Latest CVE Feed
-
3.5
CVSS31CVE-2025-6166
A vulnerability was found in frdel Agent-Zero up to 0.8.4. It has been rated as problematic. This issue affects the function image_get of the file /python/api/image_get.py. The manipulation of the argument path leads to path traversal. Upgrading to versio... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
-
8.8
CVSS31CVE-2025-6165
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been declared as critical. This vulnerability affects unknown code of the file /boafrm/formTmultiAP of the component HTTP POST Request Handler. The manipulation of the argument submit-... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
-
8.8
CVSS31CVE-2025-6164
A vulnerability was found in TOTOLINK A3002R 4.0.0-B20230531.1404. It has been classified as critical. This affects an unknown part of the file /boafrm/formMultiAP of the component HTTP POST Request Handler. The manipulation of the argument submit-url lea... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
-
0.0
NONECVE-2025-5209
The Ivory Search WordPress plugin before 5.5.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
-
8.8
CVSS31CVE-2025-6163
A vulnerability was found in TOTOLINK A3002RU 3.0.0-B20230809.1615 and classified as critical. Affected by this issue is some unknown functionality of the file /boafrm/formMultiAP of the component HTTP POST Request Handler. The manipulation of the argumen... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
-
8.8
CVSS31CVE-2025-6162
A vulnerability has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formMultiAP of the component HTTP POST Request Handler. The manipulation o... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
-
7.3
CVSS31CVE-2025-6161
A vulnerability, which was classified as critical, was found in SourceCodester Simple Food Ordering System 1.0. Affected is an unknown function of the file /editproduct.php. The manipulation of the argument photo leads to unrestricted upload. It is possib... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
-
7.3
CVSS31CVE-2025-6160
A vulnerability, which was classified as critical, has been found in SourceCodester Client Database Management System 1.0. This issue affects some unknown processing of the file /user_customer_create_order.php. The manipulation of the argument user_id lea... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
-
7.3
CVSS31CVE-2025-6159
A vulnerability classified as critical was found in code-projects Hostel Management System 1.0. This vulnerability affects unknown code of the file /allocate_room.php. The manipulation of the argument search_box leads to sql injection. The attack can be i... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
-
8.8
CVSS31CVE-2025-6158
A vulnerability classified as critical has been found in D-Link DIR-665 1.00. This affects the function sub_AC78 of the component HTTP POST Request Handler. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remot... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
-
7.3
CVSS31CVE-2025-6157
A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /registered-user-testing.php. The manipulation of the argument testtype lead... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
-
6.3
CVSS31CVE-2025-6156
A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /bwdates-report-ds.php. The manipulation of the argument testtype l... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
-
7.3
CVSS31CVE-2025-6155
A vulnerability was found in PHPGurukul Hostel Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /includes/login-hm.inc.php. The manipulation of the argument Username leads to sql injection. It is possi... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
-
7.3
CVSS31CVE-2025-6154
A vulnerability was found in PHPGurukul Hostel Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /includes/login.inc.php. The manipulation of the argument student_roll_no leads to sql injection. The a... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
-
7.3
CVSS31CVE-2025-6153
A vulnerability has been found in PHPGurukul Hostel Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/students.php. The manipulation of the argument search_box leads to sql injection. The attack c... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
-
0.0
CVSS31CVE-2025-49823
(conda) Constructor is a tool which allows constructing an installer for a collection of conda packages. Prior to version 3.11.3, shell installer scripts process the installation prefix (user_prefix) using an eval statement, which executes unsanitized use... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
-
6.3
CVSS31CVE-2025-6152
A vulnerability, which was classified as critical, was found in Steel Browser up to 0.1.3. This affects the function handleFileUpload of the file api/src/modules/files/files.routes.ts. The manipulation of the argument filename leads to path traversal. It ... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
-
6.5
CVSS31CVE-2025-5673
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to SQL Injection via the ‘prgSortPostType’ parameter in all versions up to, and including, 8.4.4 due to insufficient escaping on the user supplied parameter and lack of... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
-
6.4
CVSS31CVE-2025-4775
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-button-label HTML attribute in all versions up to, and including, 7.4.0.1 due to insufficient input sanitization and output escap... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
-
7.2
CVSS31CVE-2025-3774
The Wise Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the X-Forwarded-For header in all versions up to, and including, 3.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticat... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025