CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2025-8348

    Last Modified: 12 Sept 2025

    A vulnerability has been found in Kehua Charging Pile Cloud Platform 1.0 and classified as critical. This vulnerability affects unknown code of the file /home. The manipulation leads to improper authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Jul 2025
    2.1
    Low

    CVE-2025-8347

    Last Modified: 12 Sept 2025

    A vulnerability, which was classified as critical, was found in Kehua Charging Pile Cloud Platform 1.0. This affects an unknown part of the file /sys/task/findAllTask. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Jul 2025
    2.1
    Low

    CVE-2025-8346

    Last Modified: 13 Aug 2025

    A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar 2.10. Affected by this issue is some unknown functionality of the file /educar_aluno_lst.php. The manipulation of the argument ref_cod_matricula with the input "><img%20src=x%20onerror=alert(%27CVE-Hunters%27)> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 31 Jul 2025
    2.1
    Low

    CVE-2025-8345

    Last Modified: 28 Aug 2025

    A vulnerability classified as critical was found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.4.7. Affected by this vulnerability is the function delete_user of the file crm/WeiXinApp/yunzhijia/yunzhijiaApi.php. The manipulation of the argument function leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 8.6.5.2 is able to address this issue. It is recommended to upgrade the affected component.

    Published: 31 Jul 2025
    2.1
    Low

    CVE-2025-8344

    Last Modified: 3 Sept 2025

    A vulnerability classified as critical has been found in openviglet shio up to 0.3.8. Affected is the function shStaticFileUpload of the file shio-app/src/main/java/com/viglet/shio/api/staticfile/ShStaticFileAPI.java. The manipulation of the argument filename leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Jul 2025
    2.1
    Low

    CVE-2025-8343

    Last Modified: 3 Sept 2025

    A vulnerability was found in openviglet shio up to 0.3.8. It has been rated as critical. This issue affects the function shStaticFilePreUpload of the file shio-app/src/main/java/com/viglet/shio/api/staticfile/ShStaticFileAPI.java. The manipulation of the argument fileName leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Jul 2025
    2.1
    Low

    CVE-2025-8340

    Last Modified: 5 Aug 2025

    A vulnerability was found in code-projects Intern Membership Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file fill_details.php of the component Error Message Handler. The manipulation of the argument email leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Jul 2025
    5.5
    Medium

    CVE-2025-8339

    Last Modified: 5 Aug 2025

    A vulnerability was found in code-projects Intern Membership Management System 1.0. It has been classified as critical. This affects an unknown part of the file /student_login.php. The manipulation of the argument user_name/password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 31 Jul 2025
    6.1
    Medium

    CVE-2025-51569

    Last Modified: 15 Apr 2026

    A cross-site scripting (XSS) vulnerability exists in the LB-Link BL-CPE300M 01.01.02P42U14_06 router's web interface. The /goform/goform_get_cmd_process endpoint fails to sanitize user input in the cmd parameter before reflecting it into a text/html response. This allows unauthenticated attackers to inject arbitrary JavaScript, which is executed in the context of the router's origin when the crafted URL is accessed. The issue requires user interaction to exploit.

    Published: 31 Jul 2025
    8.8
    High

    CVE-2025-50572

    Last Modified: 15 Apr 2026

    Archer 6.11.00204.10014 allows attackers to execute arbitrary code via crafted system inputs that would be exported into the CSV and be executed after the user opened the file with compatible applications. NOTE: the Supplier does not accept this as a valid vulnerability report against their product.

    Published: 31 Jul 2025
    9.8
    Critical

    CVE-2025-50475

    Last Modified: 15 Apr 2026

    An OS command injection vulnerability exists in Russound MBX-PRE-D67F firmware version 3.1.6, allowing unauthenticated attackers to execute arbitrary commands as root via crafted input to the hostname parameter in network configuration requests. This vulnerability stems from improper neutralization of special elements used in an OS command within the network configuration handler, enabling remote code execution with the highest privileges.

