CVE Feed

    Dashboard / CVE

    4
    Medium

    CVE-2025-32094

    Last Modified: 15 Apr 2026

    An issue was discovered in Akamai Ghost, as used for the Akamai CDN platform before 2025-03-26. Under certain circumstances, a client making an HTTP/1.x OPTIONS request with an "Expect: 100-continue" header, and using obsolete line folding, can lead to a discrepancy in how two in-path Akamai servers interpret the request, allowing an attacker to smuggle a second request in the original request body.

    Published: 7 Aug 2025
    6.5
    Medium

    CVE-2024-42048

    Last Modified: 15 Apr 2026

    OpenOrange Business Framework version 1.15.5 installs to a directory with overly permissive access control, allowing all authenticated users to write to the installation path. In combination with the application's behavior of loading DLLs from this location, this allows for DLL hijacking and may result in arbitrary code execution and privilege escalation.

    Published: 7 Aug 2025
    8.1
    High

    CVE-2025-47219

    Last Modified: 12 May 2026

    In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_trak function may read past the end of a heap buffer while parsing an MP4 file, possibly leading to information disclosure.

    Published: 7 Aug 2025
    5.6
    Medium

    CVE-2025-47806

    Last Modified: 17 Mar 2026

    In GStreamer through 1.26.1, the subparse plugin's parse_subrip_time function may write data past the bounds of a stack buffer, leading to a crash.

    Published: 7 Aug 2025
    5.6
    Medium

    CVE-2025-47808

    Last Modified: 17 Mar 2026

    In GStreamer through 1.26.1, the subparse plugin's tmplayer_parse_line function may dereference a NULL pointer while parsing a subtitle file, leading to a crash.

    Published: 7 Aug 2025
    6.4
    Medium

    CVE-2025-55134

    Last Modified: 15 Apr 2026

    In Agora Foundation Agora fall23-Alpha1 before b087490, there is XSS via tag in client/agora/public/js/editorManager.js.

    Published: 7 Aug 2025
    6.4
    Medium

    CVE-2025-55133

    Last Modified: 15 Apr 2026

    In Agora Foundation Agora fall23-Alpha1 before b087490, there is XSS via topicName in client/agora/public/js/editorManager.js.

    Published: 7 Aug 2025
    6.4
    Medium

    CVE-2025-55135

    Last Modified: 15 Apr 2026

    In Agora Foundation Agora fall23-Alpha1 before 690ce56, there is XSS via a profile picture to server/controller/userController.js. Formats other than PNG, JPEG, and WEBP are permitted by server/routes/userRoutes.js; this includes SVG.

    Published: 7 Aug 2025
    4.3
    Medium

    CVE-2025-54397

    Last Modified: 12 Aug 2025

    Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 inserts Sensitive Information Into Sent Data to authenticated users.

    Published: 7 Aug 2025
    5.4
    Medium

    CVE-2025-54396

    Last Modified: 12 Aug 2025

    Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows SQL Injection. Authenticated users can exploit this.

    Published: 7 Aug 2025
    6.1
    Medium

    CVE-2025-54395

    Last Modified: 12 Aug 2025

    Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication configuration data.

    Published: 7 Aug 2025
    5.3
    Medium

    CVE-2025-54394

    Last Modified: 12 Aug 2025

    Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 has Insufficiently Protected Credentials for requests to remote Excel resources.

    Published: 7 Aug 2025
    6.1
    Medium

    CVE-2025-54392

    Last Modified: 12 Aug 2025

    Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication error data, a different vulnerability than CVE-2025-47189.

    Published: 7 Aug 2025
    6.1
    Medium

    CVE-2023-41519

    Last Modified: 13 Aug 2025

    Student Attendance Management System v1 was discovered to contain a cross-site scripting (XSS) vulnerability via the sessionName parameter at createSessionTerm.php.

    Published: 7 Aug 2025
    8.8
    High

    CVE-2023-41520

    Last Modified: 13 Aug 2025

    Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createClassArms.php via the classId and classArmName parameters.

    Published: 7 Aug 2025
    9.8
    Critical

    CVE-2023-41528

    Last Modified: 12 Aug 2025

    Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in contact.php via the txtname, txtphone, and txtmail parameters.

    Published: 7 Aug 2025
    6.5
    Medium

    CVE-2025-47188

    Last Modified: 15 Apr 2026

    A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones through 6.4 SP4 (R6.4.0.4006), and the 6970 Conference Unit through 6.4 SP4 (R6.4.0.4006) or version V1 R0.1.0, could allow an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization. A successful exploit could allow an attacker to execute arbitrary commands within the context of the phone, leading to disclosure or modification of sensitive configuration data or affecting device availability and operation.

    Published: 7 Aug 2025
    5.4
    Medium

    CVE-2025-54393

    Last Modified: 12 Aug 2025

    Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows Static Code Injection. Authenticated users can obtain administrative access.

    Published: 7 Aug 2025
    6.5
    Medium

    CVE-2023-40992

    Last Modified: 11 Aug 2025

    Hospital Management System 4 is vulnerable to a SQL injection in /Hospital-Management-System-master/func.php via the password2 parameter.

    Published: 7 Aug 2025
    9.8
    Critical

    CVE-2023-41527

    Last Modified: 11 Aug 2025

    Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the password2 parameter in func.php.

    Published: 7 Aug 2025
    8.8
    High

    CVE-2023-41521

    Last Modified: 13 Aug 2025

    Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createSessionTerm.php via the id, termId, and sessionName parameters.

    Published: 7 Aug 2025
    8.8
    High

    CVE-2023-41522

    Last Modified: 13 Aug 2025

    Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createStudents.php via the Id, firstname, and admissionNumber parameters.

    Published: 7 Aug 2025
    8.8
    High

    CVE-2023-41523

    Last Modified: 13 Aug 2025

    Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the emailAddress parameter at createClassTeacher.php.

    Published: 7 Aug 2025
    8.8
    High

    CVE-2023-41524

    Last Modified: 13 Aug 2025

    Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the username parameter at index.php.

    Published: 7 Aug 2025
    9.8
    Critical

    CVE-2023-41525

    Last Modified: 12 Aug 2025

    Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the patient_contact parameter in patientsearch.php.

    Published: 7 Aug 2025
    9.8
    Critical

    CVE-2023-41526

    Last Modified: 12 Aug 2025

    Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func1.php via the username3 and password3 parameters.

    Published: 7 Aug 2025
    6.1
    Medium

    CVE-2023-41529

    Last Modified: 11 Aug 2025

    Hospital Management System v4 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in func2.php via the fname and lname parameters.

    Published: 7 Aug 2025
    9.8
    Critical

    CVE-2023-41530

    Last Modified: 12 Aug 2025

    Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the app_contact parameter in appsearch.php.

    Published: 7 Aug 2025
    8.8
    High

    CVE-2023-41531

    Last Modified: 12 Aug 2025

    Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func3.php via the username1 and password2 parameters.

    Published: 7 Aug 2025
    8.8
    High

    CVE-2023-41532

    Last Modified: 11 Aug 2025

    Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the doctor_contact parameter in doctorsearch.php.

    Published: 7 Aug 2025
    6.1
    Medium

    CVE-2024-52680

    Last Modified: 14 Aug 2025

    EyouCMS 1.6.7 is vulnerable to Cross Site Scripting (XSS) in /login.php?m=admin&c=System&a=web&lang=cn.

    Published: 7 Aug 2025
    6.5
    Medium

    CVE-2024-55401

    Last Modified: 1 Oct 2025

    An issue in 4C Strategies Exonaut before v22.4 allows attackers to execute a directory traversal.

    Published: 7 Aug 2025
    7.4
    High

    CVE-2025-55137

    Last Modified: 15 Apr 2026

    LinkJoin through 882f196 mishandles lacks type checking in password reset.

    Published: 7 Aug 2025
    7.4
    High

    CVE-2025-55138

    Last Modified: 15 Apr 2026

    LinkJoin through 882f196 mishandles token ownership in password reset.

    Published: 7 Aug 2025
    6.6
    Medium

    CVE-2025-44779

    Last Modified: 14 Aug 2025

    An issue in Ollama v0.1.33 allows attackers to delete arbitrary files via sending a crafted packet to the endpoint /api/pull.

    Published: 7 Aug 2025
    9.1
    Critical

    CVE-2025-45765

    Last Modified: 15 Apr 2026

    ruby-jwt v3.0.0.beta1 was discovered to contain weak encryption. NOTE: the Supplier's perspective is "keysize is not something that is enforced by this library. Currently more recent versions of OpenSSL are enforcing some key sizes and those restrictions apply to the users of this gem also."

    Published: 7 Aug 2025
    6.6
    Medium

    CVE-2025-47183

    Last Modified: 17 Mar 2026

    In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_tree function may read past the end of a heap buffer while parsing an MP4 file, leading to information disclosure.

    Published: 7 Aug 2025
    5.5
    Medium

    CVE-2025-47807

    Last Modified: 17 Mar 2026

    In GStreamer through 1.26.1, the subparse plugin's subrip_unescape_formatting function may dereference a NULL pointer while parsing a subtitle file, leading to a crash.

    Published: 7 Aug 2025
    4.8
    Medium

    CVE-2025-48709

    Last Modified: 18 Dec 2025

    BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated attacker with shell access could observe these credentials and use them to log in to the database server. For example, when Control-M/Server on Windows has a database connection on, it runs 'DBUStatus.exe' frequently, which then calls 'dbu_connection_details.vbs' with the username, password, database hostname, and port written in cleartext, which can be seen in event and process logs in two separate locations. Fixed in PACTV.9.0.21.307.

    Published: 7 Aug 2025
    9.8
    Critical

    CVE-2025-50692

    Last Modified: 14 Aug 2025

    FoxCMS <=v1.2.5 is vulnerable to Code Execution in admin/template_file/editFile.html.

    Published: 7 Aug 2025
    6.5
    Medium

    CVE-2025-50952

    Last Modified: 29 Dec 2025

    openjpeg v 2.5.0 was discovered to contain a NULL pointer dereference via the component /openjp2/dwt.c.

    Published: 7 Aug 2025
    5.3
    Medium

    CVE-2025-51533

    Last Modified: 1 Oct 2025

    An Insecure Direct Object Reference (IDOR) in Sage DPW v2024_12_004 and below allows unauthorized attackers to access internal forms via sending a crafted GET request.

    Published: 7 Aug 2025
    8.8
    High

    CVE-2025-51629

    Last Modified: 15 Apr 2026

    A cross-site scripting (XSS) vulnerability in the PdfViewer component of Agenzia Impresa Eccobook 2.81.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Temp parameter.

    Published: 7 Aug 2025
    8.8
    High

    CVE-2025-54788

    Last Modified: 14 Aug 2025

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions and below, the InboundEmail module allows the arbitrary execution of queries in the backend database, leading to SQL injection. This can have wide-reaching implications on confidentiality, integrity, and availability, as database data can be retrieved, modified, or removed entirely. This issue is fixed in version 7.14.7.

    Published: 6 Aug 2025
    5.3
    Medium

    CVE-2025-54786

    Last Modified: 14 Aug 2025

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, the broken authentication in the legacy iCal service allows unauthenticated access to meeting data. An unauthenticated actor can view any user's meeting (calendar event) data given their username, related functionality allows user enumeration. This is fixed in versions 7.14.7 and 8.8.1.

    Published: 6 Aug 2025
    8.8
    High

    CVE-2025-54785

    Last Modified: 13 Aug 2025

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, user-supplied input is not validated/sanitized before it is passed to the unserialize function, which could lead to penetration, privilege escalation, sensitive data exposure, Denial of Service, cryptomining and ransomware. This issue is fixed in version 7.14.7 and 8.8.1.

    Published: 6 Aug 2025
    8.7
    High

    CVE-2025-7770

    Last Modified: 15 Apr 2026

    Tigo Energy's CCA device is vulnerable to insecure session ID generation in their remote API. The session IDs are generated using a predictable method based on the current timestamp, allowing attackers to recreate valid session IDs. When combined with the ability to circumvent session ID requirements for certain commands, this enables unauthorized access to sensitive device functions on connected solar optimization systems.

    Published: 6 Aug 2025
    7.8
    High

    CVE-2025-6634

    Last Modified: 26 Feb 2026

    A maliciously crafted TGA file, when linked or imported into Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

    Published: 6 Aug 2025
    7.8
    High

    CVE-2025-6633

    Last Modified: 26 Feb 2026

    A maliciously crafted RBG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

    Published: 6 Aug 2025
    8.7
    High

    CVE-2025-7769

    Last Modified: 15 Apr 2026

    Tigo Energy's CCA is vulnerable to a command injection vulnerability in the /cgi-bin/mobile_api endpoint when the DEVICE_PING command is called, allowing remote code execution due to improper handling of user input. When used with default credentials, this enables attackers to execute arbitrary commands on the device that could cause potential unauthorized access, service disruption, and data exposure.

    Published: 6 Aug 2025