Latest CVE Feed
-
6.5
MEDIUMCVE-2022-4363
The Wholesale Market WordPress plugin before 2.2.2, Wholesale Market for WooCommerce WordPress plugin before 2.0.1 have a flawed CSRF check when updating their settings, which could allow attackers to make a logged in admin update them via a CSRF attack... Read more
- Published: May. 16, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Request Forgery
-
9.0
HIGHCVE-2025-4809
A vulnerability was found in Tenda AC7 15.03.06.44. It has been classified as critical. Affected is the function fromSafeSetMacFilter of the file /goform/setMacFilterCfg. The manipulation of the argument deviceList leads to stack-based buffer overflow. It... Read more
- Published: May. 16, 2025
- Modified: May. 24, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-4808
A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0 and classified as critical. This issue affects some unknown processing of the file /add-normal-ticket.php. The manipulation of the argument noadult/nochildren/aprice/cprice leads... Read more
Affected Products : park_ticketing_management_system- Published: May. 16, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-4807
A vulnerability, which was classified as problematic, was found in SourceCodester Online Student Clearance System 1.0. This affects an unknown part. The manipulation leads to exposure of information through directory listing. It is possible to initiate th... Read more
Affected Products : online_student_clearance_system- Published: May. 16, 2025
- Modified: May. 28, 2025
- Vuln Type: Information Disclosure
-
7.8
HIGHCVE-2025-4802
Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen call... Read more
Affected Products : glibc- Published: May. 16, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Misconfiguration
-
3.1
LOWCVE-2025-22233
CVE-2024-38820 ensured Locale-independent, lowercase conversion for both the configured disallowedFields patterns and for request parameter names. However, there are still cases where it is possible to bypass the disallowedFields checks. Affected Spring ... Read more
Affected Products : spring_framework- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2025-4806
A vulnerability, which was classified as critical, has been found in SourceCodester/oretnom23 Stock Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/?page=back_order/view_bo. The manipulation of the argument I... Read more
Affected Products : stock_management_system- Published: May. 16, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
5.8
MEDIUMCVE-2025-4795
A vulnerability classified as critical has been found in gongfuxiang schoolcms 2.3.1. This affects the function SaveInfo of the file /index.php?m=Admin&c=article&a=SaveInfo. The manipulation of the argument ID leads to sql injection. It is possible to ini... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4794
A vulnerability was found in PHPGurukul Online Course Registration 3.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /news.php. The manipulation of the argument newstitle leads to sql injection. ... Read more
Affected Products : online_course_registration- Published: May. 16, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4793
A vulnerability was found in PHPGurukul Online Course Registration 3.1. It has been classified as critical. Affected is an unknown function of the file /edit-student-profile.php. The manipulation of the argument cgpa leads to sql injection. It is possible... Read more
Affected Products : online_course_registration- Published: May. 16, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4792
A vulnerability was found in FreeFloat FTP Server 1.0 and classified as critical. This issue affects some unknown processing of the component MDELETE Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exp... Read more
- Published: May. 16, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Memory Corruption
-
4.3
MEDIUMCVE-2025-4476
A denial-of-service vulnerability has been identified in the libsoup HTTP client library. This flaw can be triggered when a libsoup client receives a 401 (Unauthorized) HTTP response containing a specifically crafted domain parameter within the WWW-Authen... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2025-4791
A vulnerability has been found in FreeFloat FTP Server 1.0 and classified as critical. This vulnerability affects unknown code of the component HASH Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remotely. The expl... Read more
- Published: May. 16, 2025
- Modified: May. 23, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4790
A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. This affects an unknown part of the component GLOB Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The ex... Read more
- Published: May. 16, 2025
- Modified: May. 23, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4789
A vulnerability, which was classified as critical, has been found in FreeFloat FTP Server 1.0. Affected by this issue is some unknown functionality of the component LCD Command Handler. The manipulation leads to buffer overflow. The attack may be launched... Read more
- Published: May. 16, 2025
- Modified: May. 23, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4788
A vulnerability classified as critical was found in FreeFloat FTP Server 1.0. Affected by this vulnerability is an unknown functionality of the component DELETE Command Handler. The manipulation leads to buffer overflow. The attack can be launched remotel... Read more
- Published: May. 16, 2025
- Modified: May. 23, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-4787
A vulnerability classified as critical has been found in SourceCodester/oretnom23 Stock Management System 1.0. Affected is an unknown function of the file /admin/?page=sales/view_sale. The manipulation of the argument ID leads to sql injection. It is poss... Read more
Affected Products : stock_management_system- Published: May. 16, 2025
- Modified: May. 23, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-4786
A vulnerability was found in SourceCodester/oretnom23 Stock Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/?page=return/view_return. The manipulation of the argument ID leads to sql inje... Read more
Affected Products : stock_management_system- Published: May. 16, 2025
- Modified: May. 23, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2025-48146
Cross-Site Request Forgery (CSRF) vulnerability in Michael Lups SEO Flow by LupsOnline allows Stored XSS. This issue affects SEO Flow by LupsOnline: from n/a through 2.2.0.... Read more
Affected Products : seo_flow- Published: May. 16, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Cross-Site Request Forgery
-
7.1
HIGHCVE-2025-48144
Cross-Site Request Forgery (CSRF) vulnerability in sidngr Import Export For WooCommerce allows Stored XSS. This issue affects Import Export For WooCommerce: from n/a through 1.6.2.... Read more
Affected Products : import_export_for_woocommerce- Published: May. 16, 2025
- Modified: May. 30, 2025
- Vuln Type: Cross-Site Request Forgery