Latest CVE Feed
-
9.8
CRITICALCVE-2025-7132
A vulnerability was found in Campcodes Payroll Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /ajax.php?action=save_payroll. The manipulation of the argument ID leads to sql injection... Read more
Affected Products : payroll_management_system- Published: Jul. 07, 2025
- Modified: Jul. 08, 2025
-
9.8
CRITICALCVE-2025-6811
Mescius ActiveReports.NET TypeResolutionService Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Mescius ActiveReports.NET. Interaction... Read more
Affected Products : activereports.net- Published: Jul. 07, 2025
- Modified: Aug. 14, 2025
-
9.8
CRITICALCVE-2025-6810
Mescius ActiveReports.NET ReadValue Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Mescius ActiveReports.NET. Interaction with this l... Read more
Affected Products : activereports.net- Published: Jul. 07, 2025
- Modified: Aug. 14, 2025
-
7.5
HIGHCVE-2025-6807
Marvell QConvergeConsole getDriverTmpPath Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Marvell QConvergeConsole. Authentication is not r... Read more
Affected Products : qconvergeconsole- Published: Jul. 07, 2025
- Modified: Jul. 14, 2025
-
8.2
HIGHCVE-2025-6806
Marvell QConvergeConsole decryptFile Directory Traversal Arbitrary File Write Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Marvell QConvergeConsole. Authentication is not required to expl... Read more
Affected Products : qconvergeconsole- Published: Jul. 07, 2025
- Modified: Jul. 14, 2025
-
9.1
CRITICALCVE-2025-6805
Marvell QConvergeConsole deleteEventLogFile Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of Marvell QConvergeConsole. Authentication is not requir... Read more
Affected Products : qconvergeconsole- Published: Jul. 07, 2025
- Modified: Jul. 14, 2025
-
7.5
HIGHCVE-2025-6804
Marvell QConvergeConsole compressFirmwareDumpFiles Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Marvell QConvergeConsole. Authentication... Read more
Affected Products : qconvergeconsole- Published: Jul. 07, 2025
- Modified: Jul. 14, 2025
-
7.5
HIGHCVE-2025-6803
Marvell QConvergeConsole compressDriverFiles Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Marvell QConvergeConsole. Authentication is no... Read more
Affected Products : qconvergeconsole- Published: Jul. 07, 2025
- Modified: Jul. 14, 2025
-
9.8
CRITICALCVE-2025-6802
Marvell QConvergeConsole getFileFromURL Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole. Authentication is not require... Read more
Affected Products : qconvergeconsole- Published: Jul. 07, 2025
- Modified: Jul. 14, 2025
-
8.2
HIGHCVE-2025-6801
Marvell QConvergeConsole saveNICParamsToFile Directory Traversal Arbitrary File Write Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Marvell QConvergeConsole. Authentication is not required... Read more
Affected Products : qconvergeconsole- Published: Jul. 07, 2025
- Modified: Jul. 14, 2025
-
7.5
HIGHCVE-2025-6800
Marvell QConvergeConsole restoreESwitchConfig Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Marvell QConvergeConsole. Authentication is n... Read more
Affected Products : qconvergeconsole- Published: Jul. 07, 2025
- Modified: Jul. 14, 2025
-
7.5
HIGHCVE-2025-6799
Marvell QConvergeConsole getFileUploadBytes Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Marvell QConvergeConsole. Authentication is not... Read more
Affected Products : qconvergeconsole- Published: Jul. 07, 2025
- Modified: Jul. 14, 2025
-
9.1
CRITICALCVE-2025-6798
Marvell QConvergeConsole deleteAppFile Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of Marvell QConvergeConsole. Authentication is not required to... Read more
Affected Products : qconvergeconsole- Published: Jul. 07, 2025
- Modified: Jul. 14, 2025
-
7.5
HIGHCVE-2025-6797
Marvell QConvergeConsole getFileUploadBytes Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Marvell QConvergeConsole. Authentication is not... Read more
Affected Products : qconvergeconsole- Published: Jul. 07, 2025
- Modified: Jul. 14, 2025
-
7.5
HIGHCVE-2025-6796
Marvell QConvergeConsole getAppFileBytes Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Marvell QConvergeConsole. Authentication is not re... Read more
Affected Products : qconvergeconsole- Published: Jul. 07, 2025
- Modified: Jul. 14, 2025
-
7.5
HIGHCVE-2025-6795
Marvell QConvergeConsole getFileUploadSize Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Marvell QConvergeConsole. Authentication is not ... Read more
Affected Products : qconvergeconsole- Published: Jul. 07, 2025
- Modified: Jul. 14, 2025
-
9.8
CRITICALCVE-2025-6794
Marvell QConvergeConsole saveAsText Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole. Authentication is not required to expl... Read more
Affected Products : qconvergeconsole- Published: Jul. 07, 2025
- Modified: Jul. 14, 2025
-
9.4
CRITICALCVE-2025-6793
Marvell QConvergeConsole QLogicDownloadImpl Directory Traversal Arbitrary File Deletion and Information Disclosure Vulnerability. This vulnerability allows remote attackers to delete arbitrary files and disclose sensitive information on affected installat... Read more
Affected Products : qconvergeconsole- Published: Jul. 07, 2025
- Modified: Jul. 14, 2025
-
7.5
HIGHCVE-2025-6714
MongoDB Server's mongos component can become unresponsive to new connections due to incorrect handling of incomplete data. This affects MongoDB when configured with load balancer support. This issue affects MongoDB Server v6.0 prior to 6.0.23, MongoDB Ser... Read more
Affected Products : mongodb- Published: Jul. 07, 2025
- Modified: Jul. 08, 2025
-
7.7
HIGHCVE-2025-6713
An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling of the $mergeCursors stage in MongoDB Server. This may lead to access to data without further authorisation. Th... Read more
Affected Products : mongodb- Published: Jul. 07, 2025
- Modified: Jul. 18, 2025