    Published: 31 Jul 2025
    6.1
    Medium

    CVE-2025-50270

    Last Modified: 15 Apr 2026

    A stored Cross Site Scripting (xss) vulnerability in the "content management" feature in AnQiCMS v.3.4.11 allows a remote attacker to execute arbitrary code via a crafted script to the title, categoryTitle, and tmpTag parameters.

    Published: 31 Jul 2025
    6.3
    Medium

    CVE-2024-34328

    Last Modified: 15 Apr 2026

    An open redirect in Sielox AnyWare v2.1.2 allows attackers to execute a man-in-the-middle attack via a crafted URL.

    Published: 31 Jul 2025
    8
    High

    CVE-2025-52289

    Last Modified: 6 Aug 2025

    A Broken Access Control vulnerability in MagnusBilling v7.8.5.3 allows newly registered users to gain escalated privileges by sending a crafted request to /mbilling/index.php/user/save to set their account status fom "pending" to "active" without requiring administrator approval.

    Published: 31 Jul 2025
    7.6
    High

    CVE-2025-52203

    Last Modified: 6 Aug 2025

    A stored cross-site scripting (XSS) vulnerability exists in DevaslanPHP project-management v1.2.4. The vulnerability resides in the Ticket Name field, which fails to properly sanitize user-supplied input. An authenticated attacker can inject malicious JavaScript payloads into this field, which are subsequently stored in the database. When a legitimate user logs in and is redirected to the Dashboard panel "automatically upon authentication the malicious script executes in the user's browser context.

    Published: 31 Jul 2025
    3.5
    Low

    CVE-2025-51384

    Last Modified: 4 Aug 2025

    D-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_net_asp function via the remot_ip parameter.

    Published: 31 Jul 2025
    3.5
    Low

    CVE-2025-51383

    Last Modified: 4 Aug 2025

    D-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_road_asp function via the host_ip parameter.

    Published: 31 Jul 2025
    6.5
    Medium

    CVE-2025-50867

    Last Modified: 6 Aug 2025

    A SQL Injection vulnerability exists in the takeassessment2.php endpoint of the CloudClassroom-PHP-Project 1.0, where the Q5 POST parameter is directly embedded in SQL statements without sanitization.

    Published: 31 Jul 2025
    3.5
    Low

    CVE-2025-51385

    Last Modified: 1 Aug 2025

    D-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the yyxz_dlink_asp function via the id parameter.

    Published: 31 Jul 2025
    7.6
    High

    CVE-2025-51503

    Last Modified: 6 Aug 2025

    A Stored Cross-Site Scripting (XSS) vulnerability in Microweber CMS 2.0 allows attackers to inject malicious scripts into user profile fields, leading to arbitrary JavaScript execution in admin browsers.

    Published: 31 Jul 2025
    7.3
    High

    CVE-2025-26064

    Last Modified: 3 Nov 2025

    A cross-site scripting (XSS) vulnerability in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the name of a connnected device.

    Published: 31 Jul 2025
    6.5
    Medium

    CVE-2024-34327

    Last Modified: 6 Aug 2025

    Sielox AnyWare v2.1.2 was discovered to contain a SQL injection vulnerability via the email address field of the password reset form.

    Published: 31 Jul 2025
    9.8
    Critical

    CVE-2025-26062

    Last Modified: 3 Nov 2025

    An access control issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to access the router's settings file and obtain potentially sensitive information from the current settings.

    Published: 31 Jul 2025
    9.8
    Critical

    CVE-2025-26063

    Last Modified: 3 Nov 2025

    An issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to execute arbitrary code via injecting a crafted payload into the ESSID name when creating a network.

    Published: 31 Jul 2025
    7.3
    High

    CVE-2025-29556

    Last Modified: 15 Apr 2026

    ExaGrid EX10 6.3 - 7.0.1.P08 is vulnerable to Incorrect Access Control. Since version 6.3, ExaGrid enforces restrictions preventing users with the Admin role from creating or modifying users with the Security Officer role without approval. However, a flaw in the account creation process allows an attacker to bypass these restrictions via API request manipulation. An attacker with an Admin access can intercept and modify the API request during user creation, altering the parameters to assign the new account to the ExaGrid Security Officers group without the required approval.

