Latest CVE Feed
-
9.8
CRITICALCVE-2025-8336
A vulnerability classified as critical was found in Campcodes Online Recruitment Management System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=save_user. The manipulation of the argument ID leads to sql injection. The a... Read more
Affected Products : online_recruitment_management_system- Published: Jul. 30, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2025-8335
A vulnerability classified as problematic has been found in code-projects Simple Car Rental System 1.0. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has bee... Read more
- Published: Jul. 30, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Cross-Site Request Forgery
-
9.8
CRITICALCVE-2025-8334
A vulnerability was found in Campcodes Online Recruitment Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/ajax.php?action=delete_recruitment_status. The manipulation of the argu... Read more
Affected Products : online_recruitment_management_system- Published: Jul. 30, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2025-54586
GitProxy is an application that stands between developers and a Git remote endpoint. In versions 1.19.1 and below, attackers can inject extra commits into the pack sent to GitHub, commits that aren’t pointed to by any branch. Although these “hidden” com... Read more
Affected Products : gitproxy- Published: Jul. 30, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-8333
A vulnerability was found in code-projects Online Farm System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /categoryvalue.php. The manipulation of the argument Value leads to sql injection. ... Read more
Affected Products : online_farm_system- Published: Jul. 30, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-8332
A vulnerability was found in code-projects Online Farm System 1.0. It has been classified as critical. Affected is an unknown function of the file /register.php. The manipulation of the argument Username leads to sql injection. It is possible to launch th... Read more
Affected Products : online_farm_system- Published: Jul. 30, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Injection
-
8.2
HIGHCVE-2025-54585
GitProxy is an application that stands between developers and a Git remote endpoint. In versions 1.19.1 and below, attackers can exploit the way GitProxy handles new branch creation to bypass the approval of prior commits on the parent branch. The vulnera... Read more
Affected Products : gitproxy- Published: Jul. 30, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-8331
A vulnerability was found in code-projects Online Farm System 1.0 and classified as critical. This issue affects some unknown processing of the file /forgot_pass.php. The manipulation of the argument email leads to sql injection. The attack may be initiat... Read more
Affected Products : online_farm_system- Published: Jul. 30, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-8330
A vulnerability has been found in code-projects Vehicle Management 1.0 and classified as critical. This vulnerability affects unknown code of the file /edit1.php. The manipulation of the argument sno leads to sql injection. The attack can be initiated rem... Read more
- Published: Jul. 30, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Injection
-
7.0
HIGHCVE-2025-54584
GitProxy is an application that stands between developers and a Git remote endpoint (e.g., github.com). In versions 1.19.1 and below, an attacker can craft a malicious Git packfile to exploit the PACK signature detection in the parsePush.ts file. By embed... Read more
Affected Products : gitproxy- Published: Jul. 30, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Misconfiguration
-
8.3
HIGHCVE-2025-54583
GitProxy is an application that stands between developers and a Git remote endpoint (e.g., github.com). Versions 1.19.1 and below allow users to push to remote repositories while bypassing policies and explicit approvals. Since checks and plugins are skip... Read more
Affected Products : gitproxy- Published: Jul. 30, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-54581
vproxy is an HTTP/HTTPS/SOCKS5 proxy server. In versions 2.3.3 and below, untrusted data is extracted from the user-controlled HTTP Proxy-Authorization header and passed to Extension::try_from and flows into parse_ttl_extension where it is parsed as a TTL... Read more
Affected Products :- Published: Jul. 30, 2025
- Modified: Jul. 31, 2025
- Vuln Type: Denial of Service
-
9.1
CRITICALCVE-2025-54576
OAuth2-Proxy is an open-source tool that can act as either a standalone reverse proxy or a middleware component integrated into existing reverse proxy or load balancer setups. In versions 7.10.0 and below, oauth2-proxy deployments are vulnerable when usin... Read more
Affected Products : oauth2_proxy- Published: Jul. 30, 2025
- Modified: Jul. 31, 2025
- Vuln Type: Authentication
-
5.3
MEDIUMCVE-2025-54575
ImageSharp is a 2D graphics library. In versions below 2.1.11 and 3.0.0 through 3.1.10, a specially crafted GIF file containing a malformed comment extension block (with a missing block terminator) can cause the ImageSharp GIF decoder to enter an infinite... Read more
Affected Products : imagesharp- Published: Jul. 30, 2025
- Modified: Jul. 31, 2025
- Vuln Type: Denial of Service
-
8.6
HIGHCVE-2025-53022
TrustedFirmware-M (aka Trusted Firmware for M profile Arm CPUs) before 2.1.3 and 2.2.x before 2.2.1 lacks length validation during a firmware upgrade. While processing a new image, the Firmware Upgrade (FWU) module does not validate the length field of th... Read more
Affected Products :- Published: Jul. 30, 2025
- Modified: Jul. 31, 2025
- Vuln Type: Memory Corruption
-
8.2
HIGHCVE-2025-52187
GetProjectsIdea Create School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in my_profile_update_form1.php.... Read more
Affected Products : create_school_management_system- Published: Jul. 30, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-51954
playground.electronhub.ai v1.1.9 was discovered to contain a cross-site scripting (XSS) vulnerability.... Read more
Affected Products : ai_playground- Published: Jul. 30, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Cross-Site Scripting
-
8.1
HIGHCVE-2024-48916
Ceph is a distributed object, block, and file storage platform. In versions 19.2.3 and below, it is possible to send an JWT that has "none" as JWT alg. And by doing so the JWT signature is not checked. The vulnerability is most likely in the RadosGW OIDC ... Read more
Affected Products : ceph- Published: Jul. 30, 2025
- Modified: Jul. 31, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-8329
A vulnerability, which was classified as critical, was found in code-projects Vehicle Management 1.0. This affects an unknown part of the file /filter3.php. The manipulation of the argument company leads to sql injection. It is possible to initiate the at... Read more
- Published: Jul. 30, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-51951
andisearch v0.5.249 was discovered to contain a cross-site scripting (XSS) vulnerability.... Read more
Affected Products : andisearch- Published: Jul. 30, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Cross-Site Scripting