Latest CVE Feed
-
8.8
HIGHCVE-2025-6411
A vulnerability was found in PHPGurukul Art Gallery Management System 1.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/changepropic.php. The manipulation of the argument imageid leads to ... Read more
Affected Products : art_gallery_management_system- Published: Jun. 21, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-6410
A vulnerability was found in PHPGurukul Art Gallery Management System 1.1. It has been classified as critical. Affected is an unknown function of the file /admin/edit-art-medium-detail.php. The manipulation of the argument editid leads to sql injection. I... Read more
Affected Products : art_gallery_management_system- Published: Jun. 21, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6409
A vulnerability was found in PHPGurukul Art Gallery Management System 1.1 and classified as critical. This issue affects some unknown processing of the file /admin/forgot-password.php. The manipulation of the argument email leads to sql injection. The att... Read more
Affected Products : art_gallery_management_system- Published: Jun. 21, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6408
A vulnerability has been found in Campcodes Online Hospital Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /doctor/search.php. The manipulation of the argument searchdata leads to sql injection. The a... Read more
Affected Products : online_hospital_management_system- Published: Jun. 21, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6407
A vulnerability, which was classified as critical, was found in Campcodes Online Hospital Management System 1.0. This affects an unknown part of the file /user-login.php. The manipulation of the argument Username leads to sql injection. It is possible to ... Read more
Affected Products : online_hospital_management_system- Published: Jun. 21, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6406
A vulnerability, which was classified as critical, has been found in Campcodes Online Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /hms/forgot-password.php. The manipulation of the argument fullname lead... Read more
Affected Products : online_hospital_management_system- Published: Jun. 21, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6405
A vulnerability classified as critical was found in Campcodes Online Teacher Record Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/edit-teacher-detail.php. The manipulation of the argument editid leads... Read more
Affected Products : online_teacher_record_management_system- Published: Jun. 21, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Injection
-
4.3
MEDIUMCVE-2025-3629
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an authenticated user to delete another user's comments due to improper ownership management.... Read more
- Published: Jun. 21, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-3221
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.... Read more
- Published: Jun. 21, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Denial of Service
-
8.2
HIGHCVE-2025-36016
IBM Process Mining 2.0.1 IF001 and 2.0.1 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof th... Read more
Affected Products : process_mining- Published: Jun. 21, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-6404
A vulnerability classified as critical has been found in Campcodes Online Teacher Record Management System 1.0. Affected is an unknown function of the file /admin/search.php. The manipulation of the argument searchdata leads to sql injection. It is possib... Read more
Affected Products : online_teacher_record_management_system- Published: Jun. 21, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Injection
-
6.4
MEDIUMCVE-2025-5289
The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ and 'mode' parameters in all versions up to, and including, 1.16.15 due to insufficient input san... Read more
Affected Products : 3d_flipbook- Published: Jun. 21, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-6403
A vulnerability was found in code-projects School Fees Payment System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /student.php. The manipulation of the argument ID leads to sql injection. The attack may be in... Read more
Affected Products : school_fees_payment_system- Published: Jun. 21, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Injection
-
9.0
HIGHCVE-2025-6402
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been declared as critical. This vulnerability affects unknown code of the file /boafrm/formIpv6Setup of the component HTTP POST Request Handler. The manipulation of the argument submit... Read more
- Published: Jun. 21, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Memory Corruption
-
5.1
MEDIUMCVE-2025-6401
A vulnerability was found in TOTOLINK N300RH 6.1c.1390_B20191101. It has been classified as problematic. This affects an unknown part of the file /boafrm/formFilter of the component HTTP POST Message Handler. The manipulation of the argument url leads to ... Read more
- Published: Jun. 21, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Denial of Service
-
6.4
MEDIUMCVE-2025-5143
The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's tableon_popup_iframe_button shortcode in all versions up to, and including, 1.0.4.1 due to insufficient input sanitization an... Read more
Affected Products : tableon_-_wordpress_posts_table_filterable- Published: Jun. 21, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Cross-Site Scripting
-
9.0
HIGHCVE-2025-6400
A vulnerability was found in TOTOLINK N300RH 6.1c.1390_B20191101 and classified as critical. Affected by this issue is some unknown functionality of the file /boafrm/formPortFw of the component HTTP POST Message Handler. The manipulation of the argument s... Read more
- Published: Jun. 21, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Memory Corruption
-
7.1
HIGHCVE-2025-5034
The wp-file-download WordPress plugin before 6.2.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting... Read more
Affected Products : wp_file_download- Published: Jun. 21, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Cross-Site Scripting
-
9.0
HIGHCVE-2025-6399
A vulnerability, which was classified as critical, was found in TOTOLINK X15 1.0.0-B20230714.1105. Affected is an unknown function of the file /boafrm/formIPv6Addr of the component HTTP POST Request Handler. The manipulation of the argument submit-url lea... Read more
- Published: Jun. 21, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-52552
FastGPT is an AI Agent building platform. Prior to version 4.9.12, the LastRoute Parameter on login page is vulnerable to open redirect and DOM-based XSS. Improper validation and lack of sanitization of this parameter allows attackers execute malicious Ja... Read more
Affected Products :- Published: Jun. 21, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Cross-Site Scripting