    Published: 31 Jul 2025
    5.4
    Medium

    CVE-2025-29557

    Last Modified: 15 Apr 2026

    ExaGrid EX10 6.3 - 7.0.1.P08 is vulnerable to Incorrect Access Control in the MailConfiguration API endpoint, where users with operator-level privileges can issue an HTTP request to retrieve SMTP credentials, including plaintext passwords.

    Published: 31 Jul 2025
    7
    High

    CVE-2025-45768

    Last Modified: 12 Sept 2025

    pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses the library (admittedly, library users may benefit from a minimum value and a mechanism for opting in to strict enforcement).

    Published: 31 Jul 2025
    6.5
    Medium

    CVE-2025-45769

    Last Modified: 18 Feb 2026

    php-jwt v6.11.0 was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an application, not by this library. This dispute is subject to review under CNA rules 4.1.4, 4.1.14, and other rules; the dispute tagging is not meant to recommend an outcome for this CVE Record.

    Published: 31 Jul 2025
    7
    High

    CVE-2025-45770

    Last Modified: 17 Aug 2025

    jwt v5.4.3 was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an application, not by this library. This dispute is subject to review under CNA rules 4.1.4, 4.1.14, and other rules; the dispute tagging is not meant to recommend an outcome for this CVE Record.

    Published: 31 Jul 2025
    8.6
    High

    CVE-2025-50850

    Last Modified: 6 Aug 2025

    An issue was discovered in CS Cart 4.18.3 allows the vendor login functionality lacks essential security controls such as CAPTCHA verification and rate limiting. This allows an attacker to systematically attempt various combinations of usernames and passwords (brute-force attack) to gain unauthorized access to vendor accounts. The absence of any blocking mechanism makes the login endpoint susceptible to automated attacks.

    Published: 31 Jul 2025
    8
    High

    CVE-2025-50849

    Last Modified: 15 Apr 2026

    CS Cart 4.18.3 is vulnerable to Insecure Direct Object Reference (IDOR). The user profile functionality allows enabling or disabling stickers through a parameter (company_id) sent in the request. However, this operation is not properly validated on the server side. An authenticated user can manipulate the request to target other users' accounts and toggle the sticker setting by modifying the company_id or other object identifiers.

    Published: 31 Jul 2025
    6.5
    Medium

    CVE-2025-50847

    Last Modified: 6 Aug 2025

    Cross Site Request Forgery (CSRF) vulnerability in CS Cart 4.18.3, allows attackers to add products to a user's comparison list via a crafted HTTP request.

    Published: 31 Jul 2025
    6.1
    Medium

    CVE-2025-50848

    Last Modified: 6 Aug 2025

    A file upload vulnerability was discovered in CS Cart 4.18.3, allows attackers to execute arbitrary code. CS Cart 4.18.3 allows unrestricted upload of HTML files, which are rendered directly in the browser when accessed. This allows an attacker to upload a crafted HTML file containing malicious content, such as a fake login form for credential harvesting or scripts for Cross-Site Scripting (XSS) attacks. Since the content is served from a trusted domain, it significantly increases the likelihood of successful phishing or script execution against other users.

    Published: 31 Jul 2025
    6.1
    Medium

    CVE-2025-50866

    Last Modified: 6 Aug 2025

    CloudClassroom-PHP-Project 1.0 contains a reflected Cross-site Scripting (XSS) vulnerability in the email parameter of the postquerypublic endpoint. Improper sanitization allows an attacker to inject arbitrary JavaScript code that executes in the context of the user s browser, potentially leading to session hijacking or phishing attacks.

    Published: 31 Jul 2025
    6.5
    Medium

    CVE-2025-36040

    Last Modified: 6 Aug 2025

    IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms.

