Latest CVE Feed
-
9.8
CRITICALCVE-2025-6450
A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/confirm_reserve.php. The manipulation of the argument transaction_id leads to sql in... Read more
- Published: Jun. 22, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6449
A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/checkout_query.php. The manipulation of the argument transaction_id l... Read more
- Published: Jun. 22, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Injection
-
4.3
MEDIUMCVE-2025-52923
Sangfor aTrust through 2.4.10 allows users to modify the ExecStartPre command.... Read more
Affected Products : atrust- Published: Jun. 22, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-6448
A vulnerability has been found in code-projects Simple Online Hotel Reservation System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/delete_room.php. The manipulation of the argument room_id ... Read more
- Published: Jun. 22, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6447
A vulnerability, which was classified as critical, was found in code-projects Simple Online Hotel Reservation System 1.0. Affected is an unknown function of the file /admin/index.php. The manipulation of the argument Username leads to sql injection. It is... Read more
- Published: Jun. 22, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6446
A vulnerability, which was classified as critical, has been found in code-projects Client Details System 1.0. This issue affects some unknown processing of the file /clientdetails/admin/index.php. The manipulation of the argument Username leads to sql inj... Read more
Affected Products : client_details_system- Published: Jun. 21, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-6422
A vulnerability classified as critical was found in Campcodes Online Recruitment Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=save_settings of the component About Content Page. The ma... Read more
Affected Products : online_recruitment_management_system- Published: Jun. 21, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Misconfiguration
-
4.3
MEDIUMCVE-2025-52919
In Yealink RPS before 2025-05-26, the certificate upload function does not properly validate certificate content, potentially allowing invalid certificates to be uploaded.... Read more
Affected Products :- Published: Jun. 21, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Misconfiguration
-
5.0
MEDIUMCVE-2025-52918
Yealink RPS before 2025-05-26 does not prevent OpenAPI access by frozen enterprise accounts, allowing unauthorized access to deactivated interfaces.... Read more
Affected Products :- Published: Jun. 21, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Authentication
-
4.3
MEDIUMCVE-2025-52917
The Yealink RPS API before 2025-05-26 lacks rate limiting, potentially enabling information disclosure via excessive requests.... Read more
Affected Products :- Published: Jun. 21, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Information Disclosure
-
2.2
LOWCVE-2025-52916
Yealink RPS before 2025-06-04 lacks SN verification attempt limits, enabling brute-force enumeration (last five digits).... Read more
Affected Products :- Published: Jun. 21, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-6421
A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/add_account.php. The manipulation of the argument name/admin_id leads to sq... Read more
- Published: Jun. 21, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6420
A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/add_room.php. The manipulation of the argument room_type leads to sql injec... Read more
- Published: Jun. 21, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2025-1987
A Cross-Site Scripting (XSS) vulnerability has been identified in Psono-Client’s handling of vault entries of type website_password and bookmark, as used in Bitdefender SecurePass. The client does not properly sanitize the URL field in these entries. As a... Read more
- Published: Jun. 21, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-6419
A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/edit_room.php. The manipulation of the argument room_type leads to sql injection. It... Read more
- Published: Jun. 21, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6418
A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/edit_query_account.php. The manipulation of the argument Name leads t... Read more
- Published: Jun. 21, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-6417
A vulnerability has been found in PHPGurukul Art Gallery Management System 1.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/add-artist.php. The manipulation of the argument awarddetails leads to... Read more
Affected Products : art_gallery_management_system- Published: Jun. 21, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-6416
A vulnerability, which was classified as critical, was found in PHPGurukul Art Gallery Management System 1.1. Affected is an unknown function of the file /admin/changeimage4.php. The manipulation of the argument editid leads to sql injection. It is possib... Read more
Affected Products : art_gallery_management_system- Published: Jun. 21, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-6415
A vulnerability, which was classified as critical, has been found in PHPGurukul Art Gallery Management System 1.1. This issue affects some unknown processing of the file /admin/changeimage3.php. The manipulation of the argument editid leads to sql injecti... Read more
Affected Products : art_gallery_management_system- Published: Jun. 21, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-6414
A vulnerability classified as critical was found in PHPGurukul Art Gallery Management System 1.1. This vulnerability affects unknown code of the file /admin/changeimage2.php. The manipulation of the argument editid leads to sql injection. The attack can b... Read more
Affected Products : art_gallery_management_system- Published: Jun. 21, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Injection