Latest CVE Feed
-
9.8
CRITICALCVE-2025-26210
DeepSeek R1 through V3.1 allows XSS, as demonstrated by JavaScript execution in the context of the run-html-chat.deepseeksvc.com domain. NOTE: some third parties have indicated that this is intended behavior.... Read more
- Published: Sep. 03, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2024-56189
In SAEMM_DiscloseMsId of SAEMM_RadioMessageCodec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure post authentication with no additional execution privileges needed. User interaction... Read more
Affected Products : android- Published: Sep. 04, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2025-53694
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP).This issue affects Sitecore Experience Manager (XM): from 9.2 through 10.4; Experience Platform (XP): ... Read more
- Published: Sep. 03, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Information Disclosure
-
4.2
MEDIUMCVE-2025-56608
The SourceCodester Android application "Corona Virus Tracker App India" 1.0 uses MD5 for digest authentication in `OkHttpClientWrapper.java`. The `handleDigest()` function employs `MessageDigest.getInstance("MD5")` to hash credentials. MD5 is a broken cry... Read more
Affected Products : android_corona_virus_tracker_app_for_india- Published: Sep. 03, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Cryptography
-
9.8
CRITICALCVE-2025-57052
cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote attackers to bypass array bounds checking and access restricted data via malformed JSON pointer strings containing al... Read more
- Published: Sep. 03, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Misconfiguration
-
8.1
HIGHCVE-2025-57146
phpgurukul Complaint Management System in PHP 2.0 is vulnerable to SQL Injection in user/reset-password.php via the mobileno parameter.... Read more
Affected Products : complaint_management_system- Published: Sep. 03, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-57147
A SQL Injection vulnerability was found in phpgurukul Complaint Management System 2.0. The vulnerability is due to lack of input validation of multiple parameters including fullname, email, and contactno in user/registration.php.... Read more
Affected Products : complaint_management_system- Published: Sep. 03, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-55175
QuickCMS is vulnerable to Reflected XSS via sLangEdit parameter in admin's panel functionality. A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. The vendor was no... Read more
Affected Products : quick.cms- Published: Aug. 28, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2025-54544
QuickCMS is vulnerable to Stored XSS via aDirFilesDescriptions parameter in files editor functionality. Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. By d... Read more
Affected Products : quick.cms- Published: Aug. 28, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-58458
In Jenkins Git client Plugin 6.3.2 and earlier, except 6.1.4 and 6.2.1, Git URL field form validation responses differ based on whether the specified file path exists on the controller when specifying `amazon-s3` protocol for use with JGit, allowing attac... Read more
Affected Products : git_client- Published: Sep. 03, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Information Disclosure
-
6.1
MEDIUMCVE-2025-54540
QuickCMS is vulnerable to Reflected XSS via sSort parameter in admin's panel functionality. A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. The vendor was notifi... Read more
Affected Products : quick.cms- Published: Aug. 28, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-58459
Jenkins global-build-stats Plugin 322.v22f4db_18e2dd and earlier does not perform permission checks in its REST API endpoints, allowing attackers with Overall/Read permission to enumerate graph IDs.... Read more
- Published: Sep. 03, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Authorization
-
6.9
MEDIUMCVE-2025-54541
QuickCMS is vulnerable to Cross-Site Request Forgery in page deletion functionality. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request deleting an article. The vendor was notified early ... Read more
Affected Products : quick.cms- Published: Aug. 28, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.9
MEDIUMCVE-2025-54542
QuickCMS sends password and login via GET Request. This allows a local attacker with access to the victim's browser history to obtain the necessary credentials to log in as the user. The vendor was notified early about this vulnerability, but didn't resp... Read more
Affected Products : quick.cms- Published: Aug. 28, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Authentication
-
5.3
MEDIUMCVE-2025-54543
QuickCMS is vulnerable to Stored XSS via sDescriptionMeta parameter in page editor SEO functionality. Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. By def... Read more
Affected Products : quick.cms- Published: Aug. 28, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-9699
A vulnerability was detected in SourceCodester Online Polling System Code 1.0. This vulnerability affects unknown code of the file /admin/checklogin.php. The manipulation of the argument myusername results in sql injection. The attack may be performed fro... Read more
Affected Products : online_polling_system- Published: Aug. 30, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-9700
A flaw has been found in SourceCodester Online Book Store 1.0. This issue affects some unknown processing of the file /publisher_list.php. This manipulation of the argument pubid causes sql injection. It is possible to initiate the attack remotely. The ex... Read more
Affected Products : online_book_store- Published: Aug. 30, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-9701
A vulnerability was determined in SourceCodester Simple Cafe Billing System 1.0. The impacted element is an unknown function of the file /receipt.php. Executing manipulation of the argument ID can lead to sql injection. The attack can be launched remotely... Read more
Affected Products : simple_cafe_billing_system- Published: Aug. 30, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-9702
A vulnerability was identified in SourceCodester Simple Cafe Billing System 1.0. This affects an unknown function of the file /sales_report.php. The manipulation of the argument month leads to sql injection. The attack may be initiated remotely. The explo... Read more
Affected Products : simple_cafe_billing_system- Published: Aug. 30, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-9704
A security flaw has been discovered in SourceCodester Water Billing System 1.0. This impacts an unknown function of the file /viewbill.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has ... Read more
Affected Products : water_billing_system- Published: Aug. 30, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Injection