Latest CVE Feed
-
9.8
CRITICALCVE-2025-4340
A vulnerability classified as critical has been found in D-Link DIR-890L and DIR-806A1 up to 100CNb11/108B03. Affected is the function sub_175C8 of the file /htdocs/soap.cgi. The manipulation leads to command injection. It is possible to launch the attack... Read more
- Published: May. 06, 2025
- Modified: May. 13, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-4333
A vulnerability was found in feng_ha_ha/megagao ssm-erp and production_ssm up to 0.0.1. It has been classified as critical. This affects the function uploadFile of the file src/main/java/com/megagao/production/ssm/service/impl/FileServiceImpl.java. The ma... Read more
Affected Products :- Published: May. 06, 2025
- Modified: May. 07, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-4332
A vulnerability was found in PHPGurukul Company Visitor Management System 2.0 and classified as critical. Affected by this issue is some unknown functionality of the file /visitor-detail.php. The manipulation of the argument editid/remark leads to sql inj... Read more
Affected Products : company_visitor_management_system- Published: May. 06, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4331
A vulnerability classified as critical was found in SourceCodester Online Student Clearance System 1.0. This vulnerability affects unknown code of the file /Admin/login.php. The manipulation of the argument id/username/password leads to sql injection. The... Read more
Affected Products : online_student_clearance_system- Published: May. 06, 2025
- Modified: May. 17, 2025
- Vuln Type: Injection
-
5.5
MEDIUMCVE-2025-46593
Process residence vulnerability in abnormal scenarios in the print module Impact: Successful exploitation of this vulnerability may affect availability.... Read more
Affected Products : harmonyos- Published: May. 06, 2025
- Modified: May. 09, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2025-46592
Null pointer dereference vulnerability in the USB HDI driver module Impact: Successful exploitation of this vulnerability may affect availability.... Read more
Affected Products : harmonyos- Published: May. 06, 2025
- Modified: May. 09, 2025
- Vuln Type: Denial of Service
-
6.2
MEDIUMCVE-2025-46591
Out-of-bounds data read vulnerability in the authorization module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
Affected Products : harmonyos- Published: May. 06, 2025
- Modified: May. 09, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-46590
Bypass vulnerability in the network search instruction authentication module Impact: Successful exploitation of this vulnerability can bypass authentication and enable access to some network search functions.... Read more
Affected Products : harmonyos- Published: May. 06, 2025
- Modified: May. 09, 2025
- Vuln Type: Authentication
-
7.1
HIGHCVE-2025-46589
Vulnerability of unauthorized access in the app lock module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.... Read more
Affected Products : harmonyos- Published: May. 06, 2025
- Modified: May. 09, 2025
- Vuln Type: Authorization
-
7.7
HIGHCVE-2025-46588
Vulnerability of unauthorized access in the app lock module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.... Read more
Affected Products : harmonyos- Published: May. 06, 2025
- Modified: May. 09, 2025
- Vuln Type: Authentication
-
6.2
MEDIUMCVE-2025-46587
Permission control vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
Affected Products : harmonyos- Published: May. 06, 2025
- Modified: May. 09, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2025-3281
The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.1 via the create_stripe_subscription() function, d... Read more
- Published: May. 06, 2025
- Modified: May. 07, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2025-3020
An low privileged remote Attacker can execute arbitrary web scripts or HTML via a crafted payload injected into several fields of the configuration webpage with limited impact.... Read more
Affected Products :- Published: May. 06, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
6.2
MEDIUMCVE-2024-58252
Vulnerability of insufficient information protection in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
Affected Products : harmonyos- Published: May. 06, 2025
- Modified: May. 09, 2025
- Vuln Type: Information Disclosure
-
5.3
MEDIUMCVE-2025-4329
A vulnerability was found in 74CMS up to 3.33.0. It has been rated as problematic. Affected by this issue is the function index of the file /index.php/index/download/index. The manipulation of the argument url leads to path traversal. The attack may be la... Read more
Affected Products : 74cms- Published: May. 06, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Path Traversal
-
5.1
MEDIUMCVE-2025-4328
A vulnerability was found in fp2952 spring-cloud-base up to 7f050dc6db9afab82c5ce1d41cd74ed255ec9bfa. It has been declared as problematic. Affected by this vulnerability is the function sendBack of the file /spring-cloud-base-master/auth-center/auth-cente... Read more
Affected Products :- Published: May. 06, 2025
- Modified: May. 07, 2025
- Vuln Type: Misconfiguration
-
5.3
MEDIUMCVE-2025-4327
A vulnerability was found in MRCMS 3.1.2. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the pub... Read more
Affected Products : mrcms- Published: May. 06, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.5
MEDIUMCVE-2025-46586
Permission control vulnerability in the contacts module Impact: Successful exploitation of this vulnerability may affect availability.... Read more
Affected Products : harmonyos- Published: May. 06, 2025
- Modified: May. 09, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-46585
Out-of-bounds array read/write vulnerability in the kernel module Impact: Successful exploitation of this vulnerability may affect availability.... Read more
Affected Products : harmonyos- Published: May. 06, 2025
- Modified: May. 09, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-46584
Vulnerability of improper authentication logic implementation in the file system module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
Affected Products : harmonyos- Published: May. 06, 2025
- Modified: May. 09, 2025
- Vuln Type: Authentication