Latest CVE Feed
-
8.8
HIGHCVE-2025-52487
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 7.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted request or proxy to be created that could bypass the design of DNN Lo... Read more
Affected Products : dotnetnuke- Published: Jun. 21, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2025-52486
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows specially crafted content in URLs to be used with TokenReplace and not be properly saniti... Read more
Affected Products : dotnetnuke- Published: Jun. 21, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Information Disclosure
-
5.1
MEDIUMCVE-2025-52485
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted request to inject scripts in the Activity Feed Attachments endpoint w... Read more
Affected Products : dotnetnuke- Published: Jun. 21, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-6394
A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /add_reserve.php. The manipulation of the argument firstname le... Read more
- Published: Jun. 21, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Injection
-
8.6
HIGHCVE-2025-52557
Mail-0's Zero is an open-source email solution. In version 0.8 it's possible for an attacker to craft an email that executes javascript leading to session hijacking due to improper sanitization. This issue has been patched in version 0.81.... Read more
Affected Products :- Published: Jun. 21, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Cross-Site Scripting
-
9.3
CRITICALCVE-2025-52556
rfc3161-client is a Python library implementing the Time-Stamp Protocol (TSP) described in RFC 3161. Prior to version 1.0.3, there is a flaw in the timestamp response signature verification logic. In particular, chain verification is performed against the... Read more
Affected Products :- Published: Jun. 21, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Cryptography
-
9.0
HIGHCVE-2025-6393
A vulnerability was found in TOTOLINK A702R, A3002R, A3002RU and EX1200T 3.0.0-B20230809.1615/4.0.0-B20230531.1404/4.0.0-B20230721.1521/4.1.2cu.5232_B20210713. It has been classified as critical. Affected is an unknown function of the file /boafrm/formIPv... Read more
Affected Products : a3002r_firmware ex1200t_firmware a3002ru_firmware a702r_firmware a3002r a3002ru a702r ex1200t- Published: Jun. 21, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Memory Corruption
-
4.8
MEDIUMCVE-2025-6375
A vulnerability was found in poco up to 1.14.1. It has been rated as problematic. Affected by this issue is the function MultipartInputStream of the file Net/src/MultipartReader.cpp. The manipulation leads to null pointer dereference. The attack needs to ... Read more
Affected Products :- Published: Jun. 21, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-6374
A vulnerability was found in D-Link DIR-619L 2.06B01 and classified as critical. This issue affects the function formSetACLFilter of the file /goform/formSetACLFilter. The manipulation of the argument curTime leads to stack-based buffer overflow. The atta... Read more
- Published: Jun. 21, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-6218
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerability in that the ... Read more
- Published: Jun. 21, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Path Traversal
-
3.8
LOWCVE-2025-6217
PEAK-System Driver PCANFD_ADD_FILTERS Time-Of-Check Time-Of-Use Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of PEAK-System Driver. An attacker must first obtai... Read more
Affected Products : device_driver- Published: Jun. 21, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-6216
Allegra calculateTokenExpDate Password Recovery Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Allegra. Authentication is not required to exploit this vulnerability. T... Read more
Affected Products : allegra- Published: Jun. 21, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2025-5820
Sony XAV-AX8500 Bluetooth ERTM Channel Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected Sony XAV-AX8500 devices. Authentication is not required to exploit this vulnerability. T... Read more
- Published: Jun. 21, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-5479
Sony XAV-AX8500 Bluetooth AVCTP Protocol Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-AX8500 devices. An attacker must ... Read more
- Published: Jun. 21, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-5478
Sony XAV-AX8500 Bluetooth SDP Protocol Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-AX8500 devices. Authentication is not require... Read more
- Published: Jun. 21, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-5477
Sony XAV-AX8500 Bluetooth L2CAP Protocol Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Sony XAV-AX8500 devices. An attacker must first obtain the ... Read more
- Published: Jun. 21, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-5476
Sony XAV-AX8500 Bluetooth Improper Isolation Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected Sony XAV-AX8500 devices. Authentication is not required to exploit this vulnerabili... Read more
- Published: Jun. 21, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-5475
Sony XAV-AX8500 Bluetooth Packet Handling Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Sony XAV-AX8500 devices. An attacker must first obtain the ability t... Read more
- Published: Jun. 21, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-6373
A vulnerability has been found in D-Link DIR-619L 2.06B01 and classified as critical. This vulnerability affects the function formSetWizard1 of the file /goform/formWlSiteSurvey. The manipulation of the argument curTime leads to stack-based buffer overflo... Read more
- Published: Jun. 21, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-6372
A vulnerability, which was classified as critical, was found in D-Link DIR-619L 2.06B01. This affects the function formSetWizard1 of the file /goform/formSetWizard1. The manipulation of the argument curTime leads to stack-based buffer overflow. It is poss... Read more
- Published: Jun. 20, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Memory Corruption