Latest CVE Feed
-
8.8
HIGHCVE-2025-3485
Allegra extractFileFromZip Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Authentication is required to exploit this vulnerability. The s... Read more
Affected Products : allegra- Published: Jun. 06, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Path Traversal
-
8.8
HIGHCVE-2025-2766
70mai A510 Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of 70mai A510. Authentication is not required to exploit this vulnerability. T... Read more
- Published: Jun. 06, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Authentication
-
9.0
HIGHCVE-2025-5793
A vulnerability, which was classified as critical, was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. Affected is an unknown function of the file /boafrm/formPortFw of the component HTTP POST Request Handler. The manipulation of the argument service_ty... Read more
- Published: Jun. 06, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-5792
A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This issue affects some unknown processing of the file /boafrm/formWlanRedirect of the component HTTP POST Request Handler. The manipulation of t... Read more
- Published: Jun. 06, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-5790
A vulnerability classified as critical was found in TOTOLINK X15 1.0.0-B20230714.1105. This vulnerability affects unknown code of the file /boafrm/formIpQoS of the component HTTP POST Request Handler. The manipulation of the argument mac leads to buffer o... Read more
- Published: Jun. 06, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-5789
A vulnerability classified as critical has been found in TOTOLINK X15 1.0.0-B20230714.1105. This affects an unknown part of the file /boafrm/formPortFw of the component HTTP POST Request Handler. The manipulation of the argument service_type leads to buff... Read more
- Published: Jun. 06, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Memory Corruption
-
3.7
LOWCVE-2025-49011
SpiceDB is an open source database for storing and querying fine-grained authorization data. Prior to version 1.44.2, on schemas involving arrows with caveats on the arrow’ed relation, when the path to resolve a CheckPermission request involves the evalua... Read more
Affected Products : spicedb- Published: Jun. 06, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-47950
CoreDNS is a DNS server that chains plugins. In versions prior to 1.12.2, a Denial of Service (DoS) vulnerability exists in the CoreDNS DNS-over-QUIC (DoQ) server implementation. The server previously created a new goroutine for every incoming QUIC stream... Read more
Affected Products : coredns- Published: Jun. 06, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Denial of Service
-
9.0
HIGHCVE-2025-5788
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been rated as critical. Affected by this issue is some unknown functionality of the file /boafrm/formReflashClientTbl of the component HTTP POST Request Handler. The manipulation of th... Read more
- Published: Jun. 06, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-5787
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formWsc of the component HTTP POST Request Handler. The manipulation of the ar... Read more
- Published: Jun. 06, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-5786
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been classified as critical. Affected is an unknown function of the file /boafrm/formDMZ of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads t... Read more
- Published: Jun. 06, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Memory Corruption
-
4.1
MEDIUMCVE-2025-49599
Huawei EG8141A5 devices through V5R019C00S100, EG8145V5 devices through V5R019C00S100, and EG8145V5-V2 devices through V5R021C00S184 allow the Epuser account to disable ONT firewall functionality, e.g., to remove the default blocking of the SSH and TELNET... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Misconfiguration
-
9.0
HIGHCVE-2025-5785
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105 and classified as critical. This issue affects some unknown processing of the file /boafrm/formWirelessTbl of the component HTTP POST Request Handler. The manipulation of the argument submit-u... Read more
- Published: Jun. 06, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-5784
A vulnerability has been found in PHPGurukul Employee Record Management System 1.3 and classified as critical. This vulnerability affects unknown code of the file /myexp.php. The manipulation of the argument emp3ctc leads to sql injection. The attack can ... Read more
Affected Products : employee_record_management_system- Published: Jun. 06, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-5783
A vulnerability, which was classified as critical, was found in PHPGurukul Employee Record Management System 1.3. This affects an unknown part of the file /editmyexp.php. The manipulation of the argument emp3workduration leads to sql injection. It is poss... Read more
Affected Products : employee_record_management_system- Published: Jun. 06, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Injection
-
6.8
MEDIUMCVE-2025-5751
WOLFBOX Level 2 EV Charger Management Card Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows physically present attackers to bypass authentication on affected installations of WOLFBOX Level 2 EV Charger. Authentication ... Read more
- Published: Jun. 06, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2025-5750
WOLFBOX Level 2 EV Charger tuya_svc_devos_activate_result_parse Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of WOLFBOX Level 2 EV ... Read more
- Published: Jun. 06, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-5749
WOLFBOX Level 2 EV Charger BLE Encryption Keys Uninitialized Variable Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of WOLFBOX Level 2 EV Charger devices. Authe... Read more
- Published: Jun. 06, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Authentication
-
8.0
HIGHCVE-2025-5748
WOLFBOX Level 2 EV Charger LAN OTA Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of WOLFBOX Level 2 EV Charger. Although authenticatio... Read more
- Published: Jun. 06, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Authentication
-
8.0
HIGHCVE-2025-5747
WOLFBOX Level 2 EV Charger MCU Command Parsing Misinterpretation of Input Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installatons of WOLFBOX Level 2 EV Charger devices. A... Read more
- Published: Jun. 06, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Authentication