Latest CVE Feed
-
8.8
HIGHCVE-2025-8500
A vulnerability was found in code-projects Human Resource Integrated System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /insert-and-view/action.php. The manipulation of the argument content leads to sql injec... Read more
- Published: Aug. 03, 2025
- Modified: Aug. 05, 2025
-
9.8
CRITICALCVE-2025-8499
A vulnerability was found in code-projects Online Medicine Guide 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /cusfindambulence2.php. The manipulation of the argument Search leads to sql injection. The attack ... Read more
Affected Products : online_medicine_guide- Published: Aug. 03, 2025
- Modified: Aug. 05, 2025
-
9.8
CRITICALCVE-2025-8498
A vulnerability was found in code-projects Online Medicine Guide 1.0. It has been classified as critical. This affects an unknown part of the file /cart/index.php. The manipulation of the argument uname leads to sql injection. It is possible to initiate t... Read more
Affected Products : online_medicine_guide- Published: Aug. 03, 2025
- Modified: Aug. 05, 2025
-
9.8
CRITICALCVE-2025-8497
A vulnerability was found in code-projects Online Medicine Guide 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /cusfindphar2.php. The manipulation of the argument Search leads to sql injection. The attack... Read more
Affected Products : online_medicine_guide- Published: Aug. 03, 2025
- Modified: Aug. 05, 2025
-
9.8
CRITICALCVE-2025-8496
A vulnerability has been found in projectworlds Online Admission System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /viewform.php. The manipulation of the argument ID leads to sql injection. The a... Read more
Affected Products : online_admission_system- Published: Aug. 03, 2025
- Modified: Aug. 08, 2025
-
6.4
MEDIUMCVE-2025-52133
The Mocca Calendar application before 2.15 for XWiki allows XSS via a title upon calendar import.... Read more
Affected Products :- Published: Aug. 03, 2025
- Modified: Aug. 04, 2025
-
6.4
MEDIUMCVE-2025-52132
The Mocca Calendar application before 2.15 for XWiki allows XSS via a title to the view event page.... Read more
Affected Products :- Published: Aug. 03, 2025
- Modified: Aug. 04, 2025
-
6.4
MEDIUMCVE-2025-52131
The Mocca Calendar application before 2.15 for XWiki allows XSS via the background or text color field.... Read more
Affected Products :- Published: Aug. 03, 2025
- Modified: Aug. 04, 2025
-
9.8
CRITICALCVE-2025-8495
A vulnerability, which was classified as critical, was found in code-projects Intern Membership Management System 1.0. Affected is an unknown function of the file /admin/edit_admin_query.php. The manipulation of the argument Username leads to sql injectio... Read more
Affected Products : intern_membership_management_system- Published: Aug. 03, 2025
- Modified: Aug. 08, 2025
-
10.0
CRITICALCVE-2025-54351
In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).... Read more
- Published: Aug. 03, 2025
- Modified: Aug. 05, 2025
-
5.3
MEDIUMCVE-2025-54350
In iperf before 3.19.1, iperf_auth.c has a Base64Decode assertion failure and application exit upon a malformed authentication attempt.... Read more
- Published: Aug. 03, 2025
- Modified: Aug. 05, 2025
-
10.0
CRITICALCVE-2025-54349
In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow.... Read more
- Published: Aug. 03, 2025
- Modified: Aug. 05, 2025
-
9.8
CRITICALCVE-2025-8494
A vulnerability, which was classified as critical, has been found in code-projects Intern Membership Management System 1.0. This issue affects some unknown processing of the file /admin/delete_student.php. The manipulation of the argument ID leads to sql ... Read more
- Published: Aug. 03, 2025
- Modified: Aug. 05, 2025
-
8.1
HIGHCVE-2025-54955
OpenNebula Community Edition (CE) before 7.0.0 and Enterprise Edition (EE) before 6.10.3 have a critical FireEdge race condition that can lead to full account takeover. By exploiting this, an unauthenticated attacker can obtain a valid JSON Web Token (JWT... Read more
Affected Products : opennebula- Published: Aug. 03, 2025
- Modified: Aug. 04, 2025
-
9.8
CRITICALCVE-2025-8493
A vulnerability classified as critical was found in code-projects Intern Membership Management System 1.0. This vulnerability affects unknown code of the file /admin/edit_student_query.php. The manipulation of the argument ID leads to sql injection. The a... Read more
- Published: Aug. 02, 2025
- Modified: Aug. 05, 2025
-
2.5
LOWCVE-2025-23290
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a guest could get global GPU metrics which may be influenced by work in other VMs. A successful exploit of this vulnerability might lead to information disclosure.... Read more
Affected Products :- Published: Aug. 02, 2025
- Modified: Aug. 04, 2025
-
5.5
MEDIUMCVE-2025-23285
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where it allows a guest to access global resources. A successful exploit of this vulnerability might lead to denial of service.... Read more
Affected Products :- Published: Aug. 02, 2025
- Modified: Aug. 04, 2025
-
7.8
HIGHCVE-2025-23284
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause a stack buffer overflow. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, or d... Read more
Affected Products :- Published: Aug. 02, 2025
- Modified: Aug. 04, 2025
-
5.3
MEDIUMCVE-2023-32255
A flaw was found in the Linux kernel's ksmbd component. A memory leak can occur if a client sends a session setup request with an unknown NTLMSSP message type, potentially leading to resource exhaustion.... Read more
Affected Products : linux_kernel- Published: Aug. 02, 2025
- Modified: Aug. 04, 2025
-
5.9
MEDIUMCVE-2023-32253
A flaw was found in the Linux kernel's ksmbd component. A deadlock is triggered by sending multiple concurrent session setup requests, possibly leading to a denial of service.... Read more
Affected Products : linux_kernel- Published: Aug. 02, 2025
- Modified: Aug. 04, 2025