Latest CVE Feed
-
9.8
CRITICALCVE-2025-4482
A vulnerability classified as critical was found in Project Worlds Student Project Allocation System 1.0. Affected by this vulnerability is an unknown functionality of the file /change_pass/forgot_password_sql.php. The manipulation of the argument Pat_Blo... Read more
Affected Products : student_project_allocation_system- Published: May. 09, 2025
- Modified: May. 16, 2025
- Vuln Type: Injection
-
5.5
MEDIUMCVE-2025-1993
IBM App Connect Enterprise Certified Container 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, 12.4, 12.5, 12.6, 12.7, 12.8, 12.9, and 12.10 DesignerAuthoring instances store their flows in a database... Read more
- Published: May. 09, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Cryptography
-
9.8
CRITICALCVE-2025-4481
A vulnerability was found in SourceCodester Apartment Visitor Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /search-result.php. The manipulation of the argument searchdata leads to sql injecti... Read more
- Published: May. 09, 2025
- Modified: May. 16, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2025-4480
A vulnerability was found in code-projects Simple College Management System 1.0. It has been declared as critical. This vulnerability affects the function input of the component Add New Student. The manipulation of the argument name/branch leads to stack-... Read more
Affected Products : simple_college_management_system- Published: May. 09, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-46192
SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_payment_update.php via the order_id POST parameter.... Read more
Affected Products : client_database_management_system- Published: May. 09, 2025
- Modified: May. 22, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-46191
Arbitrary File Upload in user_payment_update.php in SourceCodester Client Database Management System 1.0 allows unauthenticated users to upload arbitrary files via the uploaded_file_cancelled field. Due to the absence of proper file extension checks, MIME... Read more
Affected Products : client_database_management_system- Published: May. 09, 2025
- Modified: May. 22, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-46190
SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_delivery_update.php via the order_id POST parameter.... Read more
Affected Products : client_database_management_system- Published: May. 09, 2025
- Modified: May. 22, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-29509
Jan v0.5.14 and before is vulnerable to remote code execution (RCE) when the user clicks on a rendered link in the conversation, due to opening external website in the app and the exposure of electronAPI, with a lack of filtering of URL when calling shell... Read more
Affected Products :- Published: May. 09, 2025
- Modified: May. 12, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2025-1278
An issue has been discovered in GitLab CE/EE affecting all versions from 12.0 before 17.9.8, 17.10 before 17.10.6, and 17.11 before 17.11.2. Under certain conditions users could bypass IP access restrictions and view sensitive information.... Read more
Affected Products : gitlab- Published: May. 09, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Authorization
-
6.8
MEDIUMCVE-2025-0549
An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.3 prior to 17.9.8, from 17.10 prior to 17.10.6, and from 17.11 prior to 17.11.2. A security vulnerability allows attackers to bypass Device OAuth flow protections, enabli... Read more
Affected Products : gitlab- Published: May. 09, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2024-8973
An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.9.8, from 17.10 prior to 17.10.6, and from 17.11 prior to 17.11.2. It was possible to cause a DoS condition via GitHub import requests using a malicious cra... Read more
Affected Products : gitlab- Published: May. 09, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Denial of Service
-
5.3
MEDIUMCVE-2025-4432
A flaw was found in Rust's Ring package. A panic may be triggered when overflow checking is enabled. In the QUIC protocol, this flaw allows an attacker to induce this panic by sending a specially crafted packet. It will likely occur unintentionally in 1 o... Read more
Affected Products :- Published: May. 09, 2025
- Modified: May. 12, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2025-46193
SourceCodester Client Database Management System 1.0 is vulnerable to Remote code execution via Arbitrary file upload in user_proposal_update_order.php.... Read more
Affected Products : client_database_management_system- Published: May. 09, 2025
- Modified: May. 22, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-46189
SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_order_customer_update.php via the order_id POST parameter.... Read more
Affected Products : client_database_management_system- Published: May. 09, 2025
- Modified: May. 22, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-46188
SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in superadmin_phpmyadmin.php.... Read more
Affected Products : client_database_management_system- Published: May. 09, 2025
- Modified: May. 22, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-45513
Tenda FH451 V1.0.0.9 has a stack overflow vulnerability in the function.P2pListFilter.... Read more
- Published: May. 09, 2025
- Modified: May. 24, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-28203
Victure RX1800 EN_V1.0.0_r12_110933 was discovered to contain a command injection vulnerability.... Read more
- Published: May. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-28202
Incorrect access control in Victure RX1800 EN_V1.0.0_r12_110933 allows attackers to enable SSH and Telnet services without authentication.... Read more
- Published: May. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Authentication
-
6.8
MEDIUMCVE-2025-28201
An issue in Victure RX1800 EN_V1.0.0_r12_110933 allows physically proximate attackers to execute arbitrary code or gain root access.... Read more
- Published: May. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-28200
Victure RX1800 EN_V1.0.0_r12_110933 was discovered to utilize a weak default password which includes the last 8 digits of the Mac address.... Read more
- Published: May. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Authentication