Latest CVE Feed
-
9.8
CRITICALCVE-2025-8250
A vulnerability, which was classified as critical, was found in code-projects Exam Form Submission 1.0. Affected is an unknown function of the file /admin/update_s4.php. The manipulation of the argument credits leads to sql injection. It is possible to la... Read more
Affected Products : exam_form_submission- Published: Jul. 28, 2025
- Modified: Jul. 30, 2025
-
9.8
CRITICALCVE-2025-8249
A vulnerability, which was classified as critical, has been found in code-projects Exam Form Submission 1.0. This issue affects some unknown processing of the file /admin/update_s3.php. The manipulation of the argument credits leads to sql injection. The ... Read more
Affected Products : exam_form_submission- Published: Jul. 28, 2025
- Modified: Jul. 30, 2025
-
9.8
CRITICALCVE-2025-8248
A vulnerability classified as critical was found in code-projects Online Ordering System 1.0. This vulnerability affects unknown code of the file /signup.php. The manipulation of the argument firstname leads to sql injection. The attack can be initiated r... Read more
- Published: Jul. 28, 2025
- Modified: Aug. 05, 2025
-
4.1
MEDIUMCVE-2023-53158
The gix-transport crate before 0.36.1 for Rust allows command execution via the "gix clone 'ssh://-oProxyCommand=open$IFS" substring. NOTE: this was discovered before CVE-2024-32884, a similar vulnerability (involving a username field) that is more diffic... Read more
Affected Products :- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
-
8.8
HIGHCVE-2025-8247
A vulnerability classified as critical has been found in Projectworlds Online Admission System 1.0. This affects an unknown part of the file /admin.php. The manipulation of the argument markof leads to sql injection. It is possible to initiate the attack ... Read more
Affected Products : online_admission_system- Published: Jul. 28, 2025
- Modified: Aug. 06, 2025
-
7.5
HIGHCVE-2023-53157
The rosenpass crate before 0.2.1 for Rust allows remote attackers to cause a denial of service (panic) via a one-byte UDP packet.... Read more
Affected Products : rosenpass- Published: Jul. 28, 2025
- Modified: Aug. 07, 2025
-
9.0
HIGHCVE-2025-8246
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been rated as critical. Affected by this issue is some unknown functionality of the file /boafrm/formRoute of the component HTTP POST Request Handler. The manipulation of the argument ... Read more
- Published: Jul. 27, 2025
- Modified: Jul. 29, 2025
-
9.0
HIGHCVE-2025-8245
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formMultiAPVLAN of the component HTTP POST Request Handler. The manipulation o... Read more
- Published: Jul. 27, 2025
- Modified: Jul. 29, 2025
-
9.8
CRITICALCVE-2025-8244
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been classified as critical. Affected is an unknown function of the file /boafrm/formMapDelDevice of the component HTTP POST Request Handler. The manipulation of the argument macstr le... Read more
- Published: Jul. 27, 2025
- Modified: Jul. 29, 2025
-
9.0
HIGHCVE-2025-8243
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105 and classified as critical. This issue affects some unknown processing of the file /boafrm/formMapDel of the component HTTP POST Request Handler. The manipulation of the argument devicemac1 le... Read more
- Published: Jul. 27, 2025
- Modified: Jul. 29, 2025
-
9.8
CRITICALCVE-2024-58266
The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection.... Read more
Affected Products : shlex- Published: Jul. 27, 2025
- Modified: Aug. 07, 2025
-
4.3
MEDIUMCVE-2024-58265
The snow crate before 0.9.5 for Rust, when stateful TransportState is used, allows incrementing a nonce and thereby denying message delivery.... Read more
Affected Products : snow- Published: Jul. 27, 2025
- Modified: Aug. 07, 2025
-
9.0
HIGHCVE-2025-8242
A vulnerability has been found in TOTOLINK X15 1.0.0-B20230714.1105 and classified as critical. This vulnerability affects unknown code of the file /boafrm/formFilter of the component HTTP POST Request Handler. The manipulation of the argument ip6addr/url... Read more
- Published: Jul. 27, 2025
- Modified: Jul. 29, 2025
-
9.8
CRITICALCVE-2025-8241
A vulnerability, which was classified as critical, was found in 1000 Projects ABC Courier Management System 1.0. This affects an unknown part of the file /report.php. The manipulation of the argument From leads to sql injection. It is possible to initiate... Read more
Affected Products : abc_courier_management_system- Published: Jul. 27, 2025
- Modified: Aug. 06, 2025
-
7.5
HIGHCVE-2024-58264
The serde-json-wasm crate before 1.0.1 for Rust allows stack consumption via deeply nested JSON data.... Read more
Affected Products : serde-json-wasm- Published: Jul. 27, 2025
- Modified: Aug. 06, 2025
-
5.3
MEDIUMCVE-2023-53156
The transpose crate before 0.2.3 for Rust allows an integer overflow via input_width and input_height arguments.... Read more
Affected Products : transpose- Published: Jul. 27, 2025
- Modified: Aug. 07, 2025
-
9.8
CRITICALCVE-2025-8240
A vulnerability, which was classified as critical, has been found in code-projects Exam Form Submission 1.0. Affected by this issue is some unknown functionality of the file /user/dashboard.php. The manipulation of the argument phone leads to sql injectio... Read more
Affected Products : exam_form_submission- Published: Jul. 27, 2025
- Modified: Aug. 05, 2025
-
5.3
MEDIUMCVE-2024-58263
The cosmwasm-std crate before 2.0.2 for Rust allows integer overflows that cause incorrect contract calculations.... Read more
Affected Products : cosmwasm-std- Published: Jul. 27, 2025
- Modified: Aug. 07, 2025
-
5.1
MEDIUMCVE-2024-58262
The curve25519-dalek crate before 4.1.3 for Rust has a constant-time operation on elliptic curve scalars that is removed by LLVM.... Read more
Affected Products : curve25519-dalek- Published: Jul. 27, 2025
- Modified: Aug. 07, 2025
-
7.5
HIGHCVE-2024-58261
The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupported primary key type.... Read more
Affected Products : sequoia-openpgp- Published: Jul. 27, 2025
- Modified: Aug. 06, 2025