Latest CVE Feed
-
9.8
CRITICALCVE-2025-6135
A vulnerability was found in Projectworlds Life Insurance Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /insertNominee.php. The manipulation of the argument client_id/nominee_id leads to sql i... Read more
Affected Products : life_insurance_management_system- Published: Jun. 16, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6134
A vulnerability was found in Projectworlds Life Insurance Management System 1.0. It has been classified as critical. This affects an unknown part of the file /insertClient.php. The manipulation of the argument client_id leads to sql injection. It is possi... Read more
Affected Products : life_insurance_management_system- Published: Jun. 16, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection
-
9.1
CRITICALCVE-2025-6087
A Server-Side Request Forgery (SSRF) vulnerability was identified in the @opennextjs/cloudflare package. The vulnerability stems from an unimplemented feature in the Cloudflare adapter for Open Next, which allowed unauthenticated users to proxy arbitrary ... Read more
- Published: Jun. 16, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Server-Side Request Forgery
-
7.0
HIGHCVE-2025-32797
Conda-build contains commands and tools to build conda packages. Prior to version 25.3.1, The write_build_scripts function in conda-build creates the temporary build script conda_build.sh with overly permissive file permissions (0o766), allowing write acc... Read more
Affected Products : conda-build- Published: Jun. 16, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Race Condition
-
9.8
CRITICALCVE-2025-6133
A vulnerability was found in Projectworlds Life Insurance Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /insertagent.php. The manipulation of the argument agent_id leads to sql injection... Read more
Affected Products : life_insurance_management_system- Published: Jun. 16, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-6132
A vulnerability has been found in Chanjet CRM 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /sysconfig/departmentsetting.php. The manipulation of the argument gblOrgID leads to sql injection. The at... Read more
Affected Products : chanjet_cms- Published: Jun. 16, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6179
Permissions Bypass in Extension Management in Google ChromeOS 16181.27.0 on managed Chrome devices allows a local attacker to disable extensions and access Developer Mode, including loading additional extensions via exploiting vulnerabilities usin... Read more
Affected Products : chrome_os- Published: Jun. 16, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Authorization
-
7.4
HIGHCVE-2025-6177
Privilege Escalation in MiniOS in Google ChromeOS (16063.45.2 and potentially others) on enrolled devices allows a local attacker to gain root code execution via exploiting a debug shell (VT3 console) accessible through specific key combinations during de... Read more
Affected Products : chrome_os- Published: Jun. 16, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Authorization
-
4.8
MEDIUMCVE-2025-6131
A vulnerability, which was classified as problematic, was found in CodeAstro Food Ordering System 1.0. Affected is an unknown function of the file /admin/store/edit/ of the component POST Request Parameter Handler. The manipulation of the argument Restaur... Read more
Affected Products : food_ordering_system- Published: Jun. 16, 2025
- Modified: Jul. 18, 2025
- Vuln Type: Cross-Site Scripting
-
9.0
HIGHCVE-2025-6130
A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This issue affects some unknown processing of the file /boafrm/formStats of the component HTTP POST Request Handler. The manipulation leads to bu... Read more
- Published: Jun. 16, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-5309
The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which can lead to remote code execution.... Read more
- Published: Jun. 16, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Injection
-
5.1
MEDIUMCVE-2025-2327
A flaw exists in FlashArray whereby the Key Encryption Key (KEK) is logged during key rotation when RDL is configured.... Read more
Affected Products :- Published: Jun. 16, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Information Disclosure
-
2.5
LOWCVE-2025-6170
A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow atta... Read more
- Published: Jun. 16, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Denial of Service
-
9.0
HIGHCVE-2025-6129
A vulnerability classified as critical was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This vulnerability affects unknown code of the file /boafrm/formSaveConfig of the component HTTP POST Request Handler. The manipulation of the argument submit-url... Read more
- Published: Jun. 16, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-6128
A vulnerability classified as critical has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This affects an unknown part of the file /boafrm/formWirelessTbl of the component HTTP POST Request Handler. The manipulation of the argument submit-url lead... Read more
- Published: Jun. 16, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Memory Corruption
-
9.1
CRITICALCVE-2025-49796
A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial... Read more
- Published: Jun. 16, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-49795
A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions. This flaw allows an attacker to craft a malicious XML input to libxml2, leading to a denial of service.... Read more
- Published: Jun. 16, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Denial of Service
-
9.1
CRITICALCVE-2025-49794
A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the <sch:name path="..."/> schema elements. This flaw allows a malicious actor to craft a malicious ... Read more
- Published: Jun. 16, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Memory Corruption
-
5.4
MEDIUMCVE-2025-6127
A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /search-report.php. The manipulation of the argument serachdata leads to ... Read more
Affected Products : nipah_virus_testing_management_system- Published: Jun. 16, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-6126
A vulnerability was found in PHPGurukul Rail Pass Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /contact.php. The manipulation of the argument Name leads to cross site sc... Read more
Affected Products : rail_pass_management_system- Published: Jun. 16, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Cross-Site Scripting