Latest CVE Feed
-
7.5
HIGHCVE-2025-55483
Tenda AC6 V15.03.06.23_multi is vulnerable to Buffer Overflow in the function formSetMacFilterCfg via the parameters macFilterType and deviceList.... Read more
- Published: Aug. 20, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Memory Corruption
-
4.9
MEDIUMCVE-2025-51488
A Stored Cross-Site Scripting (XSS) vulnerability exists in MoonShine version < 3.12.4, allowing remote attackers to store and execute arbitrary JavaScript by including a malicious HTML payload in the Name parameter when creating a new Admin.... Read more
- Published: Aug. 19, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Cross-Site Scripting
-
4.5
MEDIUMCVE-2025-51487
A Stored Cross-Site Scripting (XSS) vulnerability exists in MoonShine version < 3.12.5, allowing to execute arbitrary JavaScript by using "javascript:" payload, instead of the expected HTTPS protocol, in the CutCode Link parameter when creating/updating a... Read more
- Published: Aug. 19, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-51489
A Stored Cross-Site Scripting (XSS) vulnerability exists in MoonShine version < 3.12.5, allowing remote attackers to upload a malicious SVG file when creating/updating an Article and correctly execute arbitrary JavaScript when the file link is opened.... Read more
- Published: Aug. 19, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-8973
A vulnerability has been found in SourceCodester Cashier Queuing System 1.0. Affected is an unknown function of the file /Actions.php. The manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The expl... Read more
Affected Products : cashier_queuing_system- Published: Aug. 14, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-8990
A vulnerability was determined in code-projects Online Medicine Guide 1.0. Affected is an unknown function of the file /browsemdcn.php. The manipulation of the argument Search leads to sql injection. It is possible to launch the attack remotely. The explo... Read more
Affected Products : online_medicine_guide- Published: Aug. 15, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-9011
A vulnerability was determined in PHPGurukul Online Shopping Portal Project 2.0. Affected by this issue is some unknown functionality of the file /shopping/signup.php. The manipulation of the argument emailid leads to sql injection. The attack may be laun... Read more
- Published: Aug. 15, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-9012
A vulnerability was identified in PHPGurukul Online Shopping Portal Project 2.0. This affects an unknown part of the file shopping/bill-ship-addresses.php. The manipulation of the argument billingpincode leads to sql injection. It is possible to initiate ... Read more
- Published: Aug. 15, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Injection
-
10.0
CRITICALCVE-2025-53187
Authentication Bypass Using an Alternate Path or Channel vulnerability in ABB ASPECT.This issue affects ASPECT: before <3.08.04-s01.... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2025-8088
A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, ... Read more
- Actively Exploited
- Published: Aug. 08, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-55591
TOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability in the devicemac parameter in the formMapDel endpoint.... Read more
- Published: Aug. 18, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-55590
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an command injection vulnerability via the component bupload.html.... Read more
- Published: Aug. 18, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-55589
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain multiple OS command injection vulnerabilities via the macstr, bandstr, and clientoff parameters at /boafrm/formMapDelDevice.... Read more
- Published: Aug. 18, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-55588
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the fw_ip parameter at /boafrm/formPortFw. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.... Read more
- Published: Aug. 18, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2025-55587
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the hostname parameter at /boafrm/formMapDelDevice. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.... Read more
- Published: Aug. 18, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2025-55586
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the url parameter at /boafrm/formFilter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.... Read more
- Published: Aug. 18, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-55585
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an eval injection vulnerability via the eval() function.... Read more
- Published: Aug. 18, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2025-55584
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain insecure credentials for the telnet service and root account.... Read more
- Published: Aug. 18, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2024-26484
A stored cross-site scripting (XSS) vulnerability in the Edit Content Layout module of Kirby CMS v4.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Link field. NOTE: the vendor's position is that this ... Read more
Affected Products : kirby- Published: Feb. 22, 2024
- Modified: Aug. 21, 2025
-
7.1
HIGHCVE-2024-26482
An HTML injection vulnerability exists in the Edit Content Layout module of Kirby CMS v4.1.0. NOTE: the vendor disputes the significance of this report because some HTML formatting (such as with an H1 element) is allowed, but there is backend sanitization... Read more
Affected Products : kirby- Published: Feb. 22, 2024
- Modified: Aug. 21, 2025