Latest CVE Feed
-
5.5
MEDIUMCVE-2022-48690
In the Linux kernel, the following vulnerability has been resolved: ice: Fix DMA mappings leak Fix leak, when user changes ring parameters. During reallocation of RX buffers, new DMA mappings are created for those buffers. New buffers with different RX ... Read more
Affected Products : linux_kernel- Published: May. 03, 2024
- Modified: Sep. 18, 2025
-
5.5
MEDIUMCVE-2022-48704
In the Linux kernel, the following vulnerability has been resolved: drm/radeon: add a force flush to delay work when radeon Although radeon card fence and wait for gpu to finish processing current batch rings, there is still a corner case that radeon lo... Read more
Affected Products : linux_kernel- Published: May. 03, 2024
- Modified: Sep. 18, 2025
-
5.5
MEDIUMCVE-2022-48705
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921e: fix crash in chip reset fail In case of drv own fail in reset, we may need to run mac_reset several times. The sequence would trigger system crash as the log below.... Read more
Affected Products : linux_kernel- Published: May. 03, 2024
- Modified: Sep. 18, 2025
-
4.7
MEDIUMCVE-2023-52654
In the Linux kernel, the following vulnerability has been resolved: io_uring/af_unix: disable sending io_uring over sockets File reference cycles have caused lots of problems for io_uring in the past, and it still doesn't work exactly right and races wi... Read more
Affected Products : linux_kernel- Published: May. 14, 2024
- Modified: Sep. 18, 2025
-
9.1
CRITICALCVE-2025-58762
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. In Tautulli v2.15.3 and earlier, an attacker with administrative access can use the `pms_image_proxy` endpoint to write arbitrary python scripts into the application filesystem... Read more
Affected Products : tautulli- Published: Sep. 09, 2025
- Modified: Sep. 18, 2025
- Vuln Type: Path Traversal
-
5.5
MEDIUMCVE-2024-27066
In the Linux kernel, the following vulnerability has been resolved: virtio: packed: fix unmap leak for indirect desc table When use_dma_api and premapped are true, then the do_unmap is false. Because the do_unmap is false, vring_unmap_extra_packed is n... Read more
Affected Products : linux_kernel- Published: May. 01, 2024
- Modified: Sep. 18, 2025
-
5.5
MEDIUMCVE-2024-27067
In the Linux kernel, the following vulnerability has been resolved: xen/evtchn: avoid WARN() when unbinding an event channel When unbinding a user event channel, the related handler might be called a last time in case the kernel was built with CONFIG_DE... Read more
Affected Products : linux_kernel- Published: May. 01, 2024
- Modified: Sep. 18, 2025
-
5.5
MEDIUMCVE-2025-59410
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the code in the scheduler for downloading a tiny file is hard coded to use the HTTP protocol, rather than HTTPS. This means that an attacker could perfo... Read more
Affected Products : dragonfly- Published: Sep. 17, 2025
- Modified: Sep. 18, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-10564
A vulnerability was found in Campcodes Grocery Sales and Inventory System 1.0. Affected is an unknown function of the file /ajax.php?action=delete_category. Performing manipulation of the argument ID results in sql injection. The attack is possible to be ... Read more
Affected Products : grocery_sales_and_inventory_system- Published: Sep. 16, 2025
- Modified: Sep. 18, 2025
- Vuln Type: Injection
-
5.5
MEDIUMCVE-2024-27069
In the Linux kernel, the following vulnerability has been resolved: ovl: relax WARN_ON in ovl_verify_area() syzbot hit an assertion in copy up data loop which looks like it is the result of a lower file whose size is being changed underneath overlayfs. ... Read more
Affected Products : linux_kernel- Published: May. 01, 2024
- Modified: Sep. 18, 2025
-
7.2
HIGHCVE-2025-57263
An authenticated SQL injection vulnerability in VX Guestbook 1.07 allows attackers with admin access to inject malicious SQL payloads via the "word" POST parameter in the words.php admin panel.... Read more
Affected Products : vx_guestbook- Published: Sep. 04, 2025
- Modified: Sep. 18, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-10565
A vulnerability was determined in Campcodes Grocery Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=delete_receiving. Executing manipulation of the argument ID can lead to sql injecti... Read more
Affected Products : grocery_sales_and_inventory_system- Published: Sep. 16, 2025
- Modified: Sep. 18, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-10566
A vulnerability was identified in Campcodes Grocery Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file /index.php?page=users. The manipulation of the argument page leads to cross site scripting. It is possible... Read more
Affected Products : grocery_sales_and_inventory_system- Published: Sep. 16, 2025
- Modified: Sep. 18, 2025
- Vuln Type: Cross-Site Scripting
-
7.3
HIGHCVE-2025-56295
code-projects Computer Laboratory System 1.0 has a file upload vulnerability. Staff can upload malicious files by uploading PHP backdoor files when modifying personal avatar information and use web shell connection tools to obtain server permissions.... Read more
Affected Products : computer_laboratory_system- Published: Sep. 16, 2025
- Modified: Sep. 18, 2025
- Vuln Type: Misconfiguration
-
5.4
MEDIUMCVE-2025-56293
code-projects Human Resource Integrated System 1.0 is vulnerable to Cross Site Scripting (XSS) in the Add Child Information section in the Childs Name field.... Read more
Affected Products : human_resource_integrated_system- Published: Sep. 16, 2025
- Modified: Sep. 18, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-56289
code-projects Document Management System 1.0 has a Cross Site Scripting (XSS) vulnerability, where attackers can leak admin's cookie information by entering malicious XSS code in the Company field when adding files.... Read more
Affected Products : document_management_system- Published: Sep. 16, 2025
- Modified: Sep. 18, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-10562
A flaw has been found in Campcodes Grocery Sales and Inventory System 1.0. This affects an unknown function of the file /ajax.php?action=save_product. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible... Read more
Affected Products : grocery_sales_and_inventory_system- Published: Sep. 16, 2025
- Modified: Sep. 18, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2025-56280
code-projects Food Ordering Review System 1.0 is vulnerable to Cross Site Scripting (XSS) in the area where users submit reservation information.... Read more
Affected Products : food_ordering_review_system- Published: Sep. 16, 2025
- Modified: Sep. 18, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-57119
An issue in Online Library Management System v.3.0 allows an attacker to escalate privileges via the adminlogin.php component and the Login function... Read more
Affected Products : online_library_management_system- Published: Sep. 16, 2025
- Modified: Sep. 18, 2025
- Vuln Type: Authentication
-
5.4
MEDIUMCVE-2025-56276
code-projects Food Ordering Review System 1.0 is vulnerable to Cross Site Scripting (XSS) in the registration function. An attacker enters malicious JavaScript code as a username, which triggers the XSS vulnerability when the admin views user information,... Read more
Affected Products : food_ordering_review_system- Published: Sep. 16, 2025
- Modified: Sep. 18, 2025
- Vuln Type: Cross-Site Scripting