Latest CVE Feed
-
9.8
CRITICALCVE-2025-6404
A vulnerability classified as critical has been found in Campcodes Online Teacher Record Management System 1.0. Affected is an unknown function of the file /admin/search.php. The manipulation of the argument searchdata leads to sql injection. It is possib... Read more
Affected Products : online_teacher_record_management_system- Published: Jun. 21, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Injection
-
6.4
MEDIUMCVE-2025-5289
The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ and 'mode' parameters in all versions up to, and including, 1.16.15 due to insufficient input san... Read more
Affected Products : 3d_flipbook- Published: Jun. 21, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-6403
A vulnerability was found in code-projects School Fees Payment System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /student.php. The manipulation of the argument ID leads to sql injection. The attack may be in... Read more
Affected Products : school_fees_payment_system- Published: Jun. 21, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Injection
-
9.0
HIGHCVE-2025-6402
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been declared as critical. This vulnerability affects unknown code of the file /boafrm/formIpv6Setup of the component HTTP POST Request Handler. The manipulation of the argument submit... Read more
- Published: Jun. 21, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Memory Corruption
-
5.1
MEDIUMCVE-2025-6401
A vulnerability was found in TOTOLINK N300RH 6.1c.1390_B20191101. It has been classified as problematic. This affects an unknown part of the file /boafrm/formFilter of the component HTTP POST Message Handler. The manipulation of the argument url leads to ... Read more
- Published: Jun. 21, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Denial of Service
-
6.4
MEDIUMCVE-2025-5143
The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's tableon_popup_iframe_button shortcode in all versions up to, and including, 1.0.4.1 due to insufficient input sanitization an... Read more
Affected Products : tableon_-_wordpress_posts_table_filterable- Published: Jun. 21, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Cross-Site Scripting
-
9.0
HIGHCVE-2025-6400
A vulnerability was found in TOTOLINK N300RH 6.1c.1390_B20191101 and classified as critical. Affected by this issue is some unknown functionality of the file /boafrm/formPortFw of the component HTTP POST Message Handler. The manipulation of the argument s... Read more
- Published: Jun. 21, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Memory Corruption
-
7.1
HIGHCVE-2025-5034
The wp-file-download WordPress plugin before 6.2.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting... Read more
Affected Products : wp_file_download- Published: Jun. 21, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Cross-Site Scripting
-
9.0
HIGHCVE-2025-6399
A vulnerability, which was classified as critical, was found in TOTOLINK X15 1.0.0-B20230714.1105. Affected is an unknown function of the file /boafrm/formIPv6Addr of the component HTTP POST Request Handler. The manipulation of the argument submit-url lea... Read more
- Published: Jun. 21, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-52552
FastGPT is an AI Agent building platform. Prior to version 4.9.12, the LastRoute Parameter on login page is vulnerable to open redirect and DOM-based XSS. Improper validation and lack of sanitization of this parameter allows attackers execute malicious Ja... Read more
Affected Products :- Published: Jun. 21, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Cross-Site Scripting
-
8.6
HIGHCVE-2025-52488
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted series of malicious interaction to potentially expose NTLM hashes to ... Read more
Affected Products : dotnetnuke- Published: Jun. 21, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Information Disclosure
-
8.8
HIGHCVE-2025-52487
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 7.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted request or proxy to be created that could bypass the design of DNN Lo... Read more
Affected Products : dotnetnuke- Published: Jun. 21, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2025-52486
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows specially crafted content in URLs to be used with TokenReplace and not be properly saniti... Read more
Affected Products : dotnetnuke- Published: Jun. 21, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Information Disclosure
-
5.1
MEDIUMCVE-2025-52485
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted request to inject scripts in the Activity Feed Attachments endpoint w... Read more
Affected Products : dotnetnuke- Published: Jun. 21, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-6394
A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /add_reserve.php. The manipulation of the argument firstname le... Read more
- Published: Jun. 21, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Injection
-
8.6
HIGHCVE-2025-52557
Mail-0's Zero is an open-source email solution. In version 0.8 it's possible for an attacker to craft an email that executes javascript leading to session hijacking due to improper sanitization. This issue has been patched in version 0.81.... Read more
Affected Products :- Published: Jun. 21, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Cross-Site Scripting
-
9.3
CRITICALCVE-2025-52556
rfc3161-client is a Python library implementing the Time-Stamp Protocol (TSP) described in RFC 3161. Prior to version 1.0.3, there is a flaw in the timestamp response signature verification logic. In particular, chain verification is performed against the... Read more
Affected Products :- Published: Jun. 21, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Cryptography
-
9.0
HIGHCVE-2025-6393
A vulnerability was found in TOTOLINK A702R, A3002R, A3002RU and EX1200T 3.0.0-B20230809.1615/4.0.0-B20230531.1404/4.0.0-B20230721.1521/4.1.2cu.5232_B20210713. It has been classified as critical. Affected is an unknown function of the file /boafrm/formIPv... Read more
Affected Products : a3002r_firmware ex1200t_firmware a3002ru_firmware a702r_firmware a3002r a3002ru a702r ex1200t- Published: Jun. 21, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Memory Corruption
-
4.8
MEDIUMCVE-2025-6375
A vulnerability was found in poco up to 1.14.1. It has been rated as problematic. Affected by this issue is the function MultipartInputStream of the file Net/src/MultipartReader.cpp. The manipulation leads to null pointer dereference. The attack needs to ... Read more
Affected Products :- Published: Jun. 21, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-6374
A vulnerability was found in D-Link DIR-619L 2.06B01 and classified as critical. This issue affects the function formSetACLFilter of the file /goform/formSetACLFilter. The manipulation of the argument curTime leads to stack-based buffer overflow. The atta... Read more
- Published: Jun. 21, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Memory Corruption