Latest CVE Feed
-
8.8
CVSS31CVE-2025-7549
A vulnerability was found in Tenda FH1201 1.2.0.14(408) and classified as critical. This issue affects the function frmL7ProtForm of the file /goform/L7Prot. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be ini... Read more
Affected Products : fh1201_firmware- Published: Jul. 13, 2025
- Modified: Jul. 13, 2025
-
8.8
CVSS31CVE-2025-7548
A vulnerability has been found in Tenda FH1201 1.2.0.14(408) and classified as critical. This vulnerability affects the function formSafeEmailFilter of the file /goform/SafeEmailFilter. The manipulation of the argument page leads to stack-based buffer ove... Read more
Affected Products : fh1201_firmware- Published: Jul. 13, 2025
- Modified: Jul. 13, 2025
-
7.3
CVSS31CVE-2025-7547
A vulnerability, which was classified as critical, was found in Campcodes Online Movie Theater Seat Reservation System 1.0. This affects the function save_movie of the file /admin/admin_class.php. The manipulation of the argument cover leads to unrestrict... Read more
Affected Products :- Published: Jul. 13, 2025
- Modified: Jul. 13, 2025
-
5.9
CVSS31CVE-2025-1735
In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* pgsql and pdo_pgsql escaping functions do not check if the underlying quoting functions returned errors. This could cause crashes if Postgres server rejects the string as... Read more
Affected Products : php- Published: Jul. 13, 2025
- Modified: Jul. 13, 2025
-
3.7
CVSS31CVE-2025-1220
In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 some functions like fsockopen() lack validation that the hostname supplied does not contain null characters. This may lead to other functions like parse_url... Read more
Affected Products : php- Published: Jul. 13, 2025
- Modified: Jul. 13, 2025
-
5.3
CVSS31CVE-2025-7546
A vulnerability, which was classified as problematic, has been found in GNU Binutils 2.45. Affected by this issue is the function bfd_elf_set_group_contents of the file bfd/elf.c. The manipulation leads to out-of-bounds write. It is possible to launch the... Read more
Affected Products : binutils- Published: Jul. 13, 2025
- Modified: Jul. 13, 2025
-
5.3
CVSS31CVE-2025-7545
A vulnerability classified as problematic was found in GNU Binutils 2.45. Affected by this vulnerability is the function copy_section of the file binutils/objcopy.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement.... Read more
Affected Products : binutils- Published: Jul. 13, 2025
- Modified: Jul. 13, 2025
-
8.8
CVSS31CVE-2025-7544
A vulnerability was found in Tenda AC1206 15.03.06.23. It has been rated as critical. This issue affects the function formSetMacFilterCfg of the file /goform/setMacFilterCfg. The manipulation of the argument deviceList leads to stack-based buffer overflow... Read more
Affected Products : ac1206_firmware- Published: Jul. 13, 2025
- Modified: Jul. 13, 2025
-
6.3
CVSS31CVE-2025-7543
A vulnerability was found in PHPGurukul User Registration & Login and User Management System 3.3. It has been classified as critical. This affects an unknown part of the file /admin/manage-users.php. The manipulation of the argument ID leads to sql inject... Read more
Affected Products : user_registration_\&_login_and_user_management_system- Published: Jul. 13, 2025
- Modified: Jul. 13, 2025
-
5.9
CVSS31CVE-2025-6491
In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 when parsing XML data in SOAP extensions, overly large (>2Gb) XML namespace prefix may lead to null pointer dereference. This may lead to crashes and affect... Read more
Affected Products : php- Published: Jul. 13, 2025
- Modified: Jul. 13, 2025
-
7.2
CVSS31CVE-2024-58258
SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can occur.... Read more
Affected Products : sugarcrm- Published: Jul. 13, 2025
- Modified: Jul. 13, 2025
-
7.3
CVSS31CVE-2025-7542
A vulnerability was found in PHPGurukul User Registration & Login and User Management System 3.3 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/user-profile.php. The manipulation of the argument uid lea... Read more
Affected Products : user_registration_\&_login_and_user_management_system- Published: Jul. 13, 2025
- Modified: Jul. 13, 2025
-
7.3
CVSS31CVE-2025-7541
A vulnerability has been found in code-projects Online Appointment Booking System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /get_town.php. The manipulation of the argument countryid leads to sql... Read more
Affected Products :- Published: Jul. 13, 2025
- Modified: Jul. 13, 2025
-
7.3
CVSS31CVE-2025-7540
A vulnerability, which was classified as critical, was found in code-projects Online Appointment Booking System 1.0. Affected is an unknown function of the file /getclinic.php. The manipulation of the argument townid leads to sql injection. It is possible... Read more
Affected Products :- Published: Jul. 13, 2025
- Modified: Jul. 13, 2025
-
7.3
CVSS31CVE-2025-7539
A vulnerability, which was classified as critical, has been found in code-projects Online Appointment Booking System 1.0. This issue affects some unknown processing of the file /getdoctordaybooking.php. The manipulation of the argument cid leads to sql in... Read more
Affected Products :- Published: Jul. 13, 2025
- Modified: Jul. 13, 2025
-
6.4
CVSS31CVE-2025-53865
In Roundup before 2.5.0, XSS can occur via interaction between URLs and issue tracker templates (devel and responsive).... Read more
Affected Products : roundup- Published: Jul. 13, 2025
- Modified: Jul. 13, 2025
-
7.3
CVSS31CVE-2025-7538
A vulnerability classified as critical was found in Campcodes Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /pages/product_update.php. The manipulation of the argument image leads to unrestricted upload. The attack ca... Read more
Affected Products : sales_and_inventory_system- Published: Jul. 13, 2025
- Modified: Jul. 13, 2025
-
7.3
CVSS31CVE-2025-7537
A vulnerability classified as critical has been found in Campcodes Sales and Inventory System 1.0. This affects an unknown part of the file /pages/product_update.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate t... Read more
Affected Products : sales_and_inventory_system- Published: Jul. 13, 2025
- Modified: Jul. 13, 2025
-
7.3
CVSS31CVE-2025-7536
A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /pages/receipt_credit.php. The manipulation of the argument sid leads to sql injection. ... Read more
Affected Products : sales_and_inventory_system- Published: Jul. 13, 2025
- Modified: Jul. 13, 2025
-
7.3
CVSS31CVE-2025-7535
A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /pages/reprint_cash.php. The manipulation of the argument sid leads to sql inje... Read more
Affected Products : sales_and_inventory_system- Published: Jul. 13, 2025
- Modified: Jul. 13, 2025