Latest CVE Feed
-
5.3
MEDIUMCVE-2025-27587
OpenSSL 3.0.0 through 3.3.2 on the PowerPC architecture is vulnerable to a Minerva attack, exploitable by measuring the time of signing of random messages using the EVP_DigestSign API, and then using the private key to extract the K value (nonce) from the... Read more
Affected Products :- Published: Jun. 16, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Cryptography
-
3.9
LOWCVE-2025-6139
A vulnerability, which was classified as problematic, has been found in TOTOLINK T10 4.1.8cu.5207. Affected by this issue is some unknown functionality of the file /etc/shadow.sample. The manipulation leads to use of hard-coded password. The attack can on... Read more
- Published: Jun. 16, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Authentication
-
9.0
HIGHCVE-2025-6138
A vulnerability classified as critical was found in TOTOLINK T10 4.1.8cu.5207. Affected by this vulnerability is the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request Handler. The manipulation of the argument ssid5g... Read more
- Published: Jun. 16, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Memory Corruption
-
5.3
MEDIUMCVE-2025-49134
Weblate is a web based localization tool. Prior to version 5.12, the audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as SMTP relays, or spam filters. This issue has been patched i... Read more
Affected Products : weblate- Published: Jun. 16, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Information Disclosure
-
4.9
MEDIUMCVE-2025-47951
Weblate is a web based localization tool. Prior to version 5.12, the verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP g... Read more
Affected Products : weblate- Published: Jun. 16, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-32800
Conda-build contains commands and tools to build conda packages. Prior to version 25.3.0, the pyproject.toml lists conda-index as a Python dependency. This package is not published in PyPI. An attacker could claim this namespace and upload arbitrary (mali... Read more
Affected Products : conda-build- Published: Jun. 16, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Supply Chain
-
9.8
CRITICALCVE-2025-32799
Conda-build contains commands and tools to build conda packages. Prior to version 25.4.0, the conda-build processing logic is vulnerable to path traversal (Tarslip) attacks due to improper sanitization of tar entry paths. Attackers can craft tar archives ... Read more
Affected Products : conda-build- Published: Jun. 16, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Path Traversal
-
9.0
HIGHCVE-2025-6137
A vulnerability classified as critical has been found in TOTOLINK T10 4.1.8cu.5207. Affected is the function setWiFiScheduleCfg of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request Handler. The manipulation of the argument desc leads to buf... Read more
- Published: Jun. 16, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-6136
A vulnerability was found in Projectworlds Life Insurance Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /insertPayment.php. The manipulation of the argument recipt_no leads to sql injection. T... Read more
Affected Products : life_insurance_management_system- Published: Jun. 16, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-32798
Conda-build contains commands and tools to build conda packages. Prior to version 25.4.0, the conda-build recipe processing logic has been found to be vulnerable to arbitrary code execution due to unsafe evaluation of recipe selectors. Currently, conda-bu... Read more
Affected Products : conda-build- Published: Jun. 16, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6135
A vulnerability was found in Projectworlds Life Insurance Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /insertNominee.php. The manipulation of the argument client_id/nominee_id leads to sql i... Read more
Affected Products : life_insurance_management_system- Published: Jun. 16, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6134
A vulnerability was found in Projectworlds Life Insurance Management System 1.0. It has been classified as critical. This affects an unknown part of the file /insertClient.php. The manipulation of the argument client_id leads to sql injection. It is possi... Read more
Affected Products : life_insurance_management_system- Published: Jun. 16, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection
-
9.1
CRITICALCVE-2025-6087
A Server-Side Request Forgery (SSRF) vulnerability was identified in the @opennextjs/cloudflare package. The vulnerability stems from an unimplemented feature in the Cloudflare adapter for Open Next, which allowed unauthenticated users to proxy arbitrary ... Read more
- Published: Jun. 16, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Server-Side Request Forgery
-
7.0
HIGHCVE-2025-32797
Conda-build contains commands and tools to build conda packages. Prior to version 25.3.1, The write_build_scripts function in conda-build creates the temporary build script conda_build.sh with overly permissive file permissions (0o766), allowing write acc... Read more
Affected Products : conda-build- Published: Jun. 16, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Race Condition
-
9.8
CRITICALCVE-2025-6133
A vulnerability was found in Projectworlds Life Insurance Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /insertagent.php. The manipulation of the argument agent_id leads to sql injection... Read more
Affected Products : life_insurance_management_system- Published: Jun. 16, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-6132
A vulnerability has been found in Chanjet CRM 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /sysconfig/departmentsetting.php. The manipulation of the argument gblOrgID leads to sql injection. The at... Read more
Affected Products : chanjet_cms- Published: Jun. 16, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6179
Permissions Bypass in Extension Management in Google ChromeOS 16181.27.0 on managed Chrome devices allows a local attacker to disable extensions and access Developer Mode, including loading additional extensions via exploiting vulnerabilities usin... Read more
Affected Products : chrome_os- Published: Jun. 16, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Authorization
-
7.4
HIGHCVE-2025-6177
Privilege Escalation in MiniOS in Google ChromeOS (16063.45.2 and potentially others) on enrolled devices allows a local attacker to gain root code execution via exploiting a debug shell (VT3 console) accessible through specific key combinations during de... Read more
Affected Products : chrome_os- Published: Jun. 16, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Authorization
-
4.8
MEDIUMCVE-2025-6131
A vulnerability, which was classified as problematic, was found in CodeAstro Food Ordering System 1.0. Affected is an unknown function of the file /admin/store/edit/ of the component POST Request Parameter Handler. The manipulation of the argument Restaur... Read more
Affected Products : food_ordering_system- Published: Jun. 16, 2025
- Modified: Jul. 18, 2025
- Vuln Type: Cross-Site Scripting
-
9.0
HIGHCVE-2025-6130
A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This issue affects some unknown processing of the file /boafrm/formStats of the component HTTP POST Request Handler. The manipulation leads to bu... Read more
- Published: Jun. 16, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Memory Corruption