Latest CVE Feed
-
9.8
CRITICALCVE-2025-10118
A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. The affected element is an unknown function of the file /login.php. The manipulation of the argument Username leads to sql injection. The ... Read more
Affected Products : e-logbook_with_health_monitoring_system_for_covid-19- Published: Sep. 09, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Injection
-
9.0
HIGHCVE-2025-10120
A vulnerability was detected in Tenda AC20 up to 16.03.08.12. The impacted element is the function strcpy of the file /goform/GetParentControlInfo. The manipulation of the argument mac results in buffer overflow. The attack may be performed from remote. T... Read more
- Published: Sep. 09, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-10109
A vulnerability was determined in Campcodes Online Loan Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=delete_payment. Executing manipulation of the argument ID can lead to sql injection. The attack may be l... Read more
Affected Products : online_loan_management_system- Published: Sep. 08, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-10111
A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is an unknown function of the file /admin/modules/instructor/index.php. The manipulation of the argument ID results in sql injection. The a... Read more
Affected Products : student_information_management_system- Published: Sep. 08, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-10110
A vulnerability was identified in ChanCMS up to 3.3.1. Impacted is an unknown function of the file /search/. The manipulation with the input '%20or%201=1%20%23/words.html leads to sql injection. Remote exploitation of the attack is possible. The exploit i... Read more
Affected Products : chancms- Published: Sep. 08, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Injection
-
4.7
MEDIUMCVE-2025-53791
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.... Read more
Affected Products : edge_chromium- Published: Sep. 05, 2025
- Modified: Sep. 10, 2025
-
6.1
MEDIUMCVE-2025-10027
A vulnerability was determined in itsourcecode POS Point of Sale System 1.0. Affected by this issue is some unknown functionality of the file /inventory/main/vendors/datatables/unit_testing/templates/2512.php. This manipulation of the argument scripts cau... Read more
Affected Products : point_of_sale_system- Published: Sep. 05, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-48208
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache HertzBeat . The attacker needs to have an authenticated account with access, and the attack can only be triggered by crafting custom c... Read more
Affected Products : hertzbeat- Published: Sep. 09, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-24404
XML Injection RCE by parse http sitemap xml response vulnerability in Apache HertzBeat. The attacker needs to have an authenticated account with access, and add monitor parsed by xml, returned special content can trigger the XML parsing vulner... Read more
Affected Products : hertzbeat- Published: Sep. 09, 2025
- Modified: Sep. 10, 2025
- Vuln Type: XML External Entity
-
9.8
CRITICALCVE-2025-57807
ImageMagick is free and open-source software used for editing and manipulating digital images. ImageMagick versions lower than 14.8.2 include insecure functions: SeekBlob(), which permits advancing the stream offset beyond the current end without increas... Read more
Affected Products : imagemagick- Published: Sep. 05, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Memory Corruption
-
4.9
MEDIUMCVE-2025-53609
A Relative Path Traversal vulnerability [CWE-23] in FortiWeb 7.6.0 through 7.6.4, 7.4.0 through 7.4.8, 7.2.0 through 7.2.11, 7.0.2 through 7.0.11 may allow an authenticated attacker to perform an arbitrary file read on the underlying system via crafted re... Read more
Affected Products : fortiweb- Published: Sep. 09, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Path Traversal
-
8.1
HIGHCVE-2025-58370
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions below 3.26.0 contain a vulnerability in the command parsing logic where the Bash parameter expansion and indirect reference were not handled correctly. If the agent w... Read more
Affected Products : roo_code- Published: Sep. 05, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Injection
-
6.7
MEDIUMCVE-2024-45325
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiDDoS-F version 7.0.0 through 7.02 and before 6.6.3 may allow a privileged attacker to execute unauthorized code or comm... Read more
- Published: Sep. 09, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-9994
The Amp’ed RF BT-AP 111 Bluetooth access point's HTTP admin interface does not have an authentication feature, allowing unauthorized access to anyone with network access.... Read more
Affected Products :- Published: Sep. 09, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Authentication
-
7.2
HIGHCVE-2025-52915
K7RKScan.sys 23.0.0.10, part of the K7 Security Anti-Malware suite, allows an admin-privileged user to send crafted IOCTL requests to terminate processes that are protected through a third-party implementation. This is caused by insufficient caller valida... Read more
Affected Products :- Published: Sep. 09, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2025-52322
An issue in Open5GS v2.7.2 and before allows a remote attacker to cause a denial of service via a crafted Create Session Request message to the SMF (PGW-C), using the IP address of a legitimate UE in the PDN Address Allocation (PAA) field... Read more
Affected Products :- Published: Sep. 09, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Denial of Service
-
6.1
MEDIUMCVE-2025-52277
Cross Site Scripting vulnerability in YesWiki v.4.54 allows a remote attacker to execute arbitrary code via a crafted payload to the meta configuration robots field... Read more
Affected Products : yeswiki- Published: Sep. 09, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-9364
An open database issue exists in the affected product and version. The security issue stems from an over permissive Redis instance. This could result in an attacker on the intranet accessing sensitive data and potential alteration of data.... Read more
Affected Products : factorytalk_analytics_logixai- Published: Sep. 09, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2025-59017
Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke AJAX backend routes without having access to the correspondin... Read more
Affected Products : typo3- Published: Sep. 09, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2025-59016
Error messages containing sensitive information in the File Abstraction Layer in TYPO3 CMS versions 9.0.0-9.5.54, 10.0.0-10.4.53, 11.0.0-11.5.47, 12.0.0-12.4.36, and 13.0.0-13.4.17 allow backend users to disclose full file paths via failed low-level file-... Read more
Affected Products : typo3- Published: Sep. 09, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Information Disclosure