Latest CVE Feed
-
9.8
CRITICALCVE-2025-5675
A vulnerability was found in Campcodes Online Teacher Record Management System 1.0. It has been classified as critical. This affects an unknown part of the file /trms/admin/bwdates-reports-details.php. The manipulation of the argument fromdate/todate lead... Read more
Affected Products : online_teacher_record_management_system- Published: Jun. 05, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-5674
A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file urinalysis_form.php. The manipulation of the argument urinalysis_id leads to sql i... Read more
- Published: Jun. 05, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Injection
-
9.0
HIGHCVE-2025-5672
A vulnerability has been found in TOTOLINK N302R Plus up to 3.4.0-B20201028 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formFilter of the component HTTP POST Request Handler. The manipulation ... Read more
- Published: Jun. 05, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-5671
A vulnerability, which was classified as critical, was found in TOTOLINK N302R Plus up to 3.4.0-B20201028. Affected is an unknown function of the file /boafrm/formPortFw of the component HTTP POST Request Handler. The manipulation of the argument service_... Read more
- Published: Jun. 05, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Memory Corruption
-
5.4
MEDIUMCVE-2025-46258
Missing Authorization vulnerability in BdThemes Element Pack Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Element Pack Pro: from n/a before 8.0.0.... Read more
Affected Products : element_pack- Published: Jun. 05, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-46257
Cross-Site Request Forgery (CSRF) vulnerability in BdThemes Element Pack Pro allows Cross Site Request Forgery.This issue affects Element Pack Pro: from n/a before 8.0.0.... Read more
Affected Products : element_pack- Published: Jun. 05, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Cross-Site Request Forgery
-
8.8
HIGHCVE-2025-5670
A vulnerability, which was classified as critical, has been found in PHPGurukul Medical Card Generation System 1.0. This issue affects some unknown processing of the file /admin/manage-card.php. The manipulation of the argument ID leads to sql injection. ... Read more
Affected Products : medical_card_generation_system- Published: Jun. 05, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-5669
A vulnerability classified as critical was found in PHPGurukul Medical Card Generation System 1.0. This vulnerability affects unknown code of the file /admin/unreadenq.php. The manipulation of the argument ID leads to sql injection. The attack can be init... Read more
Affected Products : medical_card_generation_system- Published: Jun. 05, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-5668
A vulnerability classified as critical has been found in PHPGurukul Medical Card Generation System 1.0. This affects an unknown part of the file /admin/readenq.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the... Read more
Affected Products : medical_card_generation_system- Published: Jun. 05, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Injection
-
6.2
MEDIUMCVE-2025-49009
Para is a multitenant backend server/framework for object persistence and retrieval. A vulnerability that exists in versions prior to 1.50.8 in `FacebookAuthFilter.java` results in a full request URL being logged during a failed request to a Facebook user... Read more
Affected Products : para- Published: Jun. 05, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Information Disclosure
-
5.1
MEDIUMCVE-2025-48493
The Yii 2 Redis extension provides the redis key-value store support for the Yii framework 2.0. On failing connection, the extension writes commands sequence to logs. Prior to version 2.0.20, AUTH parameters are written in plain text exposing username and... Read more
Affected Products :- Published: Jun. 05, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Cryptography
-
9.8
CRITICALCVE-2025-5667
A vulnerability was found in FreeFloat FTP Server 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the component REIN Command Handler. The manipulation leads to buffer overflow. The attack may be launched remotel... Read more
- Published: Jun. 05, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-5666
A vulnerability was found in FreeFloat FTP Server 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component XMKD Command Handler. The manipulation leads to buffer overflow. The attack can be launche... Read more
- Published: Jun. 05, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-5665
A vulnerability was found in FreeFloat FTP Server 1.0. It has been classified as critical. Affected is an unknown function of the component XCWD Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The ... Read more
- Published: Jun. 05, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-5664
A vulnerability was found in FreeFloat FTP Server 1.0 and classified as critical. This issue affects some unknown processing of the component RESTART Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exp... Read more
- Published: Jun. 05, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-5663
A vulnerability has been found in PHPGurukul Auto Taxi Stand Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/search-autoortaxi.php. The manipulation of the argument searchdata leads to sql injec... Read more
Affected Products : auto\/taxi_stand_management_system- Published: Jun. 05, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2025-5661
A vulnerability, which was classified as problematic, was found in code-projects Traffic Offense Reporting System 1.0. This affects an unknown part of the file /save-settings.php of the component Setting Handler. The manipulation of the argument site_name... Read more
Affected Products : traffic_offense_reporting_system- Published: Jun. 05, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Cross-Site Scripting
-
6.8
MEDIUMCVE-2025-5382
Improper access control in users MFA feature in Devolutions Server 2025.1.7.0 and earlier allows a user with user management permission to remove or change administrators MFA.... Read more
Affected Products : devolutions_server- Published: Jun. 05, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Authorization
-
8.4
HIGHCVE-2025-47827
In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image.... Read more
Affected Products :- Published: Jun. 05, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Cryptography
-
5.0
MEDIUMCVE-2025-3768
Improper access control in Tor network blocking feature in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the tor blocking feature when the Devolutions hosted endpoint is not reachable.... Read more
Affected Products : devolutions_server- Published: Jun. 05, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Authorization