Latest CVE Feed
-
6.8
MEDIUMCVE-2025-58276
Permission verification vulnerability in the home screen module Impact: Successful exploitation of this vulnerability may affect availability.... Read more
- Published: Sep. 05, 2025
- Modified: Sep. 11, 2025
- Vuln Type: Authorization
-
8.4
HIGHCVE-2025-58280
Vulnerability of exposing object heap addresses in the Ark eTS module. Impact: Successful exploitation of this vulnerability may affect availability.... Read more
Affected Products : harmonyos- Published: Sep. 05, 2025
- Modified: Sep. 11, 2025
- Vuln Type: Information Disclosure
-
8.4
HIGHCVE-2025-58281
Out-of-bounds read vulnerability in the runtime interpreter module. Impact: Successful exploitation of this vulnerability may affect availability.... Read more
Affected Products : harmonyos- Published: Sep. 05, 2025
- Modified: Sep. 11, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-58296
Race condition vulnerability in the audio module. Impact: Successful exploitation of this vulnerability may affect function stability.... Read more
Affected Products : harmonyos- Published: Sep. 05, 2025
- Modified: Sep. 11, 2025
- Vuln Type: Race Condition
-
5.1
MEDIUMCVE-2025-58313
Race condition vulnerability in the device standby module. Impact: Successful exploitation of this vulnerability may cause feature exceptions of the device standby module.... Read more
Affected Products : harmonyos- Published: Sep. 05, 2025
- Modified: Sep. 11, 2025
- Vuln Type: Race Condition
-
6.1
MEDIUMCVE-2025-10028
A vulnerability was identified in itsourcecode POS Point of Sale System 1.0. This affects an unknown part of the file /inventory/main/vendors/datatables/unit_testing/templates/6776.php. Such manipulation of the argument scripts leads to cross site scripti... Read more
Affected Products : point_of_sale_system- Published: Sep. 06, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-10029
A security flaw has been discovered in itsourcecode POS Point of Sale System 1.0. This vulnerability affects unknown code of the file /inventory/main/vendors/datatables/unit_testing/templates/complex_header_2.php. Performing manipulation of the argument s... Read more
Affected Products : point_of_sale_system- Published: Sep. 06, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-10033
A vulnerability has been found in itsourcecode Online Discussion Forum 1.0. This affects an unknown function of the file /admin. Such manipulation of the argument Username leads to sql injection. The attack may be performed from remote. The exploit has be... Read more
- Published: Sep. 06, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-58445
Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. All versions of Atlantis publicly expose detailed version information through its /status endpoint. This information disclosure could allow attackers... Read more
Affected Products : atlantis- Published: Sep. 06, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Information Disclosure
-
6.1
MEDIUMCVE-2025-10063
A vulnerability was identified in itsourcecode POS Point of Sale System 1.0. This vulnerability affects unknown code of the file /inventory/main/vendors/datatables/unit_testing/templates/deferred_table.php. The manipulation of the argument scripts leads t... Read more
Affected Products : point_of_sale_system- Published: Sep. 06, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-10064
A security flaw has been discovered in itsourcecode POS Point of Sale System 1.0. This issue affects some unknown processing of the file /inventory/main/vendors/datatables/unit_testing/templates/dom_data_two_headers.php. The manipulation of the argument s... Read more
Affected Products : point_of_sale_system- Published: Sep. 07, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-57766
Fides is an open-source privacy engineering platform. Prior to version 2.69.1, admin UI user password changes in Fides do not invalidate active user sessions, creating a vulnerability chaining opportunity where attackers who have obtained session tokens t... Read more
Affected Products : fides- Published: Sep. 08, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-57815
Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Admin UI login endpoint relies on a general IP-based rate limit for all API traffic and lacks specific anti-automation controls designed to protect against brute-forc... Read more
Affected Products : fides- Published: Sep. 08, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-57816
Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Webserver API's built-in IP-based rate limiting is ineffective in environments with CDNs, proxies or load balancers. The system incorrectly applies rate limits based ... Read more
Affected Products : fides- Published: Sep. 08, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Misconfiguration
-
8.6
HIGHCVE-2025-57817
Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the OAuth client creation and update endpoints of the Fides Webserver API do not properly authorize scope assignment. This allows highly privileged users with `client:create` o... Read more
Affected Products : fides- Published: Sep. 08, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Authorization
-
6.1
MEDIUMCVE-2025-10032
A vulnerability was detected in Campcodes Grocery Sales and Inventory System 1.0. The affected element is an unknown function of the file /index.php. The manipulation of the argument page results in cross site scripting. The attack can be executed remotel... Read more
Affected Products : grocery_sales_and_inventory_system- Published: Sep. 06, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-10031
A security vulnerability has been detected in Campcodes Grocery Sales and Inventory System 1.0. Impacted is an unknown function of the file /ajax.php?action=delete_sales. The manipulation of the argument ID leads to sql injection. Remote exploitation of t... Read more
Affected Products : grocery_sales_and_inventory_system- Published: Sep. 06, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-10030
A weakness has been identified in Campcodes Grocery Sales and Inventory System 1.0. This issue affects some unknown processing of the file /ajax.php?action=save_receiving. Executing manipulation of the argument ID can lead to sql injection. The attack may... Read more
Affected Products : grocery_sales_and_inventory_system- Published: Sep. 06, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-9847
A weakness has been identified in ScriptAndTools Real Estate Management System 1.0. Impacted is an unknown function of the file register.php. This manipulation of the argument uimage causes unrestricted upload. Remote exploitation of the attack is possibl... Read more
Affected Products : real_estate_management_system- Published: Sep. 03, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-10104
A security vulnerability has been detected in code-projects Online Event Judging System 1.0. Affected is an unknown function of the file /review_search.php. The manipulation of the argument txtsearch leads to sql injection. It is possible to initiate the ... Read more
Affected Products : online_event_judging_system- Published: Sep. 08, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Injection