Latest CVE Feed
-
7.5
HIGHCVE-2025-22490
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability i... Read more
Affected Products : file_station- Published: Jun. 06, 2025
- Modified: Jun. 18, 2025
- Vuln Type: Denial of Service
-
8.8
HIGHCVE-2025-22486
An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers who have gained user access to compromise the security of the system. We have already fixed the vuln... Read more
Affected Products : file_station- Published: Jun. 06, 2025
- Modified: Jun. 18, 2025
- Vuln Type: Cryptography
-
7.1
HIGHCVE-2025-22484
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from... Read more
Affected Products : file_station- Published: Jun. 06, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Denial of Service
-
2.3
LOWCVE-2025-22482
A use of externally-controlled format string vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to obtain secret data or modify memory. We have already fixed t... Read more
Affected Products : qsync_central- Published: Jun. 06, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Information Disclosure
-
8.7
HIGHCVE-2025-22481
A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to execute arbitrary commands. We have already fixed the vulner... Read more
- Published: Jun. 06, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2024-56805
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to modify memory or crash processes. We have already fixed the vu... Read more
- Published: Jun. 06, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Memory Corruption
-
2.0
LOWCVE-2024-50406
A cross-site scripting (XSS) vulnerability has been reported to affect License Center. If exploited, the vulnerability could allow remote attackers who have gained user access to bypass security mechanisms or read application data. We have already fixed ... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Cross-Site Scripting
-
5.2
MEDIUMCVE-2024-13088
An improper authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the follow... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Authentication
-
2.4
LOWCVE-2024-13087
A command injection vulnerability has been reported to affect QHora. If an attacker gains local network access who have also gained an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-5782
A vulnerability, which was classified as critical, has been found in PHPGurukul Employee Record Management System 1.3. Affected by this issue is some unknown functionality of the file /resetpassword.php. The manipulation of the argument newpassword leads ... Read more
Affected Products : employee_record_management_system- Published: Jun. 06, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-5780
A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /view_dental.php. The manipulation of the argument itr_no leads to sql injection. ... Read more
- Published: Jun. 06, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-5779
A vulnerability has been found in code-projects Patient Record Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /birthing.php. The manipulation of the argument itr_no/comp_id leads to... Read more
- Published: Jun. 06, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-41646
An unauthorized remote attacker can bypass the authentication of the affected software package by misusing an incorrect type conversion. This leads to full compromise of the device... Read more
Affected Products : revpi_status- Published: Jun. 06, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-27531
Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 before 2.1.0, this issue would allow an authenticated attacker to read arbitrary files by double writing the param. Users are recommen... Read more
Affected Products : inlong- Published: Jun. 06, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Information Disclosure
-
8.0
HIGHCVE-2025-5806
Jenkins Gatling Plugin 136.vb_9009b_3d33a_e serves Gatling reports in a manner that bypasses the Content-Security-Policy protection introduced in Jenkins 1.641 and 1.625, resulting in a cross-site scripting (XSS) vulnerability exploitable by users able to... Read more
Affected Products : gatling- Published: Jun. 06, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-5791
A flaw was found in the user's crate for Rust. This vulnerability allows privilege escalation via incorrect group listing when a user or process has fewer than exactly 1024 groups, leading to the erroneous inclusion of the root group in the access list.... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jul. 31, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-5778
A vulnerability, which was classified as critical, was found in 1000 Projects ABC Courier Management System 1.0. Affected is an unknown function of the file /admin. The manipulation of the argument Username leads to sql injection. It is possible to launch... Read more
Affected Products : abc_courier_management_system- Published: Jun. 06, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Injection
-
0.0
NACVE-2025-38002
In the Linux kernel, the following vulnerability has been resolved: io_uring/fdinfo: grab ctx->uring_lock around io_uring_show_fdinfo() Not everything requires locking in there, which is why the 'has_lock' variable exists. But enough does that it's a bi... Read more
Affected Products : linux_kernel- Published: Jun. 06, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Race Condition
-
0.0
NACVE-2025-38001
In the Linux kernel, the following vulnerability has been resolved: net_sched: hfsc: Address reentrant enqueue adding class to eltree twice Savino says: "We are writing to report that this recent patch (141d34391abbb315d68556b7c67ad97885407547) ... Read more
Affected Products : linux_kernel- Published: Jun. 06, 2025
- Modified: Jul. 13, 2025
- Vuln Type: Memory Corruption
-
6.6
MEDIUMCVE-2025-0620
A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an expired SMB session. This issue can expose file shares until clients disconnect and then connect again.... Read more
Affected Products : samba- Published: Jun. 06, 2025
- Modified: Aug. 13, 2025
- Vuln Type: Authentication