Latest CVE Feed
-
5.1
MEDIUMCVE-2025-40630
Open redirection vulnerability in IceWarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to redirect a user to any domain by sending a malicious URL to the victim, for example “ https://icewarp.domain.com//<MALICIOUS_DOMAIN>/%... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 16, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2025-4768
A vulnerability classified as critical has been found in feng_ha_ha/megagao ssm-erp and production_ssm 1.0. This affects the function uploadPicture of the file PictureServiceImpl.java. The manipulation of the argument File leads to unrestricted upload. It... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 16, 2025
- Vuln Type: Misconfiguration
-
5.3
MEDIUMCVE-2025-4767
A vulnerability was found in defog-ai introspect up to 0.1.4. It has been rated as critical. Affected by this issue is the function test_custom_tool of the file introspect/backend/integration_routes.py of the component Test Endpoint. The manipulation of t... Read more
Affected Products : introspect- Published: May. 16, 2025
- Modified: May. 16, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4766
A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/profile.php. The manipulation of the argument contactnumber leads to sql inj... Read more
Affected Products : zoo_management_system- Published: May. 16, 2025
- Modified: May. 27, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4765
A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been classified as critical. Affected is an unknown function of the file /admin/contactus.php. The manipulation of the argument mobnum leads to sql injection. It is possible to laun... Read more
Affected Products : zoo_management_system- Published: May. 16, 2025
- Modified: May. 27, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-4679
A vulnerability in Synology Active Backup for Microsoft 365 allows remote authenticated attackers to obtain sensitive information via unspecified vectors.... Read more
Affected Products : active_backup_for_microsoft_365- Published: May. 16, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2025-1975
A vulnerability in the Ollama server version 0.5.11 allows a malicious user to cause a Denial of Service (DoS) attack by customizing the manifest content and spoofing a service. This is due to improper validation of array index access when downloading a m... Read more
Affected Products : ollama- Published: May. 16, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2025-4761
A vulnerability has been found in PHPGurukul Complaint Management System 2.0 and classified as critical. This vulnerability affects unknown code of the file /admin/admin-profile.php. The manipulation of the argument mobilenumber leads to sql injection. Th... Read more
Affected Products : complaint_management_system- Published: May. 16, 2025
- Modified: May. 27, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4758
A vulnerability classified as critical has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected is an unknown function of the file /contact.php. The manipulation of the argument fname leads to sql injection. It is possible to launch the... Read more
Affected Products : beauty_parlour_management_system- Published: May. 16, 2025
- Modified: May. 27, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4757
A vulnerability was found in PHPGurukul Beauty Parlour Management System 1.1. It has been rated as critical. This issue affects some unknown processing of the file /forgot-password.php. The manipulation of the argument email leads to sql injection. The at... Read more
Affected Products : beauty_parlour_management_system- Published: May. 16, 2025
- Modified: May. 27, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-4756
A vulnerability was found in D-Link DI-7003GV2 24.04.18D1 R(68125). It has been declared as problematic. This vulnerability affects unknown code of the file /H5/restart.asp. The manipulation leads to denial of service. The attack can be initiated remotely... Read more
- Published: May. 16, 2025
- Modified: May. 21, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2024-53827
Ericsson Packet Core Controller (PCC) contains a vulnerability where an attacker sending a large volume of specially crafted messages may cause service degradation... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 16, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2025-4755
A vulnerability was found in D-Link DI-7003GV2 24.04.18D1 R(68125). It has been classified as critical. This affects the function sub_497DE4 of the file /H5/netconfig.asp. The manipulation leads to improper authentication. It is possible to initiate the a... Read more
- Published: May. 16, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Authentication
-
6.9
MEDIUMCVE-2025-4753
A vulnerability was found in D-Link DI-7003GV2 24.04.18D1 R(68125) and classified as problematic. Affected by this issue is some unknown functionality of the file /login.data. The manipulation leads to information disclosure. The attack may be launched re... Read more
- Published: May. 16, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2025-3624
Missing Authorization vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component).This issue affects Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.4-00.... Read more
Affected Products : ops_center_analyzer- Published: May. 16, 2025
- Modified: May. 16, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-1531
Authentication credentials leakage vulnerability in Hitachi Ops Center Analyzer viewpoint.This issue affects Hitachi Ops Center Analyzer viewpoint: from 10.0.0-00 before 11.0.4-00.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 16, 2025
- Vuln Type: Authentication
-
5.4
MEDIUMCVE-2024-8201
Cross-Site WebSocket Hijacking vulnerability in Hitachi Ops Center Analyzer (RAID Agent component).This issue affects Hitachi Ops Center Analyzer: from 10.8.0-00 before 11.0.4-00; Hitachi Ops Center Analyzer: from 10.9.0-00 before 11.0.4-00.... Read more
Affected Products : ops_center_analyzer- Published: May. 16, 2025
- Modified: May. 16, 2025
- Vuln Type: Authentication
-
6.9
MEDIUMCVE-2025-4752
A vulnerability has been found in D-Link DI-7003GV2 24.04.18D1 R(68125) and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /install_base.data. The manipulation leads to information disclosure. The attack ... Read more
- Published: May. 16, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2025-4751
A vulnerability, which was classified as problematic, was found in D-Link DI-7003GV2 24.04.18D1 R(68125). Affected is an unknown function of the file /index.data. The manipulation leads to information disclosure. It is possible to launch the attack remote... Read more
- Published: May. 16, 2025
- Modified: May. 27, 2025
- Vuln Type: Information Disclosure
-
6.9
MEDIUMCVE-2025-4750
A vulnerability, which was classified as problematic, has been found in D-Link DI-7003GV2 24.04.18D1 R(68125). This issue affects some unknown processing of the file /H5/get_version.data of the component Configuration Handler. The manipulation leads to in... Read more
- Published: May. 16, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Information Disclosure