Latest CVE Feed
-
0.0
NACVE-2025-38471
In the Linux kernel, the following vulnerability has been resolved: tls: always refresh the queue when reading sock After recent changes in net-next TCP compacts skbs much more aggressively. This unearthed a bug in TLS where we may try to operate on an ... Read more
Affected Products : linux_kernel- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Memory Corruption
-
0.0
NACVE-2025-38470
In the Linux kernel, the following vulnerability has been resolved: net: vlan: fix VLAN 0 refcount imbalance of toggling filtering during runtime Assuming the "rx-vlan-filter" feature is enabled on a net device, the 8021q module will automatically add o... Read more
Affected Products : linux_kernel- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Misconfiguration
-
0.0
NACVE-2025-38469
In the Linux kernel, the following vulnerability has been resolved: KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls kvm_xen_schedop_poll does a kmalloc_array() when a VM polls the host for more than one event channel potr (nr... Read more
Affected Products : linux_kernel- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Memory Corruption
-
0.0
NACVE-2025-38468
In the Linux kernel, the following vulnerability has been resolved: net/sched: Return NULL when htb_lookup_leaf encounters an empty rbtree htb_lookup_leaf has a BUG_ON that can trigger with the following: tc qdisc del dev lo root tc qdisc add dev lo ro... Read more
Affected Products : linux_kernel- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-8273
A vulnerability classified as critical has been found in code-projects Exam Form Submission 1.0. Affected is an unknown function of the file /admin/update_s8.php. The manipulation of the argument credits leads to sql injection. It is possible to launch th... Read more
Affected Products : exam_form_submission- Published: Jul. 28, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-8272
A vulnerability was found in code-projects Exam Form Submission 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/update_fst.php. The manipulation of the argument credits leads to sql injection. The attack m... Read more
Affected Products : exam_form_submission- Published: Jul. 28, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6918
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ncvav Virtual PBX Software allows SQL Injection.This issue affects Virtual PBX Software: before 09.07.2025.... Read more
Affected Products :- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Injection
-
4.8
MEDIUMCVE-2025-40730
HTML injection in Vox Media's Chorus CMS. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL using the 'q' parameter in '/search'. This vulnerability can be exploited to steal sensitive... Read more
Affected Products :- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-8271
A vulnerability was found in code-projects Exam Form Submission 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/delete_s3.php. The manipulation of the argument ID leads to sql injection. The attack can be ... Read more
Affected Products : exam_form_submission- Published: Jul. 28, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-8270
A vulnerability was found in code-projects Exam Form Submission 1.0. It has been classified as critical. This affects an unknown part of the file /admin/delete_s2.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate ... Read more
Affected Products : exam_form_submission- Published: Jul. 28, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-8269
A vulnerability was found in code-projects Exam Form Submission 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/delete_s1.php. The manipulation of the argument ID leads to sql injection. The attack m... Read more
Affected Products : exam_form_submission- Published: Jul. 28, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-8266
A vulnerability has been found in yanyutao0402 ChanCMS up to 3.1.2 and classified as critical. Affected by this vulnerability is the function getArticle of the file app/modules/cms/controller/collect.js. The manipulation of the argument targetUrl leads to... Read more
- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Injection
-
5.8
MEDIUMCVE-2025-8265
A vulnerability classified as critical has been found in 299Ko CMS 2.0.0. This affects an unknown part of the file /admin/filemanager/view of the component File Management. The manipulation leads to unrestricted upload. It is possible to initiate the atta... Read more
Affected Products :- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Authentication
-
4.8
MEDIUMCVE-2025-27802
The Episerver Content Management System (CMS) by Optimizely was affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities. This allowed an authenticated attacker to execute malicious JavaScript code in the victim's browser. RTE properties (t... Read more
Affected Products :- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-27801
The Episerver Content Management System (CMS) by Optimizely was affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities. This allowed an authenticated attacker to execute malicious JavaScript code in the victim's browser. ContentReferenc... Read more
Affected Products :- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-27800
The Episerver Content Management System (CMS) by Optimizely was affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities. This allowed an authenticated attacker to execute malicious JavaScript code in the victim's browser. The Admin dashb... Read more
Affected Products :- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-8262
A vulnerability was found in yarnpkg Yarn up to 1.22.22. It has been classified as problematic. Affected is the function explodeHostedGitFragment of the file src/resolvers/exotics/hosted-git-resolver.js. The manipulation leads to inefficient regular expre... Read more
Affected Products : yarn- Published: Jul. 28, 2025
- Modified: Jul. 31, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2025-8261
A vulnerability was found in Vaelsys 4.1.0 and classified as critical. This issue affects some unknown processing of the file /grid/vgrid_server.php of the component User Creation Handler. The manipulation leads to improper authorization. The attack may b... Read more
Affected Products : vaelsys- Published: Jul. 28, 2025
- Modified: Jul. 31, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-8260
A vulnerability has been found in Vaelsys 4.1.0 and classified as problematic. This vulnerability affects unknown code of the file /grid/vgrid_server.php of the component MD4 Hash Handler. The manipulation of the argument xajaxargs leads to use of weak ha... Read more
Affected Products : vaelsys- Published: Jul. 28, 2025
- Modified: Jul. 31, 2025
- Vuln Type: Cryptography
-
9.8
CRITICALCVE-2025-8259
A vulnerability, which was classified as critical, was found in Vaelsys 4.1.0. This affects the function execute_DataObjectProc of the file /grid/vgrid_server.php. The manipulation of the argument xajaxargs leads to os command injection. It is possible to... Read more
Affected Products : vaelsys- Published: Jul. 28, 2025
- Modified: Jul. 31, 2025
- Vuln Type: Injection