Latest CVE Feed
-
5.5
MEDIUMCVE-2024-48828
Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized... Read more
Affected Products : smartfabric_os10- Published: Mar. 17, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2024-48017
Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged attacker with remote access could potenti... Read more
Affected Products : smartfabric_os10- Published: Mar. 17, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Injection
-
6.7
MEDIUMCVE-2024-48015
Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged attacker with local access could potentia... Read more
Affected Products : smartfabric_os10- Published: Mar. 17, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2386
A vulnerability was found in PHPGurukul Local Services Search Engine Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /serviceman-search.php. The manipulation of the argument location leads to sql in... Read more
- Published: Mar. 17, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2385
A vulnerability has been found in code-projects Modern Bag 1.0 and classified as critical. This vulnerability affects unknown code of the file /login.php. The manipulation of the argument userEmail/userPassword leads to sql injection. The attack can be in... Read more
Affected Products : modern_bag- Published: Mar. 17, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Injection
-
8.2
HIGHCVE-2025-2241
A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read acce... Read more
Affected Products :- Published: Mar. 17, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Information Disclosure
-
3.2
LOWCVE-2025-29431
Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/department.php via the id, code, and name parameters.... Read more
Affected Products : online_class_and_exam_scheduling_system- Published: Mar. 17, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-25685
An issue was discovered in GL-INet Beryl AX GL-MT3000 v4.7.0. Attackers are able to download arbitrary files from the device's file system via adding symbolic links on an external drive used as a samba share.... Read more
Affected Products :- Published: Mar. 17, 2025
- Modified: Mar. 21, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2025-25684
A lack of validation in the path parameter (/download) of GL-INet Beryl AX GL-MT3000 v4.7.0 allows attackers to download arbitrary files from the device's file system via a crafted POST request.... Read more
Affected Products :- Published: Mar. 17, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Path Traversal
-
6.8
MEDIUMCVE-2025-22474
Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) a Server-Side Request Forgery (SSRF) vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Server... Read more
Affected Products : smartfabric_os10- Published: Mar. 17, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Server-Side Request Forgery
-
7.8
HIGHCVE-2024-48830
Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access could potential... Read more
Affected Products : smartfabric_os10- Published: Mar. 17, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2024-48013
Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Execution with Unnecessary Privileges vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Ele... Read more
Affected Products : smartfabric_os10- Published: Mar. 17, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2025-30143
Rule 3000216 (before version 2) in Akamai App & API Protector (with Akamai ASE) before 2024-12-10 does not properly consider JavaScript variable assignment to built-in functions and properties.... Read more
Affected Products :- Published: Mar. 17, 2025
- Modified: Mar. 17, 2025
-
7.5
HIGHCVE-2025-2384
A vulnerability, which was classified as critical, was found in code-projects Real Estate Property Management System 1.0. This affects an unknown part of the file /InsertCustomer.php of the component Parameter Handler. The manipulation of the argument txt... Read more
Affected Products : real_estate_property_management_system- Published: Mar. 17, 2025
- Modified: Mar. 25, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2383
A vulnerability, which was classified as critical, has been found in PHPGurukul Doctor Appointment Management System 1.0. Affected by this issue is some unknown functionality of the file /doctor/search.php. The manipulation of the argument searchdata lead... Read more
- Published: Mar. 17, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2382
A vulnerability classified as critical was found in PHPGurukul Online Banquet Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/booking-search.php. The manipulation of the argument searchdata leads to sql in... Read more
Affected Products : online_banquet_booking_system- Published: Mar. 17, 2025
- Modified: May. 26, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2381
A vulnerability classified as critical has been found in PHPGurukul Curfew e-Pass Management System 1.0. Affected is an unknown function of the file /admin/search-pass.php. The manipulation of the argument searchdata leads to sql injection. It is possible... Read more
Affected Products : curfew_e-pass_management_system- Published: Mar. 17, 2025
- Modified: May. 06, 2025
- Vuln Type: Injection
-
2.1
LOWCVE-2025-27512
Zincati is an auto-update agent for Fedora CoreOS hosts. Zincati ships a polkit rule which allows the `zincati` system user to use the actions `org.projectatomic.rpmostree1.deploy` to deploy updates to the system and `org.projectatomic.rpmostree1.finalize... Read more
Affected Products :- Published: Mar. 17, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Authorization
-
5.0
MEDIUMCVE-2025-26127
A stored cross-site scripting (XSS) vulnerability in the Send for Approval function of FileCloud v23.241.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products :- Published: Mar. 17, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Cross-Site Scripting
-
9.1
CRITICALCVE-2025-25650
An issue in the storage of NFC card data in Dorset DG 201 Digital Lock H5_433WBSK_v2.2_220605 allows attackers to produce cloned NFC cards to bypass authentication.... Read more
Affected Products :- Published: Mar. 17, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Authentication