Latest CVE Feed
-
4.3
MEDIUMCVE-2025-52996
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. In versions 2.32.0 and prior, the implementation of password protected links is error-prone, resulting in po... Read more
Affected Products : filebrowser- Published: Jun. 30, 2025
- Modified: Aug. 04, 2025
- Vuln Type: Misconfiguration
-
8.0
HIGHCVE-2025-52995
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.33.10, the implementation of the allowlist is erroneous, allowing a user to execute more ... Read more
Affected Products : filebrowser- Published: Jun. 30, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-52901
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.33.9, access tokens are used as GET parameters. The JSON Web Token (JWT) which is used as... Read more
Affected Products : filebrowser- Published: Jun. 30, 2025
- Modified: Aug. 04, 2025
- Vuln Type: Information Disclosure
-
5.8
MEDIUMCVE-2025-52491
Akamai CloudTest before 60 2025.06.09 (12989) allows SSRF.... Read more
Affected Products : cloudtest- Published: Jun. 30, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Server-Side Request Forgery
-
5.8
MEDIUMCVE-2025-49493
Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection.... Read more
Affected Products : cloudtest- Published: Jun. 30, 2025
- Modified: Jul. 03, 2025
- Vuln Type: XML External Entity
-
8.8
HIGHCVE-2025-36593
Dell OpenManage Network Integration, versions prior to 3.8, contains an Authentication Bypass by Capture-replay vulnerability in the RADIUS protocol. An attacker with local network access could potentially exploit this vulnerability to forge a valid prot... Read more
Affected Products :- Published: Jun. 30, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Authentication
-
5.5
MEDIUMCVE-2025-6925
A vulnerability has been found in Dromara RuoYi-Vue-Plus 5.4.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /src/main/java/org/dromara/demo/controller/MailController.java of the component Mail Handler.... Read more
Affected Products :- Published: Jun. 30, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-6917
A vulnerability has been found in code-projects Online Hotel Booking 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/registration.php. The manipulation of the argument uname leads to sql injection. The attack can... Read more
Affected Products : online_hotel_booking- Published: Jun. 30, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-52898
Frappe is a full-stack web application framework. Prior to versions 14.94.3 and 15.58.0, a carefully crafted request could lead to a malicious actor getting access to a user's password reset token. This can only be exploited on self hosted instances confi... Read more
Affected Products : frappe- Published: Jun. 30, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2025-6916
A vulnerability, which was classified as critical, was found in TOTOLINK T6 4.1.5cu.748_B20211015. This affects the function Form_Login of the file /formLoginAuth.htm. The manipulation of the argument authCode/goURL leads to missing authentication. The at... Read more
- Published: Jun. 30, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2025-6915
A vulnerability, which was classified as critical, has been found in PHPGurukul Student Record System 3.2. Affected by this issue is some unknown functionality of the file /register.php. The manipulation of the argument session leads to sql injection. The... Read more
Affected Products : student_record_system- Published: Jun. 30, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
8.6
HIGHCVE-2025-52896
Frappe is a full-stack web application framework. Prior to versions 14.94.2 and 15.57.0, authenticated users could upload carefully crafted malicious files via Data Import, leading to cross-site scripting (XSS). This issue has been patched in versions 14.... Read more
Affected Products : frappe- Published: Jun. 30, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Cross-Site Scripting
-
8.7
HIGHCVE-2025-52895
Frappe is a full-stack web application framework. Prior to versions 14.94.3 and 15.58.0, SQL injection could be achieved via a specially crafted request, which could allow malicious person to gain access to sensitive information. This issue has been patch... Read more
Affected Products : frappe- Published: Jun. 30, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2025-47871
Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly validate channel membership when retrieving playbook run metadata, allowing authenticated users who are playbook members but not... Read more
Affected Products : mattermost_server- Published: Jun. 30, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Information Disclosure
-
5.4
MEDIUMCVE-2025-46702
Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly enforce channel member management permissions when adding participants to playbook runs. This allows authenticated users with me... Read more
Affected Products : mattermost_server- Published: Jun. 30, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-45931
An issue D-Link DIR-816-A2 DIR-816A2_FWv1.10CNB05_R1B011D88210 allows a remote attacker to execute arbitrary code via system() function in the bin/goahead file... Read more
- Published: Jun. 30, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
7.0
HIGHCVE-2025-45143
string-math v1.2.2 was discovered to contain a Regex Denial of Service (ReDoS) which is exploited via a crafted input.... Read more
Affected Products :- Published: Jun. 30, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2025-26074
Orkes Conductor v3.21.11 allows remote attackers to execute arbitrary OS commands through unrestricted access to Java classes.... Read more
Affected Products :- Published: Jun. 30, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2025-6914
A vulnerability classified as critical was found in PHPGurukul Student Record System 3.2. Affected by this vulnerability is an unknown functionality of the file /edit-student.php. The manipulation of the argument fmarks2 leads to sql injection. The attack... Read more
Affected Products : student_record_system- Published: Jun. 30, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-6913
A vulnerability classified as critical has been found in PHPGurukul Student Record System 3.2. Affected is an unknown function of the file /admin-profile.php. The manipulation of the argument aemailid leads to sql injection. It is possible to launch the a... Read more
Affected Products : student_record_system- Published: Jun. 30, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection