Search

Found 33,989 results in 1290ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-13442 critical 9.8 9.8 7mo ago A security vulnerability has been detected in UTT 进取 750W up to 3.2.2-191225. Affected by this vulnerability is the function system of the file /goform/formPdbUpConfig. Such manipulation of the argum…
CVE-2025-13424 critical 9.8 9.8 campcodes 7mo ago A vulnerability has been found in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /admin/add_product.php. The manipulation of the argument txtProductName leads …
CVE-2025-13422 critical 9.8 9.8 darkseid 7mo ago A vulnerability was detected in freeprojectscodes Sports Club Management System 1.0. The affected element is an unknown function of the file /dashboard/admin/change_s_pwd.php. Performing manipulation…
CVE-2025-47914 unknown FIX debian debian sles 7mo ago SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the program to panic if the message is malformed due to an out of bounds read.
CVE-2025-13421 critical 9.8 9.8 angeljudesuarez 7mo ago A security vulnerability has been detected in itsourcecode Human Resource Management System 1.0. Impacted is an unknown function of the file /src/store/NoticeStore.php. Such manipulation of the argum…
CVE-2025-13420 critical 9.8 9.8 angeljudesuarez 7mo ago A weakness has been identified in itsourcecode Human Resource Management System 1.0. This issue affects some unknown processing of the file /src/store/EventStore.php. This manipulation of the argumen…
CVE-2025-58181 unknown FIX debian debian sles 7mo ago SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.
CVE-2025-13411 critical 9.8 9.8 campcodes 7mo ago A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/admin_football.php. Performing a manipula…
CVE-2025-13410 critical 9.8 9.8 campcodes 7mo ago A vulnerability has been found in Campcodes Retro Basketball Shoes Online Store 1.0. Affected is an unknown function of the file /admin/receipt.php. Such manipulation of the argument tid leads to sql…
CVE-2025-13396 critical 9.8 9.8 carmelogarcia 7mo ago A weakness has been identified in code-projects Courier Management System 1.0. This affects an unknown function of the file /add-office.php. This manipulation of the argument OfficeName causes sql in…
CVE-2025-64408 unknown 7mo ago Apache Causeway vulnerable to deserialization in Java
CVE-2025-10437 critical 9.8 9.8 7mo ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eksagate Electronic Engineering and Computer Industry Trade Inc. Webpack Management System allows…
CVE-2025-12119 unknown FIX debian debian 7mo ago A mongoc_bulk_operation_t may read invalid memory if large options are passed.
CVE-2025-13223 unknown 1.5 KEVFIX debian debian 7mo ago Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2025-65089 unknown 7mo ago XWiki view file macro: User can view content of office file without view rights on the attachment
CVE-2025-12383 unknown 7mo ago Eclipse Jersey has a Race Condition
CVE-2025-65015 unknown FIX debian debian 7mo ago joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In versions from 1.3.3 to before 1.3.5 and from 1.4.0 to before 1.4.2, the …
CVE-2025-54990 unknown 7mo ago XWiki AdminTools application doesn't set permissions on the AdminTools space
CVE-2025-13344 critical 9.8 9.8 oretnom23 7mo ago A weakness has been identified in SourceCodester Train Station Ticketing System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=login. This manipulation o…
CVE-2025-13323 critical 9.8 9.8 carmelo 7mo ago A security flaw has been discovered in code-projects Simple Pizza Ordering System 1.0. Affected is an unknown function of the file /listorder.php. Performing manipulation of the argument ID results i…
CVE-2025-58034 unknown 2.5 KEVEXP 7mo ago Fortinet FortiWeb contains an OS command Injection vulnerability that may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI comman…
CVE-2025-13303 critical 9.8 9.8 carmelogarcia 7mo ago A vulnerability was determined in code-projects Courier Management System 1.0. Affected by this issue is some unknown functionality of the file /search-edit.php. This manipulation of the argument Con…
CVE-2025-13302 critical 9.8 9.8 carmelogarcia 7mo ago A vulnerability was identified in code-projects Courier Management System 1.0. This affects an unknown part of the file /add-new-officer.php. Such manipulation of the argument ManagerName leads to sq…
CVE-2025-13301 critical 9.8 9.8 itsourcecode 7mo ago A vulnerability was found in itsourcecode Web-Based Internet Laboratory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /subject/controller.php. The mani…
CVE-2025-13300 critical 9.8 9.8 itsourcecode 7mo ago A vulnerability has been found in itsourcecode Web-Based Internet Laboratory Management System 1.0. Affected is an unknown function of the file /settings/controller.php. The manipulation leads to sql…
CVE-2025-13299 critical 9.8 9.8 itsourcecode 7mo ago A flaw has been found in itsourcecode Web-Based Internet Laboratory Management System 1.0. This impacts an unknown function of the file /user/controller.php. Executing a manipulation can lead to sql …
CVE-2025-13298 critical 9.8 9.8 itsourcecode 7mo ago A vulnerability was detected in itsourcecode Web-Based Internet Laboratory Management System 1.0. This affects an unknown function of the file /enrollment/controller.php. Performing a manipulation re…
CVE-2025-13297 critical 9.8 9.8 itsourcecode 7mo ago A security vulnerability has been detected in itsourcecode Web-Based Internet Laboratory Management System 1.0. The impacted element is an unknown function of the file /course/controller.php. Such ma…
CVE-2025-13291 critical 9.8 9.8 campcodes 7mo ago A vulnerability was found in Campcodes Supplier Management System 1.0. This affects an unknown part of the file /manufacturer/confirm_order.php. Performing a manipulation of the argument ID results i…
CVE-2025-13285 critical 9.8 9.8 angeljudesuarez 7mo ago A vulnerability was identified in itsourcecode Online Voting System 1.0. The affected element is an unknown function of the file /login.php. Such manipulation of the argument Username leads to sql in…
CVE-2025-13280 critical 9.8 9.8 codeastro 7mo ago A vulnerability was determined in CodeAstro Simple Inventory System 1.0. The impacted element is an unknown function of the file /index.php of the component Login. Executing a manipulation of the arg…
CVE-2025-13277 critical 9.8 9.8 fabian 7mo ago A flaw has been found in code-projects Nero Social Networking Site 1.0. This issue affects some unknown processing of the file /friendsphoto.php. This manipulation of the argument ID causes sql injec…
CVE-2025-65073 unknown FIX debian debian 7mo ago OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization.
CVE-2025-13272 critical 9.8 9.8 campcodes 7mo ago A vulnerability was identified in Campcodes School Fees Payment Management System 1.0. Affected is an unknown function of the file /manage_course.php. Such manipulation of the argument ID leads to sq…
CVE-2025-13271 critical 9.8 9.8 campcodes 7mo ago A vulnerability was determined in Campcodes School Fees Payment Management System 1.0. This impacts an unknown function of the file /ajax.php?action=login. This manipulation of the argument Username …
CVE-2025-13267 critical 9.8 9.8 jkev 7mo ago A vulnerability was detected in SourceCodester Dental Clinic Appointment Reservation System 1.0. Impacted is an unknown function of the file /success.php. Performing manipulation of the argument user…
CVE-2025-13266 unknown 7mo ago vlife-base has Path Traversal vulnerability
CVE-2025-13265 unknown 7mo ago lsFusion Server is vulnerable to Path Traversal through its unpackFile function
CVE-2025-13261 unknown 7mo ago lsFusion Platform has a Path Traversal vulnerability
CVE-2025-13262 critical 9.8 9.8 lsfusion 7mo ago lsFusion Platform has a Path Traversal vulnerability
CVE-2025-13257 critical 9.8 9.8 janobe 7mo ago A security vulnerability has been detected in itsourcecode Inventory Management System 1.0. The affected element is an unknown function of the file /admin/user/index.php?view=edit. The manipulation o…
CVE-2025-47151 critical 9.5 FIX rocky rheldebian debian 7mo ago RHSA-2025:21628: lasso security update (Critical)
CVE-2025-13248 critical 9.8 9.8 pamzey 7mo ago A weakness has been identified in SourceCodester Patients Waiting Area Queue Management System 1.0. The impacted element is an unknown function of the file /php/api_patient_schedule.php. This manipul…
CVE-2025-13247 critical 9.8 9.8 phpgurukul 7mo ago A security flaw has been discovered in PHPGurukul Tourism Management System 1.0. The affected element is an unknown function of the file /admin/user-bookings.php. The manipulation of the argument uid…
CVE-2025-13242 critical 9.8 9.8 fabian 7mo ago A vulnerability has been found in code-projects Student Information System 2.0. This issue affects some unknown processing of the file /register.php. The manipulation leads to sql injection. The atta…
CVE-2025-13241 critical 9.8 9.8 fabian 7mo ago A flaw has been found in code-projects Student Information System 2.0. This vulnerability affects unknown code of the file /index.php. Executing manipulation of the argument Username can lead to sql …
CVE-2025-13240 critical 9.8 9.8 fabian 7mo ago A vulnerability was detected in code-projects Student Information System 2.0. This affects an unknown part of the file /searchquery.php. Performing manipulation of the argument s results in sql injec…
CVE-2025-13237 critical 9.8 9.8 janobe 7mo ago A security flaw has been discovered in itsourcecode Inventory Management System 1.0. Affected is an unknown function of the file /LogSignModal.PHP. The manipulation of the argument U_USERNAME results…
CVE-2025-13236 critical 9.8 9.8 janobe 7mo ago A vulnerability was identified in itsourcecode Inventory Management System 1.0. This impacts an unknown function of the file /admin/products/index.php?view=edit. The manipulation of the argument ID l…
CVE-2025-13235 critical 9.8 9.8 janobe 7mo ago A vulnerability was determined in itsourcecode Inventory Management System 1.0. This affects an unknown function of the file /admin/login.php. Executing manipulation of the argument user_email can le…
CVE-2025-13234 critical 9.8 9.8 janobe 7mo ago A vulnerability was found in itsourcecode Inventory Management System 1.0. The impacted element is an unknown function of the file /index.php?q=product. Performing manipulation of the argument PROID …
CVE-2025-13233 critical 9.8 9.8 janobe 7mo ago A vulnerability has been found in itsourcecode Inventory Management System 1.0. The affected element is an unknown function of the file /index.php?q=single-item. Such manipulation of the argument ID …
CVE-2025-13210 critical 9.8 9.8 janobe 7mo ago A security vulnerability has been detected in itsourcecode Inventory Management System 1.0. This impacts an unknown function of the file /admin/products/index.php?view=add. Such manipulation of the a…
CVE-2025-13203 critical 9.8 9.8 fabian 7mo ago A weakness has been identified in code-projects Simple Cafe Ordering System 1.0. This vulnerability affects unknown code of the file /addmem.php. Executing manipulation of the argument studentnum can…
CVE-2025-13201 critical 9.8 9.8 fabian 7mo ago A vulnerability was identified in code-projects Simple Cafe Ordering System 1.0. Affected by this issue is some unknown functionality of the file /login.php. Such manipulation of the argument Usernam…
CVE-2025-13170 critical 9.8 9.8 fabian 7mo ago A vulnerability was detected in code-projects Simple Online Hotel Reservation System 1.0. This issue affects some unknown processing of the file /admin/edit_account.php. Performing a manipulation of …
CVE-2025-13169 critical 9.8 9.8 fabian 7mo ago A security vulnerability has been detected in code-projects Simple Online Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /add_query_reserve.php. Such manipulation o…
CVE-2025-13168 critical 9.8 9.8 ury 7mo ago A weakness has been identified in ury-erp ury up to 0.2.0. This affects the function overrided_past_order_list of the file ury/ury/api/pos_extend.py. This manipulation of the argument search_term cau…
CVE-2025-64446 unknown 2.5 KEVEXP 7mo ago Fortinet FortiWeb contains a relative path traversal vulnerability that may allow an unauthenticated attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.
CVE-2025-13123 critical 9.8 9.8 amttgroup 7mo ago A flaw has been found in AMTT Hotel Broadband Operation System 1.0. The impacted element is an unknown function of the file /user/portal/get_firstdate.php. Executing manipulation of the argument uid …
CVE-2025-13122 critical 9.8 9.8 pamzey 7mo ago A vulnerability was detected in SourceCodester Patients Waiting Area Queue Management System 1.0. The affected element is the function getPatientAppointment of the file /php/api_patient_checkin.php. …
CVE-2025-64507 unknown FIX debian debian 7mo ago Incus is a system container and virtual machine manager. An issue in versions prior to 6.0.6 and 6.19.0 affects any Incus user in an environment where an unprivileged user may have root access to a c…
CVE-2025-13076 critical 9.8 9.8 fabian 7mo ago A flaw has been found in code-projects Responsive Hotel Site 1.0. The affected element is an unknown function of the file /admin/usersetting.php. Executing manipulation of the argument usname can lea…
CVE-2025-13075 critical 9.8 9.8 fabian 7mo ago A vulnerability was detected in code-projects Responsive Hotel Site 1.0. Impacted is an unknown function of the file /admin/usersettingdel.php. Performing manipulation of the argument eid results in …
CVE-2025-64500 unknown FIX debian debian 7mo ago Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundation component defines an object-oriented layer for the HTTP specification. Start…
CVE-2025-64099 unknown 7mo ago OpenAM: Using arbitrary OIDC requested claims values in id_token and user_info is allowed
CVE-2025-62780 unknown 7mo ago changedetection.io: Stored XSS in Watch update via API
CVE-2025-63396 unknown debian debian 7mo ago An issue was discovered in PyTorch v2.5 and v2.7.1. Omission of profiler.stop() can cause torch.profiler.profile (PythonTracer) to crash or hang during finalization, leading to a Denial of Service (D…
CVE-2025-13060 critical 9.8 9.8 oretnom23 7mo ago A security vulnerability has been detected in SourceCodester Survey Application System 1.0. This affects an unknown function of the file /view_survey.php. Such manipulation of the argument ID leads t…
CVE-2025-13059 critical 9.8 9.8 oretnom23 7mo ago A weakness has been identified in SourceCodester Alumni Management System 1.0. The impacted element is an unknown function of the file /manage_career.php. This manipulation of the argument ID causes …
CVE-2025-13057 critical 9.8 9.8 campcodes 7mo ago A vulnerability was identified in Campcodes School Fees Payment Management System 1.0. Impacted is an unknown function of the file /ajax.php?action=save_student. The manipulation of the argument ID l…
CVE-2025-40163 unknown FIX slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: sched/deadline: Stop dl_server before CPU goes offline IBM CI tool reported kernel warning[1] when running a CPU removal operatio…
CVE-2025-9242 unknown 1.5 KEV 7mo ago WatchGuard Firebox contains an out-of-bounds write vulnerability in the OS iked process that may allow a remote unauthenticated attacker to execute arbitrary code.
CVE-2025-62215 unknown 2.5 KEVEXP 7mo ago Microsoft Windows Kernel contains a race condition vulnerability that allows a local attacker with low-level privileges to escalate privileges. Successful exploitation of this vulnerability could ena…
CVE-2025-12480 unknown 1.5 KEV 7mo ago Gladinet Triofox contains an improper access control vulnerability that allows access to initial setup pages even after setup is complete.
CVE-2025-60724 critical 9.8 9.8 FIX windows windows microsoft 7mo ago Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
CVE-2025-64518 unknown 7mo ago CycloneDX Core (Java): BOM validation is vulnerable to XML External Entity injection
CVE-2025-12939 critical 9.8 9.8 janobe 7mo ago A security flaw has been discovered in SourceCodester Interview Management System up to 1.0. Affected by this issue is some unknown functionality of the file /addCandidate.php. The manipulation of th…
CVE-2025-12938 critical 9.8 9.8 projectworlds 7mo ago A vulnerability was identified in projectworlds Online Admission System 1.0. Affected by this vulnerability is an unknown functionality of the file /process_login.php. The manipulation of the argumen…
CVE-2025-12933 critical 9.8 9.8 janobe 7mo ago A vulnerability was identified in SourceCodester Baby Care System 1.0. This affects an unknown part of the file /updatewelcome.php?id=siteoptions&action=welcome. Such manipulation of the argument rol…
CVE-2025-12932 critical 9.8 9.8 janobe 7mo ago A vulnerability was determined in SourceCodester Baby Care System 1.0. Affected by this issue is some unknown functionality of the file /admin.php?id=inbox. This manipulation of the argument msgid ca…
CVE-2025-12931 critical 9.8 9.8 janobe 7mo ago A vulnerability was found in SourceCodester Food Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file /routers/edit-orders.php. The manipulation of the argument…
CVE-2025-12930 critical 9.8 9.8 janobe 7mo ago A vulnerability has been found in SourceCodester Food Ordering System 1.0. Affected is an unknown function of the file /view-ticket.php. The manipulation of the argument ID leads to sql injection. It…
CVE-2025-12929 critical 9.8 9.8 oretnom23 7mo ago A flaw has been found in SourceCodester Survey Application System 1.0. This impacts the function save_user/update_user of the file /LoginRegistration.php. Executing manipulation of the argument fulln…
CVE-2025-12928 critical 9.8 9.8 fabian 7mo ago A vulnerability was detected in code-projects Online Job Search Engine 1.0. This affects an unknown function of the file /login.php. Performing manipulation of the argument username/phone results in …
CVE-2025-21042 unknown 1.5 KEV 7mo ago Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so. This vulnerability could allow remote attackers to execute arbitrary code.
CVE-2025-12916 critical 9.8 9.8 sangfor 7mo ago A vulnerability was determined in Sangfor Operation and Maintenance Security Management System 3.0. Impacted is an unknown function of the file /fort/portal_login of the component Frontend. This mani…
CVE-2025-12913 critical 9.8 9.8 fabian 7mo ago A flaw has been found in code-projects Responsive Hotel Site 1.0. This affects an unknown part of the file /admin/roomdel.php. Executing manipulation of the argument ID can lead to sql injection. It …
CVE-2025-12873 critical 9.8 9.8 campcodes 7mo ago A security flaw has been discovered in Campcodes School File Management 1.0. This affects an unknown part of the file /admin/update_user.php. Performing manipulation of the argument user_id results i…
CVE-2025-12862 critical 9.8 9.8 projectworlds 7mo ago A vulnerability was identified in projectworlds Online Notes Sharing Platform 1.0. Affected by this issue is some unknown functionality of the file /dashboard/userprofile.php. Such manipulation of th…
CVE-2025-12857 critical 9.8 9.8 fabian 7mo ago A security vulnerability has been detected in code-projects Responsive Hotel Site 1.0. The affected element is an unknown function of the file /admin/roombook.php. Such manipulation of the argument r…
CVE-2025-12856 critical 9.8 9.8 fabian 7mo ago A weakness has been identified in code-projects Responsive Hotel Site 1.0. Impacted is an unknown function of the file /admin/reservation.php. This manipulation of the argument email causes sql injec…
CVE-2025-12855 critical 9.8 9.8 fabian 7mo ago A security flaw has been discovered in code-projects Responsive Hotel Site 1.0. This issue affects some unknown processing of the file /admin/newsletterdel.php. The manipulation of the argument eid r…
CVE-2025-12853 critical 9.8 9.8 mayurik 7mo ago A vulnerability was determined in SourceCodester Best House Rental Management System 1.0. This affects the function delete_house of the file /admin_class.php. Executing manipulation of the argument I…
CVE-2025-67897 unknown FIX debian debian 7mo ago In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted me…
CVE-2025-48089 critical 9.3 9.3 7mo ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rainbow-Themes Education WordPress Theme | HiStudy histudy allows SQL Injection.This issue affect…
CVE-2025-64326 unknown 7mo ago Weblate leaks the IP of project member inviting user to be reviewer in Audit log
CVE-2025-10713 unknown 7mo ago WSO2 Carbon Mediation vulnerable to XML External Entity (XXE) attacks
CVE-2025-64459 unknown 1.0 EXPFIX debian debian 7mo ago Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.
CVE-2025-64458 unknown FIX debian debian 7mo ago Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows