Latest CVE Feed
-
5.3
MEDIUMCVE-2023-53161
The buffered-reader crate before 1.1.5 for Rust allows out-of-bounds array access and a panic.... Read more
Affected Products : buffered-reader- Published: Jul. 28, 2025
- Modified: Aug. 06, 2025
-
5.3
MEDIUMCVE-2023-53160
The sequoia-openpgp crate before 1.16.0 for Rust allows out-of-bounds array access and a panic.... Read more
Affected Products : sequoia-openpgp- Published: Jul. 28, 2025
- Modified: Aug. 06, 2025
-
9.1
CRITICALCVE-2023-53159
The openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_host.... Read more
- Published: Jul. 28, 2025
- Modified: Aug. 07, 2025
-
9.8
CRITICALCVE-2025-8251
A vulnerability has been found in code-projects Exam Form Submission 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/delete_s4.php. The manipulation of the argument ID leads to sql injection. T... Read more
Affected Products : exam_form_submission- Published: Jul. 28, 2025
- Modified: Jul. 30, 2025
-
5.9
MEDIUMCVE-2022-50237
The ed25519-dalek crate before 2 for Rust allows a double public key signing function oracle attack. The Keypair implementation leads to a simple computation for extracting a private key.... Read more
Affected Products :- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
-
9.8
CRITICALCVE-2025-8250
A vulnerability, which was classified as critical, was found in code-projects Exam Form Submission 1.0. Affected is an unknown function of the file /admin/update_s4.php. The manipulation of the argument credits leads to sql injection. It is possible to la... Read more
Affected Products : exam_form_submission- Published: Jul. 28, 2025
- Modified: Jul. 30, 2025
-
9.8
CRITICALCVE-2025-8249
A vulnerability, which was classified as critical, has been found in code-projects Exam Form Submission 1.0. This issue affects some unknown processing of the file /admin/update_s3.php. The manipulation of the argument credits leads to sql injection. The ... Read more
Affected Products : exam_form_submission- Published: Jul. 28, 2025
- Modified: Jul. 30, 2025
-
9.8
CRITICALCVE-2025-8248
A vulnerability classified as critical was found in code-projects Online Ordering System 1.0. This vulnerability affects unknown code of the file /signup.php. The manipulation of the argument firstname leads to sql injection. The attack can be initiated r... Read more
- Published: Jul. 28, 2025
- Modified: Aug. 05, 2025
-
4.1
MEDIUMCVE-2023-53158
The gix-transport crate before 0.36.1 for Rust allows command execution via the "gix clone 'ssh://-oProxyCommand=open$IFS" substring. NOTE: this was discovered before CVE-2024-32884, a similar vulnerability (involving a username field) that is more diffic... Read more
Affected Products :- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
-
8.8
HIGHCVE-2025-8247
A vulnerability classified as critical has been found in Projectworlds Online Admission System 1.0. This affects an unknown part of the file /admin.php. The manipulation of the argument markof leads to sql injection. It is possible to initiate the attack ... Read more
Affected Products : online_admission_system- Published: Jul. 28, 2025
- Modified: Aug. 06, 2025
-
7.5
HIGHCVE-2023-53157
The rosenpass crate before 0.2.1 for Rust allows remote attackers to cause a denial of service (panic) via a one-byte UDP packet.... Read more
Affected Products : rosenpass- Published: Jul. 28, 2025
- Modified: Aug. 07, 2025
-
9.0
HIGHCVE-2025-8246
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been rated as critical. Affected by this issue is some unknown functionality of the file /boafrm/formRoute of the component HTTP POST Request Handler. The manipulation of the argument ... Read more
- Published: Jul. 27, 2025
- Modified: Jul. 29, 2025
-
9.0
HIGHCVE-2025-8245
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formMultiAPVLAN of the component HTTP POST Request Handler. The manipulation o... Read more
- Published: Jul. 27, 2025
- Modified: Jul. 29, 2025
-
9.8
CRITICALCVE-2025-8244
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been classified as critical. Affected is an unknown function of the file /boafrm/formMapDelDevice of the component HTTP POST Request Handler. The manipulation of the argument macstr le... Read more
- Published: Jul. 27, 2025
- Modified: Jul. 29, 2025
-
9.0
HIGHCVE-2025-8243
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105 and classified as critical. This issue affects some unknown processing of the file /boafrm/formMapDel of the component HTTP POST Request Handler. The manipulation of the argument devicemac1 le... Read more
- Published: Jul. 27, 2025
- Modified: Jul. 29, 2025
-
9.8
CRITICALCVE-2024-58266
The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection.... Read more
Affected Products : shlex- Published: Jul. 27, 2025
- Modified: Aug. 07, 2025
-
4.3
MEDIUMCVE-2024-58265
The snow crate before 0.9.5 for Rust, when stateful TransportState is used, allows incrementing a nonce and thereby denying message delivery.... Read more
Affected Products : snow- Published: Jul. 27, 2025
- Modified: Aug. 07, 2025
-
9.0
HIGHCVE-2025-8242
A vulnerability has been found in TOTOLINK X15 1.0.0-B20230714.1105 and classified as critical. This vulnerability affects unknown code of the file /boafrm/formFilter of the component HTTP POST Request Handler. The manipulation of the argument ip6addr/url... Read more
- Published: Jul. 27, 2025
- Modified: Jul. 29, 2025
-
9.8
CRITICALCVE-2025-8241
A vulnerability, which was classified as critical, was found in 1000 Projects ABC Courier Management System 1.0. This affects an unknown part of the file /report.php. The manipulation of the argument From leads to sql injection. It is possible to initiate... Read more
Affected Products : abc_courier_management_system- Published: Jul. 27, 2025
- Modified: Aug. 06, 2025
-
7.5
HIGHCVE-2024-58264
The serde-json-wasm crate before 1.0.1 for Rust allows stack consumption via deeply nested JSON data.... Read more
Affected Products : serde-json-wasm- Published: Jul. 27, 2025
- Modified: Aug. 06, 2025