Latest CVE Feed
-
9.8
CRITICALCVE-2025-9024
A vulnerability was found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this vulnerability is an unknown functionality of the file /book-appointment.php. The manipulation of the argument Message leads to sql injection. The attack can be ... Read more
Affected Products : beauty_parlour_management_system- Published: Aug. 15, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2024-5383
A vulnerability classified as problematic has been found in lakernote EasyAdmin up to 20240324. This affects an unknown part of the file /sys/file/upload. The manipulation of the argument file leads to cross site scripting. It is possible to initiate the ... Read more
Affected Products : easyadmin- Published: May. 26, 2024
- Modified: Aug. 21, 2025
-
8.8
HIGHCVE-2025-9025
A vulnerability was determined in code-projects Simple Cafe Ordering System 1.0. Affected by this issue is some unknown functionality of the file /portal.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely.... Read more
Affected Products : simple_cafe_ordering_system- Published: Aug. 15, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Injection
-
6.9
MEDIUMCVE-2025-54364
Microsoft Knack 0.12.0 allows Regular expression Denial of Service (ReDoS) in the knack.introspection module. option_descriptions employs an inefficient regular expression pattern: "\s(:param)\s+(.+?)\s:(.*)" that is susceptible to catastrophic backtracki... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Denial of Service
-
6.9
MEDIUMCVE-2025-54363
Microsoft Knack 0.12.0 allows Regular expression Denial of Service (ReDoS) in the knack.introspection module. extract_full_summary_from_signature employs an inefficient regular expression pattern: "\s(:param)\s+(.+?)\s:(.*)" that is susceptible to catastr... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Denial of Service
-
7.0
HIGHCVE-2025-45767
jose v6.0.10 was discovered to contain weak encryption. NOTE: this is disputed by a third party because the claim of "do not meet recommended security standards" does not reflect guidance in a final publication.... Read more
Affected Products :- Published: Aug. 01, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Cryptography
-
7.1
HIGHCVE-2025-2503
An improper permission handling vulnerability was reported in Lenovo PC Manager that could allow a local attacker to perform arbitrary file deletions as an elevated user.... Read more
Affected Products : pc_manager- Published: May. 30, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2024-6004
A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to deny printer connections until the system is rebooted.... Read more
Affected Products :- Published: Aug. 16, 2024
- Modified: Aug. 21, 2025
-
6.5
MEDIUMCVE-2024-5210
A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to prevent printer services from being reachable until the system is rebooted.... Read more
Affected Products :- Published: Aug. 16, 2024
- Modified: Aug. 21, 2025
-
6.5
MEDIUMCVE-2024-5209
A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to deny printing capabilities until the system is rebooted.... Read more
Affected Products :- Published: Aug. 16, 2024
- Modified: Aug. 21, 2025
-
6.5
MEDIUMCVE-2024-4782
A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to disrupt the printer's functionality until a manual system reboot occurs.... Read more
Affected Products :- Published: Aug. 16, 2024
- Modified: Aug. 21, 2025
-
6.5
MEDIUMCVE-2024-4781
A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to crash printer communications until the system is rebooted.... Read more
Affected Products :- Published: Aug. 16, 2024
- Modified: Aug. 21, 2025
-
7.5
HIGHCVE-2023-6603
A flaw was found in FFmpeg's HLS playlist parsing. This vulnerability allows a denial of service via a maliciously crafted HLS playlist that triggers a null pointer dereference during initialization.... Read more
Affected Products : ffmpeg- Published: Dec. 31, 2024
- Modified: Aug. 21, 2025
-
4.8
MEDIUMCVE-2023-38533
A vulnerability has been identified in TIA Administrator (All versions < V3 SP2). The affected component creates temporary download files in a directory with insecure permissions. This could allow any authenticated attacker on Windows to disrupt the updat... Read more
Affected Products : tia_administrator- Published: Jun. 11, 2024
- Modified: Aug. 21, 2025
-
8.8
HIGHCVE-2024-37905
authentik is an open-source Identity Provider that emphasizes flexibility and versatility. Authentik API-Access-Token mechanism can be exploited to gain admin user privileges. A successful exploit of the issue will result in a user gaining full admin acce... Read more
Affected Products : authentik- Published: Jun. 28, 2024
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2025-9087
A vulnerability has been found in Tenda AC20 16.03.08.12. This affects the function set_qosMib_list of the file /goform/SetNetControlList of the component SetNetControlList Endpoint. The manipulation of the argument list leads to stack-based buffer overfl... Read more
- Published: Aug. 16, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-9088
A vulnerability was found in Tenda AC20 16.03.08.12. This vulnerability affects the function save_virtualser_data of the file /goform/formSetVirtualSer. The manipulation of the argument list leads to stack-based buffer overflow. The attack can be initiate... Read more
- Published: Aug. 16, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-9089
A vulnerability was determined in Tenda AC20 16.03.08.12. This issue affects the function sub_48E628 of the file /goform/SetIpMacBind. The manipulation of the argument list leads to stack-based buffer overflow. The attack may be initiated remotely. The ex... Read more
- Published: Aug. 17, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-9090
A vulnerability was identified in Tenda AC20 16.03.08.12. Affected is the function websFormDefine of the file /goform/telnet of the component Telnet Service. The manipulation leads to command injection. It is possible to launch the attack remotely. The ex... Read more
- Published: Aug. 17, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2025-9091
A security flaw has been discovered in Tenda AC20 16.03.08.12. Affected by this vulnerability is an unknown functionality of the file /etc_ro/shadow. The manipulation leads to hard-coded credentials. It is possible to launch the attack on the local host. ... Read more
- Published: Aug. 17, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Authentication