Latest CVE Feed
-
7.8
HIGHCVE-2025-53416
Delta Electronics DTN Soft Project File Parsing Deserialization of Untrusted Data Remote Code Execution... Read more
Affected Products : dtn_soft- Published: Jun. 30, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2025-41439
A reflected cross-site scripting vulnerability via a specific parameter exists in SLNX Help Documentation of RICOH Streamline NX. If this vulnerability is exploited, an arbitrary script may be executed in the web browser of the user who accessed the produ... Read more
Affected Products :- Published: Jun. 30, 2025
- Modified: Jun. 30, 2025
-
7.5
HIGHCVE-2024-8419
The endpoint hosts a script that allows an unauthorized remote attacker to put the system in a fail-safe state over the network due to missing authentication.... Read more
Affected Products :- Published: Jun. 30, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-6900
A vulnerability has been found in code-projects Library System 1.0 and classified as critical. This vulnerability affects unknown code of the file /add-book.php. The manipulation of the argument image leads to unrestricted upload. The attack can be initia... Read more
Affected Products : library_system- Published: Jun. 30, 2025
- Modified: Jul. 01, 2025
-
8.8
HIGHCVE-2025-6899
A vulnerability, which was classified as critical, was found in D-Link DI-7300G+ and DI-8200G 17.12.20A1/19.12.25A1. This affects an unknown part of the file msp_info.htm. The manipulation of the argument flag/cmd/iface leads to os command injection. It i... Read more
- Published: Jun. 30, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2025-53415
Delta Electronics DTM Soft Project File Parsing Deserialization of Untrusted Data Remote Code Execution... Read more
Affected Products :- Published: Jun. 30, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Information Disclosure
-
6.1
MEDIUMCVE-2025-40734
Reflected Cross-Site Scripting (XSS) vulnerability in Daily Expense Manager v1.0. This vulnerability allows an attacker to execute JavaScript code by sending a POST request through the password and confirm_password parameters in /register.php.... Read more
Affected Products : daily_expense_manager- Published: Jun. 30, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-40733
Reflected Cross-Site Scripting (XSS) vulnerability in Daily Expense Manager v1.0. This vulnerability allows an attacker to execute JavaScript code by sending a POST request through the username parameter in /login.php.... Read more
Affected Products : daily_expense_manager- Published: Jun. 30, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Cross-Site Scripting
-
8.7
HIGHCVE-2025-40732
user enumeration vulnerability in Daily Expense Manager v1.0. To exploit this vulnerability a POST request must be sent using the name parameter in /check.php... Read more
Affected Products : daily_expense_manager- Published: Jun. 30, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-40731
SQL injection vulnerability in Daily Expense Manager v1.0. This vulnerability allows an attacker to retrieve, create, update and delete databases through the pname, pprice and id parameters in /update.php.... Read more
Affected Products : daily_expense_manager- Published: Jun. 30, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-6898
A vulnerability, which was classified as critical, has been found in D-Link DI-7300G+ 19.12.25A1. Affected by this issue is some unknown functionality of the file in proxy_client.asp. The manipulation of the argument proxy_srv/proxy_lanport/proxy_lanip/pr... Read more
- Published: Jun. 30, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6897
A vulnerability classified as critical was found in D-Link DI-7300G+ 19.12.25A1. Affected by this vulnerability is an unknown functionality of the file httpd_debug.asp. The manipulation of the argument Time leads to os command injection. The exploit has b... Read more
- Published: Jun. 30, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Injection
-
0.0
NACVE-2025-38090
In the Linux kernel, the following vulnerability has been resolved: drivers/rapidio/rio_cm.c: prevent possible heap overwrite In riocm_cdev_ioctl(RIO_CM_CHAN_SEND) -> cm_chan_msg_send() -> riocm_ch_send() cm_chan_msg_send() checks that usersp... Read more
Affected Products : linux_kernel- Published: Jun. 30, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Memory Corruption
-
0.0
NACVE-2025-38089
In the Linux kernel, the following vulnerability has been resolved: sunrpc: handle SVC_GARBAGE during svc auth processing as auth error tianshuo han reported a remotely-triggerable crash if the client sends a kernel RPC server a specially crafted packet... Read more
Affected Products : linux_kernel- Published: Jun. 30, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Authentication
-
0.0
NACVE-2025-38088
In the Linux kernel, the following vulnerability has been resolved: powerpc/powernv/memtrace: Fix out of bounds issue in memtrace mmap memtrace mmap issue has an out of bounds issue. This patch fixes the by checking that the requested mapping region siz... Read more
Affected Products : linux_kernel- Published: Jun. 30, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Memory Corruption
-
0.0
NACVE-2025-38087
In the Linux kernel, the following vulnerability has been resolved: net/sched: fix use-after-free in taprio_dev_notifier Since taprio’s taprio_dev_notifier() isn’t protected by an RCU read-side critical section, a race with advance_sched() can lead to a... Read more
Affected Products : linux_kernel- Published: Jun. 30, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Race Condition
-
8.8
HIGHCVE-2025-6896
A vulnerability classified as critical has been found in D-Link DI-7300G+ 19.12.25A1. Affected is an unknown function of the file wget_test.asp. The manipulation of the argument url leads to os command injection. It is possible to launch the attack remote... Read more
- Published: Jun. 30, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6891
A vulnerability classified as critical has been found in code-projects Inventory Management System 1.0. Affected is an unknown function of the file /php_action/createUser.php. The manipulation of the argument Username leads to sql injection. It is possibl... Read more
Affected Products : inventory_management_system- Published: Jun. 30, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-6890
A vulnerability was found in code-projects Movie Ticketing System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /ticketConfirmation.php. The manipulation of the argument Date leads to sql injection. The attack ... Read more
Affected Products : movie_ticketing_system- Published: Jun. 30, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6889
A vulnerability was found in code-projects Movie Ticketing System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /logIn.php. The manipulation of the argument postName leads to sql injection. The attack can be in... Read more
Affected Products : movie_ticketing_system- Published: Jun. 30, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection