Latest CVE Feed
-
8.8
HIGHCVE-2025-6875
A vulnerability has been found in SourceCodester Best Salon Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /panel/edit-subscription.php. The manipulation of the argument editid lead... Read more
Affected Products : best_salon_management_system- Published: Jun. 29, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-6874
A vulnerability, which was classified as critical, was found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the file /panel/add_subscribe.php. The manipulation of the argument user_id/plan_id leads to sql injection.... Read more
Affected Products : best_salon_management_system- Published: Jun. 29, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Injection
-
7.2
HIGHCVE-2025-6873
A vulnerability, which was classified as critical, has been found in SourceCodester Simple Company Website 1.0. This issue affects some unknown processing of the file /classes/Users.php?f=save. The manipulation of the argument img leads to unrestricted up... Read more
Affected Products : simple_company_website- Published: Jun. 29, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Authentication
-
7.2
HIGHCVE-2025-6872
A vulnerability classified as critical was found in SourceCodester Simple Company Website 1.0. This vulnerability affects unknown code of the file /classes/SystemSettings.php?f=update_settings. The manipulation of the argument img leads to unrestricted up... Read more
Affected Products : simple_company_website- Published: Jun. 29, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-6871
A vulnerability classified as critical has been found in SourceCodester Simple Company Website 1.0. This affects an unknown part of the file /classes/Login.php. The manipulation of the argument Username leads to sql injection. It is possible to initiate t... Read more
Affected Products : simple_company_website- Published: Jun. 29, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Injection
-
3.4
LOWCVE-2015-20112
RLPx 5 has two CTR streams based on the same key, IV, and nonce. This can facilitate decryption on a private network.... Read more
Affected Products :- Published: Jun. 29, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Cryptography
-
5.8
MEDIUMCVE-2025-6870
A vulnerability was found in SourceCodester Simple Company Website 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /classes/Content.php?f=service. The manipulation of the argument img leads to unrestric... Read more
Affected Products : simple_company_website- Published: Jun. 29, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Misconfiguration
-
7.2
HIGHCVE-2025-6869
A vulnerability was found in SourceCodester Simple Company Website 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/testimonials/manage.php. The manipulation of the argument ID leads to s... Read more
Affected Products : simple_company_website- Published: Jun. 29, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
6.8
MEDIUMCVE-2025-24292
A misconfigured query in UniFi Network (v9.1.120 and earlier) could allow users to authenticate to Enterprise WiFi or VPN Server (l2tp and OpenVPN) using a device’s MAC address from 802.1X or MAC Authentication, if both services are enabled and share the... Read more
Affected Products : unifi_network_application- Published: Jun. 29, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Authentication
-
9.9
CRITICALCVE-2025-24290
Multiple Authenticated SQL Injection vulnerabilities found in UISP Application (Version 2.4.206 and earlier) could allow a malicious actor with low privileges to escalate privileges.... Read more
Affected Products :- Published: Jun. 29, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-24289
A Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) vulnerability in the UCRM Client Signup Plugin (v1.3.4 and earlier) could allow privilege escalation if an Administrator is tricked into visiting a crafted malicious page. The plugi... Read more
Affected Products :- Published: Jun. 29, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Cross-Site Request Forgery
-
7.2
HIGHCVE-2025-6868
A vulnerability was found in SourceCodester Simple Company Website 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/clients/manage.php. The manipulation of the argument ID leads to sql injection. It is possible t... Read more
Affected Products : simple_company_website- Published: Jun. 29, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
7.2
HIGHCVE-2025-6867
A vulnerability was found in SourceCodester Simple Company Website 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/services/manage.php. The manipulation of the argument ID leads to sql injection. The attack ma... Read more
Affected Products : simple_company_website- Published: Jun. 29, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2025-6866
A vulnerability has been found in code-projects Simple Forum 1.0 and classified as critical. This vulnerability affects unknown code of the file /forum_downloadfile.php. The manipulation of the argument filename leads to path traversal. The attack can be ... Read more
Affected Products : simple_forum- Published: Jun. 29, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Path Traversal
-
5.3
MEDIUMCVE-2025-6865
A vulnerability, which was classified as problematic, was found in DaiCuo up to 1.3.13. This affects an unknown part of the file /admin.php/addon/index. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. ... Read more
Affected Products : daicuo- Published: Jun. 29, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.3
MEDIUMCVE-2025-6864
A vulnerability, which was classified as problematic, has been found in SeaCMS up to 13.2. Affected by this issue is some unknown functionality of the file /admin_type.php. The manipulation leads to cross-site request forgery. The attack may be launched r... Read more
Affected Products : seacms- Published: Jun. 29, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Cross-Site Request Forgery
-
9.8
CRITICALCVE-2025-6863
A vulnerability classified as critical was found in PHPGurukul Local Services Search Engine Management System 2.1. Affected by this vulnerability is an unknown functionality of the file /admin/edit-category-detail.php. The manipulation of the argument edi... Read more
Affected Products : local_services_search_engine_management_system- Published: Jun. 29, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-6862
A vulnerability classified as critical has been found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the file /panel/edit_plan.php. The manipulation of the argument editid leads to sql injection. It is possible to l... Read more
Affected Products : best_salon_management_system- Published: Jun. 29, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-6861
A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /panel/add_plan.php. The manipulation of the argument plan_name/description/duration_days/p... Read more
Affected Products : best_salon_management_system- Published: Jun. 29, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-6860
A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /panel/staff_commision.php. The manipulation of the argument fromdate/todate leads to sql i... Read more
Affected Products : best_salon_management_system- Published: Jun. 29, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Injection