Latest CVE Feed
-
9.8
CRITICALCVE-2025-4949
In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, a... Read more
Affected Products : jgit- Published: May. 21, 2025
- Modified: Aug. 25, 2025
- Vuln Type: XML External Entity
-
9.8
CRITICALCVE-2025-4524
The Madara – Responsive and modern WordPress theme for manga sites theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2.2 via the 'template' parameter. This makes it possible for unauthenticated attackers to ... Read more
Affected Products :- Published: May. 21, 2025
- Modified: May. 21, 2025
- Vuln Type: Path Traversal
-
6.9
MEDIUMCVE-2021-25262
Yandex Browser for Android prior to version 21.3.0 allows remote attackers to perform IDN homograph attack.... Read more
- Published: May. 21, 2025
- Modified: Jun. 10, 2025
-
8.3
HIGHCVE-2021-25255
Yandex Browser Lite for Android prior to version 21.1.0 allows remote attackers to cause a denial of service.... Read more
Affected Products : yandex_browser- Published: May. 21, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Denial of Service
-
8.2
HIGHCVE-2021-25254
Yandex Browser Lite for Android before 21.1.0 allows remote attackers to spoof the address bar.... Read more
Affected Products : yandex_browser- Published: May. 21, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Information Disclosure
-
5.3
MEDIUMCVE-2025-5013
A vulnerability, which was classified as problematic, was found in HkCms up to 2.3.2.240702. This affects an unknown part of the file /index.php/search/index.html of the component Search. The manipulation of the argument keyword leads to cross site script... Read more
- Published: May. 21, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-4969
A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can allow a remote attacker to send a specially crafted multipart HTTP body, causing the libsoup-consum... Read more
Affected Products :- Published: May. 21, 2025
- Modified: May. 21, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4094
The DIGITS: WordPress Mobile Number Signup and Login WordPress plugin before 8.4.6.1 does not rate limit OTP validation attempts, making it straightforward for attackers to bruteforce them.... Read more
Affected Products : digits- Published: May. 21, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Authentication
-
4.8
MEDIUMCVE-2025-5011
A vulnerability classified as problematic was found in moonlightL hexo-boot 4.3.0. This vulnerability affects unknown code of the file /admin/home/index.html of the component Dynamic List Page. The manipulation leads to cross site scripting. The attack ca... Read more
Affected Products : hexo-boot- Published: May. 21, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-5010
A vulnerability classified as problematic has been found in moonlightL hexo-boot 4.3.0. This affects an unknown part of the file /admin/home/index.html of the component Blog Backend. The manipulation of the argument Description leads to cross site scripti... Read more
Affected Products : hexo-boot- Published: May. 21, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-5008
A vulnerability was found in projectworlds Online Time Table Generator 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/add_teacher.php. The manipulation of the argument e leads to sql injection. ... Read more
- Published: May. 20, 2025
- Modified: Aug. 28, 2025
- Vuln Type: Injection
-
5.1
MEDIUMCVE-2025-5007
A vulnerability was found in Part-DB up to 1.17.0. It has been declared as problematic. Affected by this vulnerability is the function handleUpload of the file src/Services/Attachments/AttachmentSubmitHandler.php of the component Profile Picture Feature. ... Read more
Affected Products :- Published: May. 20, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-5006
A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/category.php. The manipulation of the argument Category leads to sql injection. It is possible to lau... Read more
Affected Products : online_shopping_portal- Published: May. 20, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5004
A vulnerability was found in projectworlds Online Time Table Generator 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/add_course.php. The manipulation of the argument c/subname leads to sql injection. The att... Read more
- Published: May. 20, 2025
- Modified: Aug. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5003
A vulnerability has been found in projectworlds Online Time Table Generator 1.0 and classified as critical. This vulnerability affects unknown code of the file /semester_ajax.php. The manipulation of the argument ID leads to sql injection. The attack can ... Read more
- Published: May. 20, 2025
- Modified: Aug. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5002
A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file /user_proposal_update_order.php. The manipulation of the argument order_id leads to sql injectio... Read more
- Published: May. 20, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
5.5
MEDIUMCVE-2025-5001
A vulnerability was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. It has been declared as problematic. This vulnerability affects the function calloc of the file pspp-convert.c. The manipulation of the argument -l leads to integer overflow. ... Read more
Affected Products : pspp- Published: May. 20, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-5000
A vulnerability was found in Linksys FGW3000-AH and FGW3000-HK up to 1.0.17.000000. It has been classified as critical. This affects the function control_panel_sw of the file /cgi-bin/sysconf.cgi of the component HTTP POST Request Handler. The manipulatio... Read more
- Published: May. 20, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4999
A vulnerability was found in Linksys FGW3000-AH and FGW3000-HK up to 1.0.17.000000 and classified as critical. Affected by this issue is the function sub_4153FC of the file /cgi-bin/sysconf.cgi of the component HTTP POST Request Handler. The manipulation ... Read more
- Published: May. 20, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2025-4998
A vulnerability has been found in H3C Magic R200G up to 100R002 and classified as problematic. Affected by this vulnerability is the function Edit_BasicSSID/Edit_BasicSSID_5G/SetAPWifiorLedInfoById/SetMobileAPInfoById/Asp_SetTimingtimeWifiAndLed/AddMacLis... Read more
Affected Products :- Published: May. 20, 2025
- Modified: May. 21, 2025
- Vuln Type: Denial of Service