Latest CVE Feed
-
3.1
LOWCVE-2025-47279
Undici is an HTTP/1.1 client for Node.js. Prior to versions 5.29.0, 6.21.2, and 7.5.0, applications that use undici to implement a webhook-like system are vulnerable. If the attacker set up a server with an invalid certificate, and they can force the appl... Read more
Affected Products : undici- Published: May. 15, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
5.4
MEDIUMCVE-2025-44110
FluxBB 1.5.11 is vulnerable to Cross Site Scripting (XSS) in via the Forum Description Field in admin_forums.php.... Read more
Affected Products : fluxbb- Published: May. 15, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Scripting
-
7.0
HIGHCVE-2025-43853
The WebAssembly Micro Runtime's (WAMR) iwasm package is the executable binary built with WAMR VMcore which supports WebAssembly System Interface (WASI) and command line interface. Anyone running WAMR up to and including version 2.2.0 or WAMR built with li... Read more
Affected Products : webassembly_micro_runtime- Published: May. 15, 2025
- Modified: May. 16, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-4708
A vulnerability classified as critical has been found in Campcodes Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/sales_add.php. The manipulation of the argument discount leads to sql injection. It is possible to launch... Read more
Affected Products : sales_and_inventory_system- Published: May. 15, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4707
A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /pages/transaction_add.php. The manipulation of the argument prod_name leads to sql injection. The... Read more
Affected Products : sales_and_inventory_system- Published: May. 15, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4706
A vulnerability was found in projectworlds Online Examination System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /Procedure3b_yearwiseVisit.php. The manipulation of the argument Visit_year leads to sql inject... Read more
- Published: May. 15, 2025
- Modified: Aug. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-47580
Missing Authorization vulnerability in Rustaurius Front End Users allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Front End Users: from n/a through 3.2.32.... Read more
Affected Products : front_end_users- Published: May. 15, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Authorization
-
8.5
HIGHCVE-2025-30421
There is a memory corruption vulnerability due to a stack-based buffer overflow in DrObjectStorage::XML_Serialize() when using the SymbolEditor in NI Circuit Design Suite. This vulnerability may result in information disclosure or arbitrary code executio... Read more
Affected Products : circuit_design_suite- Published: May. 15, 2025
- Modified: May. 20, 2025
- Vuln Type: Memory Corruption
-
8.5
HIGHCVE-2025-30420
There is a memory corruption vulnerability due to an out of bounds read in Bitmap::InternalDraw() when using the SymbolEditor in NI Circuit Design Suite. This vulnerability may result in information disclosure or arbitrary code execution. Successful expl... Read more
Affected Products : circuit_design_suite- Published: May. 15, 2025
- Modified: May. 20, 2025
- Vuln Type: Memory Corruption
-
8.5
HIGHCVE-2025-30419
There is a memory corruption vulnerability due to an out of bounds read in GetSymbolBorderRectSize() when using the SymbolEditor in NI Circuit Design Suite. This vulnerability may result in information disclosure or arbitrary code execution. Successful e... Read more
Affected Products : circuit_design_suite- Published: May. 15, 2025
- Modified: May. 20, 2025
- Vuln Type: Memory Corruption
-
8.5
HIGHCVE-2025-30418
There is a memory corruption vulnerability due to an out of bounds write in CheckPins() when using the SymbolEditor in NI Circuit Design Suite. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation r... Read more
Affected Products : circuit_design_suite- Published: May. 15, 2025
- Modified: May. 20, 2025
- Vuln Type: Memory Corruption
-
8.5
HIGHCVE-2025-30417
There is a memory corruption vulnerability due to an out of bounds write in Library!DecodeBase64() when using the SymbolEditor in NI Circuit Design Suite. This vulnerability may result in information disclosure or arbitrary code execution. Successful ex... Read more
Affected Products : circuit_design_suite- Published: May. 15, 2025
- Modified: May. 20, 2025
- Vuln Type: Memory Corruption
-
5.6
MEDIUMCVE-2025-1647
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bootstrap allows Cross-Site Scripting (XSS).This issue affects Bootstrap: from 3.4.1 before 4.0.0.... Read more
Affected Products : bootstrap- Published: May. 15, 2025
- Modified: Jun. 01, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-4705
A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13. It has been classified as critical. This affects an unknown part of the file /admin/view-incomingvehicle-detail.php. The manipulation of the argument viewid leads to sql injec... Read more
Affected Products : vehicle_parking_management_system- Published: May. 15, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-4704
A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/edit-category.php. The manipulation of the argument editid leads to sql inje... Read more
Affected Products : vehicle_parking_management_system- Published: May. 15, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4703
A vulnerability has been found in PHPGurukul Vehicle Parking Management System 1.13 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/admin-profile.php. The manipulation of the argument contactnumber... Read more
Affected Products : vehicle_parking_management_system- Published: May. 15, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-48051
powertip.ts in Lila (for Lichess) before ab0beaf allows XSS in some applications because of an innerHTML usage pattern in which text is extracted from a DOM node and interpreted as HTML.... Read more
Affected Products : powertip.ts- Published: May. 15, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-48050
In DOMPurify through 3.2.5 before 6bc6d60, scripts/server.js does not ensure that a pathname is located under the current working directory. NOTE: the Supplier disputes the significance of this report because the "Uncontrolled data used in path expression... Read more
Affected Products : dompurify- Published: May. 15, 2025
- Modified: May. 16, 2025
- Vuln Type: Path Traversal
-
5.5
MEDIUMCVE-2025-3440
IBM Security Guardium 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure wi... Read more
Affected Products : security_guardium- Published: May. 15, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Cross-Site Scripting
-
2.7
LOWCVE-2025-2570
Mattermost versions 10.5.x <= 10.5.3, 9.11.x <= 9.11.11 fail to check `RestrictSystemAdmin` setting if user doesn't have access to `ExperimentalSettings` which allows a System Manager to access `ExperimentSettings` when `RestrictSystemAdmin` is true via S... Read more
Affected Products : mattermost_server- Published: May. 15, 2025
- Modified: May. 16, 2025
- Vuln Type: Authorization