Latest CVE Feed
-
9.8
CRITICALCVE-2025-5604
A vulnerability was found in Campcodes Hospital Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /user-login.php. The manipulation of the argument Username leads to sql injection. The attac... Read more
Affected Products : online_hospital_management_system- Published: Jun. 04, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5603
A vulnerability has been found in Campcodes Hospital Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /registration.php. The manipulation of the argument full_name/username leads to s... Read more
Affected Products : online_hospital_management_system- Published: Jun. 04, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5602
A vulnerability, which was classified as critical, was found in Campcodes Hospital Management System 1.0. Affected is an unknown function of the file /admin/registration.php. The manipulation of the argument full_name leads to sql injection. It is possibl... Read more
Affected Products : online_hospital_management_system- Published: Jun. 04, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Injection
-
10.0
HIGHCVE-2025-5600
A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This issue affects the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument LangType leads to stack-based b... Read more
- Published: Jun. 04, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-5599
A vulnerability classified as critical was found in PHPGurukul Student Result Management System 1.3. This vulnerability affects unknown code of the file /editmyexp.php. The manipulation of the argument emp1ctc leads to sql injection. The attack can be ini... Read more
Affected Products : student_result_management_system- Published: Jun. 04, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-5688
We have identified a buffer overflow issue allowing out-of-bounds write when processing LLMNR or mDNS queries with very long DNS names. This issue only affects systems using Buffer Allocation Scheme 1 with LLMNR or mDNS enabled. Users should upgrade to ... Read more
Affected Products : freertos- Published: Jun. 04, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-5596
A vulnerability was found in FreeFloat FTP Server 1.0. It has been classified as critical. Affected is an unknown function of the component REGET Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The... Read more
- Published: Jun. 04, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-5595
A vulnerability was found in FreeFloat FTP Server 1.0 and classified as critical. This issue affects some unknown processing of the component PROGRESS Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The ex... Read more
- Published: Jun. 04, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Memory Corruption
-
4.8
MEDIUMCVE-2025-2336
Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '<image>' SVG elements in AngularJS's 'ngSanitize' module allows attackers to bypass common image source restrictions. This can lead to a form of Content Spoofing https://owa... Read more
Affected Products :- Published: Jun. 04, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Cross-Site Scripting
-
9.9
CRITICALCVE-2025-20286
A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to access sensitive data, execute limited admini... Read more
Affected Products : identity_services_engine- Published: Jun. 04, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Misconfiguration
-
4.8
MEDIUMCVE-2025-20279
A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, remote attacker to conduct a stored XSS attack on an affected system. To exploit this vulnerability, the attacker must have valid administrative crede... Read more
Affected Products : unified_contact_center_express- Published: Jun. 04, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cross-Site Scripting
-
6.7
MEDIUMCVE-2025-20278
A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device as the root user. This vulnerability is due... Read more
- Published: Jun. 04, 2025
- Modified: Jul. 31, 2025
- Vuln Type: Authorization
-
6.7
MEDIUMCVE-2025-20277
A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, local attacker to execute arbitrary code on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials... Read more
Affected Products : unified_contact_center_express- Published: Jun. 04, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Path Traversal
-
7.2
HIGHCVE-2025-20276
A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, remote attacker to execute arbitrary code on an affected device. To exploit this vulnerability, the attacker must have valid administrative credential... Read more
Affected Products : unified_contact_center_express- Published: Jun. 04, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authentication
-
7.8
HIGHCVE-2025-20275
A vulnerability in the file opening process of Cisco Unified Contact Center Express (Unified CCX) Editor could allow an unauthenticated attacker to execute arbitrary code on an affected device. This vulnerability is due to insecure deserializatio... Read more
Affected Products : unified_contact_center_express- Published: Jun. 04, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Misconfiguration
-
6.1
MEDIUMCVE-2025-20273
A vulnerability in the web-based management interface of Cisco Unified Intelligent Contact Management Enterprise could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management inte... Read more
Affected Products : unified_intelligent_contact_management_enterprise- Published: Jun. 04, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-20261
A vulnerability in the SSH connection handling of Cisco Integrated Management Controller (IMC) for Cisco UCS B-Series, UCS C-Series, UCS S-Series, and UCS X-Series Servers could allow an authenticated, remote attacker to access internal services with elev... Read more
- Published: Jun. 04, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2025-20259
Multiple vulnerabilities in the update process of Cisco ThousandEyes Endpoint Agent for Windows could allow an authenticated, local attacker to delete arbitrary files on an affected device. These vulnerabilities are due to improper access controls on f... Read more
- Published: Jun. 04, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authorization
-
8.7
HIGHCVE-2025-20163
A vulnerability in the SSH implementation of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to impersonate Cisco NDFC-managed devices. This vulnerability is due to insufficient SSH host key validation. An... Read more
- Published: Jun. 04, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authentication
-
7.2
HIGHCVE-2025-20130
A vulnerability in the API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker with administrative privileges to upload files to an affected device. This vulnerability... Read more
- Published: Jun. 04, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Misconfiguration