Latest CVE Feed
-
0.0
NACVE-2025-38469
In the Linux kernel, the following vulnerability has been resolved: KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls kvm_xen_schedop_poll does a kmalloc_array() when a VM polls the host for more than one event channel potr (nr... Read more
Affected Products : linux_kernel- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
-
0.0
NACVE-2025-38468
In the Linux kernel, the following vulnerability has been resolved: net/sched: Return NULL when htb_lookup_leaf encounters an empty rbtree htb_lookup_leaf has a BUG_ON that can trigger with the following: tc qdisc del dev lo root tc qdisc add dev lo ro... Read more
Affected Products : linux_kernel- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
-
9.8
CRITICALCVE-2025-8273
A vulnerability classified as critical has been found in code-projects Exam Form Submission 1.0. Affected is an unknown function of the file /admin/update_s8.php. The manipulation of the argument credits leads to sql injection. It is possible to launch th... Read more
Affected Products : exam_form_submission- Published: Jul. 28, 2025
- Modified: Jul. 30, 2025
-
9.8
CRITICALCVE-2025-8272
A vulnerability was found in code-projects Exam Form Submission 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/update_fst.php. The manipulation of the argument credits leads to sql injection. The attack m... Read more
Affected Products : exam_form_submission- Published: Jul. 28, 2025
- Modified: Jul. 30, 2025
-
9.8
CRITICALCVE-2025-6918
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ncvav Virtual PBX Software allows SQL Injection.This issue affects Virtual PBX Software: before 09.07.2025.... Read more
Affected Products :- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
-
4.8
MEDIUMCVE-2025-40730
HTML injection in Vox Media's Chorus CMS. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL using the 'q' parameter in '/search'. This vulnerability can be exploited to steal sensitive... Read more
Affected Products :- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
-
9.8
CRITICALCVE-2025-8271
A vulnerability was found in code-projects Exam Form Submission 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/delete_s3.php. The manipulation of the argument ID leads to sql injection. The attack can be ... Read more
Affected Products : exam_form_submission- Published: Jul. 28, 2025
- Modified: Jul. 30, 2025
-
9.8
CRITICALCVE-2025-8270
A vulnerability was found in code-projects Exam Form Submission 1.0. It has been classified as critical. This affects an unknown part of the file /admin/delete_s2.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate ... Read more
Affected Products : exam_form_submission- Published: Jul. 28, 2025
- Modified: Jul. 30, 2025
-
9.8
CRITICALCVE-2025-8269
A vulnerability was found in code-projects Exam Form Submission 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/delete_s1.php. The manipulation of the argument ID leads to sql injection. The attack m... Read more
Affected Products : exam_form_submission- Published: Jul. 28, 2025
- Modified: Jul. 30, 2025
-
6.5
MEDIUMCVE-2025-8266
A vulnerability has been found in yanyutao0402 ChanCMS up to 3.1.2 and classified as critical. Affected by this vulnerability is the function getArticle of the file app/modules/cms/controller/collect.js. The manipulation of the argument targetUrl leads to... Read more
Affected Products : chancms- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
-
5.8
MEDIUMCVE-2025-8265
A vulnerability classified as critical has been found in 299Ko CMS 2.0.0. This affects an unknown part of the file /admin/filemanager/view of the component File Management. The manipulation leads to unrestricted upload. It is possible to initiate the atta... Read more
Affected Products :- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
-
4.8
MEDIUMCVE-2025-27802
The Episerver Content Management System (CMS) by Optimizely was affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities. This allowed an authenticated attacker to execute malicious JavaScript code in the victim's browser. RTE properties (t... Read more
Affected Products :- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
-
4.8
MEDIUMCVE-2025-27801
The Episerver Content Management System (CMS) by Optimizely was affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities. This allowed an authenticated attacker to execute malicious JavaScript code in the victim's browser. ContentReferenc... Read more
Affected Products :- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
-
4.8
MEDIUMCVE-2025-27800
The Episerver Content Management System (CMS) by Optimizely was affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities. This allowed an authenticated attacker to execute malicious JavaScript code in the victim's browser. The Admin dashb... Read more
Affected Products :- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
-
7.5
HIGHCVE-2025-8262
A vulnerability was found in yarnpkg Yarn up to 1.22.22. It has been classified as problematic. Affected is the function explodeHostedGitFragment of the file src/resolvers/exotics/hosted-git-resolver.js. The manipulation leads to inefficient regular expre... Read more
Affected Products : yarn- Published: Jul. 28, 2025
- Modified: Jul. 31, 2025
-
9.8
CRITICALCVE-2025-8261
A vulnerability was found in Vaelsys 4.1.0 and classified as critical. This issue affects some unknown processing of the file /grid/vgrid_server.php of the component User Creation Handler. The manipulation leads to improper authorization. The attack may b... Read more
Affected Products : vaelsys- Published: Jul. 28, 2025
- Modified: Jul. 31, 2025
-
7.5
HIGHCVE-2025-8260
A vulnerability has been found in Vaelsys 4.1.0 and classified as problematic. This vulnerability affects unknown code of the file /grid/vgrid_server.php of the component MD4 Hash Handler. The manipulation of the argument xajaxargs leads to use of weak ha... Read more
Affected Products : vaelsys- Published: Jul. 28, 2025
- Modified: Jul. 31, 2025
-
9.8
CRITICALCVE-2025-8259
A vulnerability, which was classified as critical, was found in Vaelsys 4.1.0. This affects the function execute_DataObjectProc of the file /grid/vgrid_server.php. The manipulation of the argument xajaxargs leads to os command injection. It is possible to... Read more
Affected Products : vaelsys- Published: Jul. 28, 2025
- Modified: Jul. 31, 2025
-
8.8
HIGHCVE-2025-8267
Versions of the package ssrfcheck before 1.2.0 are vulnerable to Server-Side Request Forgery (SSRF) due to an incomplete denylist of IP address ranges. Specifically, the package fails to classify the reserved IP address space 224.0.0.0/4 (Multicast) as in... Read more
Affected Products : ssrf_check- Published: Jul. 28, 2025
- Modified: Aug. 07, 2025
-
5.3
MEDIUMCVE-2025-8258
A vulnerability, which was classified as problematic, has been found in Cool Mo Maigcal Number App up to 1.0.3 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.sdmagic.number. The manipu... Read more
Affected Products : maigcal_number- Published: Jul. 28, 2025
- Modified: Aug. 07, 2025