Latest CVE Feed
-
9.8
CRITICALCVE-2025-7933
A vulnerability classified as critical was found in Campcodes Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /pages/settings_update.php of the component Setting Handler. The manipulation of the argument ID leads to sql... Read more
Affected Products : sales_and_inventory_system- Published: Jul. 21, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-52575
EspoCRM is an Open Source CRM (Customer Relationship Management) software. EspoCRM versions 9.1.6 and earlier are vulnerable to blind LDAP Injection when LDAP authentication is enabled. A remote, unauthenticated attacker can manipulate LDAP queries by inj... Read more
Affected Products : espocrm- Published: Jul. 21, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-44654
In Linksys E2500 3.0.04.002, the chroot_local_user option is enabled in the vsftpd configuration file. This could lead to unauthorized access to system files, privilege escalation, or use of the compromised server as a pivot point for internal network att... Read more
Affected Products :- Published: Jul. 21, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-44652
In Netgear RAX30 V1.0.10.94_3, the USERLIMIT_GLOBAL option is set to 0 in multiple bftpd-related configuration files. This can cause DoS attacks when unlimited users are connected.... Read more
Affected Products :- Published: Jul. 21, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2025-36846
An issue was discovered in Eveo URVE Web Manager 27.02.2025. The application exposes a /_internal/pc/vpro.php localhost endpoint to unauthenticated users that is vulnerable to OS Command Injection. The endpoint takes an input parameter that is passed dire... Read more
Affected Products :- Published: Jul. 21, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Injection
-
8.6
HIGHCVE-2025-36845
An issue was discovered in Eveo URVE Web Manager 27.02.2025. The endpoint /_internal/redirect.php allows for Server-Side Request Forgery (SSRF). The endpoint takes a URL as input, sends a request to this address, and reflects the content in the response. ... Read more
Affected Products :- Published: Jul. 21, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Server-Side Request Forgery
-
7.5
HIGHCVE-2025-36107
IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could allow malicious actors to obtain sensitive information due to the cleartext transmission of data.... Read more
Affected Products : cognos_analytics_mobile- Published: Jul. 21, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Information Disclosure
-
6.5
MEDIUMCVE-2025-7932
A vulnerability classified as critical has been found in D-Link DIR‑817L up to 1.04B01. This affects the function lxmldbc_system of the file ssdpcgi. The manipulation leads to command injection. It is possible to initiate the attack remotely. The exploit ... Read more
Affected Products :- Published: Jul. 21, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-7931
A vulnerability was found in code-projects Church Donation System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /members/admin_pic.php. The manipulation of the argument image leads to unrestricted upl... Read more
Affected Products : church_donation_system- Published: Jul. 21, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-7717
Missing Authorization vulnerability in Drupal File Download allows Forceful Browsing.This issue affects File Download: from 0.0.0 before 1.9.0, from 2.0.0 before 2.0.1.... Read more
Affected Products : file_download- Published: Jul. 21, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Authorization
-
6.1
MEDIUMCVE-2025-7716
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Real-time SEO for Drupal allows Cross-Site Scripting (XSS).This issue affects Real-time SEO for Drupal: from 2.0.0 before 2.2.0.... Read more
Affected Products : real-time_seo- Published: Jul. 21, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-7715
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Block Attributes allows Cross-Site Scripting (XSS).This issue affects Block Attributes: from 0.0.0 before 1.1.0, from 2.0.0 before 2.0.1.... Read more
Affected Products : block_attributes- Published: Jul. 21, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-7393
Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Mail Login allows Brute Force.This issue affects Mail Login: from 3.0.0 before 3.2.0, from 4.0.0 before 4.2.0.... Read more
Affected Products : mail_login- Published: Jul. 21, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2025-7392
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Cookies Addons allows Cross-Site Scripting (XSS).This issue affects Cookies Addons: from 1.0.0 before 1.2.4.... Read more
Affected Products : cookies_addons- Published: Jul. 21, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Cross-Site Scripting
-
8.1
HIGHCVE-2025-54082
marshmallow-packages/nova-tiptap is a rich text editor for Laravel Nova based on tiptap. Prior to 5.7.0, a vulnerability was discovered in the marshmallow-packages/nova-tiptap Laravel Nova package that allows unauthenticated users to upload arbitrary file... Read more
Affected Products :- Published: Jul. 21, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-44653
In H3C GR2200 MiniGR1A0V100R016, the USERLIMIT_GLOBAL option is set to 0 in the /etc/bftpd.conf. This can cause DoS attacks when unlimited users are connected.... Read more
- Published: Jul. 21, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2025-44649
In the configuration file of racoon in the TRENDnet TEW-WLC100P 2.03b03, the first item of exchage_mode is set to aggressive. Aggressive mode in IKE Phase 1 exposes identity information in plaintext, is vulnerable to offline dictionary attacks, and lacks ... Read more
- Published: Jul. 21, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2025-43720
Headwind MDM before 5.33.1 makes configuration details accessible to unauthorized users. The Configuration profile is exposed to the Observer user role, revealing the password requires to escape out of the MDM controlled device's profile.... Read more
Affected Products : headwind_mdm- Published: Jul. 21, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Information Disclosure
-
4.8
MEDIUMCVE-2025-36603
Dell AppSync, version(s) 4.6.0.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure and Information ... Read more
Affected Products : appsync- Published: Jul. 21, 2025
- Modified: Aug. 06, 2025
- Vuln Type: XML External Entity
-
6.6
MEDIUMCVE-2025-32744
Dell AppSync, version(s) 4.6.0.0, contains an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.... Read more
Affected Products : appsync- Published: Jul. 21, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Misconfiguration