Latest CVE Feed
-
7.5
HIGHCVE-2025-43919
GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ directory traversal at /mailman/private/mailman (aka the private archive authentication endpoint) via the username parameter. NOTE: multip... Read more
Affected Products : mailman- Published: Apr. 20, 2025
- Modified: Apr. 28, 2025
- Vuln Type: Path Traversal
-
6.4
MEDIUMCVE-2025-43918
SSL.com before 2025-04-19, when domain validation method 3.2.2.4.14 is used, processes certificate requests such that a trusted TLS certificate may be issued for the domain name of a requester's email address, even when the requester does not otherwise es... Read more
Affected Products :- Published: Apr. 19, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Authorization
-
2.9
LOWCVE-2023-30421
mystrtod in mjson 1.2.7 requires more than a billion iterations during processing of certain digit strings such as 8891110122900e913013935755114.... Read more
Affected Products :- Published: Apr. 19, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Denial of Service
-
2.9
LOWCVE-2023-26819
cJSON 1.7.15 might allow a denial of service via a crafted JSON document such as {"a": true, "b": [ null,9999999999999999999999999999999999999999999999912345678901234567]}.... Read more
Affected Products : cjson- Published: Apr. 19, 2025
- Modified: Jun. 25, 2025
-
9.0
HIGHCVE-2025-3820
A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644) and classified as critical. Affected by this issue is the function cgiSysUplinkCheckSet of the file /bin/httpd. The manipulation of the argument hostIp1/hostIp2 leads to stack-base... Read more
- Published: Apr. 19, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Memory Corruption
-
3.3
LOWCVE-2022-47112
7-Zip 22.01 does not report an error for certain invalid xz files, involving stream flags and reserved bits. Some later versions are unaffected.... Read more
Affected Products : 7-zip- Published: Apr. 19, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Misconfiguration
-
3.3
LOWCVE-2022-47111
7-Zip 22.01 does not report an error for certain invalid xz files, involving block flags and reserved bits. Some later versions are unaffected.... Read more
Affected Products : 7-zip- Published: Apr. 19, 2025
- Modified: Aug. 18, 2025
-
9.8
CRITICALCVE-2025-3819
A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/search-appointment.php. The manipulation of the argument searchdata lead... Read more
Affected Products : men_salon_management_system- Published: Apr. 19, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-3818
A vulnerability, which was classified as critical, was found in webpy web.py 0.70. Affected is the function PostgresDB._process_insert_query of the file web/db.py. The manipulation of the argument seqname leads to sql injection. It is possible to launch t... Read more
Affected Products :- Published: Apr. 19, 2025
- Modified: May. 29, 2025
- Vuln Type: Injection
-
8.2
HIGHCVE-2025-43917
In Pritunl Client before 1.3.4220.57, an administrator with access to /Applications can escalate privileges after uninstalling the product. Specifically, an administrator can insert a new file at the pathname of the removed pritunl-service file. This file... Read more
Affected Products : pritunl-client- Published: Apr. 19, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2025-3817
A vulnerability, which was classified as critical, has been found in SourceCodester Online Eyewear Shop 1.0. This issue affects some unknown processing of the file /oews/classes/Master.php?f=delete_stock. The manipulation of the argument ID leads to sql i... Read more
Affected Products : online_eyewear_shop- Published: Apr. 19, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
5.8
MEDIUMCVE-2025-3816
A vulnerability classified as critical was found in westboy CicadasCMS 2.0. This vulnerability affects unknown code of the file /system/schedule/save of the component Scheduled Task Handler. The manipulation leads to os command injection. The attack can b... Read more
Affected Products : cicadascms- Published: Apr. 19, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2025-3808
A vulnerability has been found in zhenfeng13 My-BBS 1.0 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to t... Read more
Affected Products :- Published: Apr. 19, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.5
MEDIUMCVE-2025-3807
A vulnerability, which was classified as critical, was found in zhenfeng13 My-BBS 1.0. This affects the function Upload of the file src/main/java/com/my/bbs/controller/common/UploadController.java of the component Endpoint. The manipulation leads to unres... Read more
Affected Products :- Published: Apr. 19, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Authentication
-
4.8
MEDIUMCVE-2025-3806
A vulnerability, which was classified as problematic, has been found in dazhouda lecms up to 3.0.3. Affected by this issue is some unknown functionality of the file /admin of the component Edit Profile Handler. The manipulation leads to cross site scripti... Read more
Affected Products : lecms- Published: Apr. 19, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2025-3805
A vulnerability classified as critical was found in sarrionandia tournatrack up to 4c13a23f43da5317eea4614870a7a8510fc540ec. Affected by this vulnerability is an unknown functionality of the file check_id.py of the component Jinja2 Template Handler. The m... Read more
Affected Products :- Published: Apr. 19, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2025-3804
A vulnerability classified as critical has been found in thautwarm vscode-diana 0.0.1. Affected is an unknown function of the file Gen.py of the component Jinja2 Template Handler. The manipulation leads to injection. Attacking locally is a requirement. Th... Read more
Affected Products :- Published: Apr. 19, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Injection
-
9.0
HIGHCVE-2025-3803
A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644). It has been rated as critical. This issue affects the function cgiSysScheduleRebootSet of the file /bin/httpd. The manipulation of the argument rebootDate leads to stack-based buf... Read more
- Published: Apr. 19, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-3802
A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644). It has been declared as critical. This vulnerability affects the function cgiPingSet of the file /bin/httpd. The manipulation of the argument pingIP leads to stack-based buffer ov... Read more
- Published: Apr. 19, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Memory Corruption
-
4.8
MEDIUMCVE-2025-3801
A vulnerability was found in songquanpeng one-api up to 0.6.10. It has been classified as problematic. This affects an unknown part of the component System Setting Handler. The manipulation of the argument Homepage Content/About System/Footer leads to cro... Read more
Affected Products :- Published: Apr. 19, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Cross-Site Scripting