Latest CVE Feed
-
9.8
CRITICALCVE-2023-44752
An issue in Student Study Center Desk Management System v1.0 allows attackers to bypass authentication via a crafted GET request to /php-sscdms/admin/login.php.... Read more
Affected Products : student_study_center_desk_management_system- Published: Apr. 22, 2025
- Modified: Apr. 24, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2023-43958
An arbitrary file upload vulnerability in the component /jquery-file-upload/server/php/index.php of Hospital Management System v4.0 allows an unauthenticated attacker to upload any file to the server and execute arbitrary code.... Read more
Affected Products : hospital_management_system- Published: Apr. 22, 2025
- Modified: May. 14, 2025
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2023-43378
A cross-site scripting (XSS) vulnerability in Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the commento1_1 parameter.... Read more
Affected Products : hoteldruid- Published: Apr. 22, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Cross-Site Scripting
-
10.0
CRITICALCVE-2025-34028
The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vulnerable to path traversal vulnerability that can result in Remote Code Exe... Read more
- Actively Exploited
- Published: Apr. 22, 2025
- Modified: May. 29, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2025-29339
An issue in UPF in Open5GS UPF versions up to v2.7.2 results an assertion failure vulnerability in PFCP session parameter validation. When processing a PFCP Session Establishment Request with PDN Type=0, the UPF fails to handle the invalid value propagate... Read more
Affected Products : open5gs- Published: Apr. 22, 2025
- Modified: Jun. 19, 2025
- Vuln Type: Denial of Service
-
4.1
MEDIUMCVE-2025-27907
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other atta... Read more
- Published: Apr. 22, 2025
- Modified: Jul. 18, 2025
- Vuln Type: Server-Side Request Forgery
-
7.2
HIGHCVE-2025-3767
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon BAM (Boolean KPi Listing modules) allows SQL Injection. This page is only accessible to authenticated users with high privileges. This issue ... Read more
Affected Products :- Published: Apr. 22, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-28037
TOTOLINK A810R V4.1.2cu.5182_B20201026 and A950RG V4.1.2cu.5161_B20200903 were found to contain a pre-auth remote command execution vulnerability in the setDiagnosisCfg function through the ipDomain parameter.... Read more
- Published: Apr. 22, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-28031
TOTOLINK A810R V4.1.2cu.5182_B20201026 was discovered to contain a hardcoded password for the telnet service in product.ini.... Read more
Affected Products : a810r_firmware- Published: Apr. 22, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2025-28030
TOTOLINK A810R V4.1.2cu.5182_B20201026 was discovered to contain a stack overflow via the startTime and endTime parameters in setParentalRules function.... Read more
- Published: Apr. 22, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-28024
TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in the cstecgi.cgi... Read more
- Published: Apr. 22, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Memory Corruption
-
7.6
HIGHCVE-2025-23251
NVIDIA NeMo Framework contains a vulnerability where a user could cause an improper control of generation of code by remote code execution. A successful exploit of this vulnerability might lead to code execution and data tampering.... Read more
Affected Products :- Published: Apr. 22, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Injection
-
7.6
HIGHCVE-2025-23250
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause an improper limitation of a pathname to a restricted directory by an arbitrary file write. A successful exploit of this vulnerability might lead to code execution and data tamper... Read more
Affected Products :- Published: Apr. 22, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Path Traversal
-
7.6
HIGHCVE-2025-23249
NVIDIA NeMo Framework contains a vulnerability where a user could cause a deserialization of untrusted data by remote code execution. A successful exploit of this vulnerability might lead to code execution and data tampering.... Read more
Affected Products :- Published: Apr. 22, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Injection
-
7.7
HIGHCVE-2024-33452
An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD request.... Read more
Affected Products : lua-nginx-module- Published: Apr. 22, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Misconfiguration
-
7.0
HIGHCVE-2025-29547
In Rollback Rx Professional 12.8.0.0, the driver file shieldm.sys allows local users to cause a denial of service because of a null pointer dereference from IOCtl 0x96202000.... Read more
Affected Products : rollback_rx_pro- Published: Apr. 22, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Denial of Service
-
8.8
HIGHCVE-2025-23176
CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')... Read more
Affected Products : tcexam- Published: Apr. 22, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Injection
-
8.4
HIGHCVE-2025-1951
IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to execute commands as a privileged user due to execution of commands with unnecessary privileges.... Read more
- Published: Apr. 22, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Authorization
-
9.3
CRITICALCVE-2025-1950
IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to execute commands locally due to improper validation of libraries of an untrusted source.... Read more
- Published: Apr. 22, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-28034
TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a pre-auth remote command executio... Read more
Affected Products : a830r_firmware a3100r_firmware a950rg_firmware a800r_firmware a3000ru_firmware a810r_firmware a3100r a3000ru a830r a800r +2 more products- Published: Apr. 22, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Injection