Latest CVE Feed
-
5.5
MEDIUMCVE-2025-6492
A vulnerability has been found in MarkText up to 0.17.1 and classified as problematic. Affected by this vulnerability is the function getRecommendTitleFromMarkdownString of the file marktext/src/main/utils/index.js. The manipulation leads to inefficient r... Read more
Affected Products : marktext- Published: Jun. 22, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Denial of Service
-
4.8
MEDIUMCVE-2025-6490
A vulnerability was found in sparklemotion nokogiri c29c920907366cb74af13b4dc2230e9c9e23b833 and classified as problematic. This issue affects the function hashmap_set_with_hash of the file gumbo-parser/src/hashmap.c. The manipulation leads to heap-based ... Read more
Affected Products : nokogiri- Published: Jun. 22, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-6489
A vulnerability has been found in itsourcecode Agri-Trading Online Shopping System 1.0 and classified as critical. This vulnerability affects unknown code of the file /transactionsave.php. The manipulation of the argument del leads to sql injection. The a... Read more
Affected Products : agri-trading_online_shopping_system- Published: Jun. 22, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Injection
-
9.0
HIGHCVE-2025-6487
A vulnerability was found in TOTOLINK A3002R 1.1.1-B20200824.0128. It has been rated as critical. This issue affects the function formRoute of the file /boafrm/formRoute. The manipulation of the argument subnet leads to stack-based buffer overflow. The at... Read more
- Published: Jun. 22, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-6486
A vulnerability was found in TOTOLINK A3002R 1.1.1-B20200824.0128. It has been declared as critical. This vulnerability affects the function formWlanMultipleAP of the file /boafrm/formWlanMultipleAP. The manipulation of the argument submit-url leads to st... Read more
- Published: Jun. 22, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2025-6485
A vulnerability was found in TOTOLINK A3002R 1.1.1-B20200824.0128. It has been classified as critical. This affects the function formWlSiteSurvey of the file /boafrm/formWlSiteSurvey. The manipulation of the argument wlanif leads to os command injection. ... Read more
- Published: Jun. 22, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Injection
-
7.2
HIGHCVE-2025-6484
A vulnerability was found in code-projects Online Shopping Store 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /action.php. The manipulation of the argument cat_id/brand_id/keyword/proId/pid leads to sql ... Read more
Affected Products : online_shopping_store- Published: Jun. 22, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6483
A vulnerability has been found in code-projects Simple Pizza Ordering System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /edituser.php. The manipulation of the argument ID leads to sql injection. ... Read more
Affected Products : simple_pizza_ordering_system- Published: Jun. 22, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6482
A vulnerability, which was classified as critical, was found in code-projects Simple Pizza Ordering System 1.0. Affected is an unknown function of the file /edituser-exec.php. The manipulation of the argument userid leads to sql injection. It is possible ... Read more
Affected Products : simple_pizza_ordering_system- Published: Jun. 22, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6481
A vulnerability, which was classified as critical, has been found in code-projects Simple Pizza Ordering System 1.0. This issue affects some unknown processing of the file /update.php. The manipulation of the argument ID leads to sql injection. The attack... Read more
Affected Products : simple_pizza_ordering_system- Published: Jun. 22, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6480
A vulnerability classified as critical was found in code-projects Simple Pizza Ordering System 1.0. This vulnerability affects unknown code of the file /addcatexec.php. The manipulation of the argument textfield leads to sql injection. The attack can be i... Read more
Affected Products : simple_pizza_ordering_system- Published: Jun. 22, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6479
A vulnerability classified as critical has been found in code-projects Simple Pizza Ordering System 1.0. This affects an unknown part of the file /salesreport.php. The manipulation of the argument dayfrom leads to sql injection. It is possible to initiate... Read more
Affected Products : simple_pizza_ordering_system- Published: Jun. 22, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2025-6478
A vulnerability was found in CodeAstro Expense Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack may be launched remotely.... Read more
- Published: Jun. 22, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.8
MEDIUMCVE-2025-6477
A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /script/admin/system of the component System Settings Page. The m... Read more
Affected Products : student_result_management_system- Published: Jun. 22, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2025-6476
A vulnerability was found in SourceCodester Gym Management System 1.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit ... Read more
Affected Products : gym_management_system- Published: Jun. 22, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.8
MEDIUMCVE-2025-6475
A vulnerability was found in SourceCodester Student Result Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /script/admin/manage_students of the component Manage Students Module. The manipulation ... Read more
Affected Products : student_result_management_system- Published: Jun. 22, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-6474
A vulnerability has been found in code-projects Inventory Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /changeUsername.php. The manipulation of the argument user_id leads to sql injection. The attac... Read more
Affected Products : inventory_management_system- Published: Jun. 22, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-6473
A vulnerability, which was classified as problematic, was found in code-projects School Fees Payment System 1.0. This affects an unknown part of the file /fees.php. The manipulation of the argument transcation_remark leads to cross site scripting. It is p... Read more
Affected Products : school_fees_payment_system- Published: Jun. 22, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-6472
A vulnerability, which was classified as critical, has been found in code-projects Online Bidding System 1.0. Affected by this issue is some unknown functionality of the file /showprod.php. The manipulation of the argument ID leads to sql injection. The a... Read more
Affected Products : online_bidding_system- Published: Jun. 22, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6471
A vulnerability classified as critical was found in code-projects Online Bidding System 1.0. Affected by this vulnerability is an unknown functionality of the file /administrator. The manipulation of the argument aduser leads to sql injection. The attack ... Read more
Affected Products : online_bidding_system- Published: Jun. 22, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Injection