Latest CVE Feed
-
9.8
CRITICALCVE-2025-5212
A vulnerability was found in PHPGurukul Employee Record Management System 1.3. It has been classified as critical. Affected is an unknown function of the file /admin/editempexp.php. The manipulation of the argument emp1name leads to sql injection. It is p... Read more
Affected Products : employee_record_management_system- Published: May. 26, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5211
A vulnerability was found in PHPGurukul Employee Record Management System 1.3 and classified as critical. This issue affects some unknown processing of the file /myprofile.php. The manipulation of the argument EmpCode leads to sql injection. The attack ma... Read more
Affected Products : employee_record_management_system- Published: May. 26, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5210
A vulnerability has been found in PHPGurukul Employee Record Management System 1.3 and classified as critical. This vulnerability affects unknown code of the file /loginerms.php. The manipulation of the argument Email leads to sql injection. The attack ca... Read more
Affected Products : employee_record_management_system- Published: May. 26, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5208
A vulnerability, which was classified as critical, was found in SourceCodester Online Hospital Management System 1.0. This affects an unknown part of the file /admin/check_availability.php. The manipulation of the argument emailid leads to sql injection. ... Read more
- Published: May. 26, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5207
A vulnerability, which was classified as critical, has been found in SourceCodester Client Database Management System 1.0. Affected by this issue is some unknown functionality of the file /superadmin_update_profile.php. The manipulation of the argument ni... Read more
- Published: May. 26, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5206
A vulnerability classified as critical was found in Pixelimity 1.0. Affected by this vulnerability is an unknown functionality of the file /install/index.php of the component Installation. The manipulation of the argument site_description leads to sql inj... Read more
Affected Products : pixelimity- Published: May. 26, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5205
A vulnerability classified as critical has been found in 1000 Projects Daily College Class Work Report Book 1.0. Affected is an unknown function of the file /dcwr_entry.php. The manipulation of the argument Date leads to sql injection. It is possible to l... Read more
Affected Products : daily_college_class_work_report_book- Published: May. 26, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2025-5204
A vulnerability classified as problematic has been found in Open Asset Import Library Assimp 5.4.3. This affects the function MDLImporter::ParseSkinLump_3DGS_MDL7 of the file assimp/code/AssetLib/MDL/MDLMaterialLoader.cpp. The manipulation leads to out-of... Read more
Affected Products : assimp- Published: May. 26, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-5203
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been rated as problematic. Affected by this issue is the function SkipSpaces in the library assimp/include/assimp/ParsingUtils.h. The manipulation leads to out-of-bounds read. Loc... Read more
Affected Products : assimp- Published: May. 26, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-5202
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been declared as problematic. Affected by this vulnerability is the function HL1MDLLoader::validate_header of the file assimp/code/AssetLib/MDL/HalfLife/HL1MDLLoader.cpp. The mani... Read more
Affected Products : assimp- Published: May. 26, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-5201
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as problematic. Affected is the function LWOImporter::CountVertsAndFacesLWO2 of the file assimp/code/AssetLib/LWO/LWOLoader.cpp. The manipulation leads to out-of-b... Read more
Affected Products : assimp- Published: May. 26, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-5200
A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function MDLImporter::InternReadFile_Quake1 of the file assimp/code/AssetLib/MDL/MDLLoader.cpp. The manipulation leads to out-of-boun... Read more
Affected Products : assimp- Published: May. 26, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Memory Corruption
-
6.0
MEDIUMCVE-2025-46802
For a short time they PTY is set to mode 666, allowing any user on the system to connect to the screen session.... Read more
Affected Products :- Published: May. 26, 2025
- Modified: May. 28, 2025
- Vuln Type: Misconfiguration
-
7.8
HIGHCVE-2025-23395
Screen 5.0.0 when it runs with setuid-root privileges does not drop privileges while operating on a user supplied path. This allows unprivileged users to create files in arbitrary locations with `root` ownership, the invoking user's (real) group ownership... Read more
Affected Products :- Published: May. 26, 2025
- Modified: May. 28, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-23394
A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed cyrus-imapd allows escalation from cyrus to root.This issue affects openSUSE Tumbleweed cyrus-imapd before 3.8.4-2.1.... Read more
Affected Products :- Published: May. 26, 2025
- Modified: May. 28, 2025
- Vuln Type: Path Traversal
-
5.6
MEDIUMCVE-2025-23392
A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in spacewalk-java allows execution of arbitrary Javascript code on target systems.This issue affects Container suse/manager/5.0/x86_64/server:5.0.4.7.19.1: from ... Read more
Affected Products :- Published: May. 26, 2025
- Modified: May. 28, 2025
- Vuln Type: Cross-Site Scripting
-
5.1
MEDIUMCVE-2025-46803
The default mode of pseudo terminals (PTYs) allocated by Screen was changed from 0620 to 0622, thereby allowing anyone to write to any Screen PTYs in the system.... Read more
Affected Products :- Published: May. 26, 2025
- Modified: May. 28, 2025
- Vuln Type: Misconfiguration
-
0.0
NACVE-2025-37992
In the Linux kernel, the following vulnerability has been resolved: net_sched: Flush gso_skb list too during ->change() Previously, when reducing a qdisc's limit via the ->change() operation, only the main skb queue was trimmed, potentially leaving pack... Read more
Affected Products : linux_kernel- Published: May. 26, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-5196
A vulnerability has been found in Wing FTP Server up to 7.4.3 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Lua Admin Console. The manipulation leads to execution with unnecessary privileges. The a... Read more
Affected Products : wing_ftp_server- Published: May. 26, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Authorization
-
5.7
MEDIUMCVE-2025-46805
Screen version 5.0.0 and older version 4 releases have a TOCTOU race potentially allowing to send SIGHUP, SIGCONT to privileged processes when installed setuid-root.... Read more
Affected Products :- Published: May. 26, 2025
- Modified: May. 28, 2025
- Vuln Type: Race Condition