025-6101
A vulnerability classified as critical has been found in letta-ai letta up to 0.4.1. Affected is the function function_message of the file letta/letta/interface.py. The manipulation of the argument function_name/function_args leads to improper neutralizat... Read more
Affected Products :- Published: Jun. 16, 2025
- Modified: Jun. 16, 2025
-
6.3
CVSS31CVE-2025-6100
A vulnerability was found in realguoshuai open-video-cms 1.0. It has been rated as critical. This issue affects some unknown processing of the file /v1/video/list. The manipulation of the argument sort leads to sql injection. The attack may be initiated r... Read more
Affected Products :- Published: Jun. 16, 2025
- Modified: Jun. 16, 2025
-
5.3
CVSS31CVE-2025-6099
A vulnerability was found in szluyu99 gin-vue-blog up to 61dd11ccd296e8642a318ada3ef7b3f7776d2410. It has been declared as critical. This vulnerability affects unknown code of the file gin-blog-server/internal/manager.go of the component PATCH Request Han... Read more
Affected Products :- Published: Jun. 16, 2025
- Modified: Jun. 16, 2025
-
9.8
CVSS31CVE-2025-6098
A vulnerability was found in UTT 进取 750W up to 5.0. It has been classified as critical. This affects the function strcpy of the file /goform/setSysAdm of the component API. The manipulation of the argument passwd1 leads to buffer overflow. It is possible ... Read more
Affected Products :- Published: Jun. 16, 2025
- Modified: Jun. 16, 2025
-
5.3
CVSS31CVE-2025-6097
A vulnerability was found in UTT 进取 750W up to 5.0 and classified as critical. Affected by this issue is the function formDefineManagement of the file /goform/setSysAdm of the component Administrator Password Handler. The manipulation of the argument pass... Read more
Affected Products :- Published: Jun. 16, 2025
- Modified: Jun. 16, 2025
-
6.3
CVSS31CVE-2025-6096
A vulnerability has been found in codesiddhant Jasmin Ransomware up to 1.0.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /dashboard.php. The manipulation of the argument Search leads to sql injection.... Read more
Affected Products :- Published: Jun. 16, 2025
- Modified: Jun. 16, 2025
-
7.3
CVSS31CVE-2025-6095
A vulnerability, which was classified as critical, was found in codesiddhant Jasmin Ransomware 1.0.1. Affected is an unknown function of the file /checklogin.php. The manipulation of the argument username/password leads to sql injection. It is possible to... Read more
Affected Products :- Published: Jun. 15, 2025
- Modified: Jun. 15, 2025
-
6.3
CVSS31CVE-2025-6094
A vulnerability, which was classified as critical, has been found in FoxCMS up to 1.2.5. This issue affects the function batchCope of the file app/admin/controller/Download.php. The manipulation of the argument ids leads to sql injection. The attack may b... Read more
Affected Products :- Published: Jun. 15, 2025
- Modified: Jun. 15, 2025
-
5.5
CVSS31CVE-2025-6093
A vulnerability classified as critical was found in uYanki board-stm32f103rc-berial up to 84daed541609cb7b46854cc6672a275d1007e295. This vulnerability affects the function heartrate1_i2c_hal_write of the file 7.Example/hal/i2c/max30100/Manual/demo2/2/hear... Read more
Affected Products :- Published: Jun. 15, 2025
- Modified: Jun. 15, 2025
-
0.0
NONECVE-2025-5964
A path traversal issue in the API endpoint in M-Files Server before version 25.6.14925.0 allows an authenticated user to read files in the server.... Read more
Affected Products :- Published: Jun. 15, 2025
- Modified: Jun. 15, 2025
-
4.3
CVSS31CVE-2025-6092
A vulnerability was found in comfyanonymous comfyui up to 0.3.39. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /upload/image of the component Incomplete Fix CVE-2024-10099. The manipulation of... Read more
Affected Products :- Published: Jun. 15, 2025
- Modified: Jun. 15, 2025
-
7.6
CVSS31CVE-2025-5990
An input neutralization vulnerability in the Server Name form and API Key form components of Crafty Controller allows a remote, authenticated attacker to perform stored XSS via malicious form input.... Read more
Affected Products :- Published: Jun. 15, 2025
- Modified: Jun. 15, 2025
-
8.8
CVSS31CVE-2025-6091
A vulnerability was found in H3C GR-3000AX V100R007L50. It has been classified as critical. Affected is the function UpdateWanParamsMulti/UpdateIpv6Params of the file /routing/goform/aspForm. The manipulation of the argument param leads to buffer overflow... Read more
Affected Products :- Published: Jun. 15, 2025
- Modified: Jun. 15, 2025
-
0.0
NONECVE-2024-25573
Unsanitized user-supplied data saved in the PingFederate Administrative Console could trigger the execution of JavaScript code in subsequent user processing.... Read more
Affected Products : pingfederate- Published: Jun. 15, 2025
- Modified: Jun. 15, 2025