    Published: 30 Jul 2025
    6.5
    Medium

    CVE-2025-36039

    Last Modified: 6 Aug 2025

    IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms,

    Published: 30 Jul 2025
    5.1
    Medium

    CVE-2025-49082

    Last Modified: 5 Aug 2025

    CVE-2025-49082 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access to the console and who have been assigned a certain set of permissions can bypass those permissions to improperly read other settings. The attack complexity is low, there are no preexisting attack requirements; the privileges required are high, and there is no user interaction required. The impact to system confidentiality is low, there is no impact to system availability or integrity.

    Published: 30 Jul 2025
    5.1
    Medium

    CVE-2025-54085

    Last Modified: 5 Aug 2025

    CVE-2025-54085 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access to the console and who have been assigned a certain set of permissions can bypass those permissions to improperly read or change other settings. The attack complexity is low, there are no preexisting attack requirements; the privileges required are high, and there is no user interaction required. The impact to system confidentiality and integrity is low, there is no impact to system availability.

    Published: 30 Jul 2025
    5.3
    Medium

    CVE-2025-49084

    Last Modified: 5 Aug 2025

    CVE-2025-49084 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access can overwrite policy rules without the requisite permissions. The attack complexity is low, attack requirements are present, privileges required are high and no user interaction is required. There is no impact to confidentiality, the impact to integrity is low, and there is no impact to availability. The impact to confidentiality and availability of subsequent systems is high and the impact to the integrity of subsequent systems is low.

    Published: 30 Jul 2025
    5.5
    Medium

    CVE-2025-8338

    Last Modified: 6 Aug 2025

    A vulnerability was found in projectworlds Online Admission System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /adminac.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jul 2025
    7
    High

    CVE-2025-49083

    Last Modified: 5 Aug 2025

    CVE-2025-49083 is a vulnerability in the management console of Absolute Secure Access after version 12.00 and prior to version 13.56. Attackers with administrative access to the console can cause unsafe content to be deserialized and executed in the security context of the console. The attack complexity is low and there are no attack requirements. Privileges required are high and there is no user interaction required. The impact to confidentiality is low, impact to integrity is high and there is no impact to availability. The impact to the confidentiality and integrity of subsequent systems is low and there is no subsequent system impact to availability.

    Published: 30 Jul 2025
    1.9
    Low

    CVE-2025-8337

    Last Modified: 5 Aug 2025

    A vulnerability, which was classified as problematic, has been found in code-projects Simple Car Rental System 1.0. This issue affects some unknown processing of the file /admin/add_vehicles.php. The manipulation of the argument car_name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jul 2025
    5.5
    Medium

    CVE-2025-8336

    Last Modified: 6 Aug 2025

    A vulnerability classified as critical was found in Campcodes Online Recruitment Management System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=save_user. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jul 2025
    2.1
    Low

    CVE-2025-8335

    Last Modified: 5 Aug 2025

    A vulnerability classified as problematic has been found in code-projects Simple Car Rental System 1.0. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jul 2025
    5.5
    Medium

    CVE-2025-8334

    Last Modified: 6 Aug 2025

    A vulnerability was found in Campcodes Online Recruitment Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/ajax.php?action=delete_recruitment_status. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jul 2025
    7.1
    High

    CVE-2025-54586

    Last Modified: 1 Aug 2025

    GitProxy is an application that stands between developers and a Git remote endpoint. In versions 1.19.1 and below, attackers can inject extra commits into the pack sent to GitHub, commits that aren’t pointed to by any branch. Although these “hidden” commits never show up in the repository’s visible history, GitHub still serves them at their direct commit URLs. This lets an attacker exfiltrate sensitive data without ever leaving a trace in the branch view. We rate this a High‑impact vulnerability because it completely compromises repository confidentiality. This is fixed in version 1.19.2.

    Published: 30 Jul 2025
    5.5
    Medium

    CVE-2025-8333

    Last Modified: 5 Aug 2025

    A vulnerability was found in code-projects Online Farm System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /categoryvalue.php. The manipulation of the argument Value leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jul 2025
    Unknown

    CVE-2025-8395

    Last Modified: 12 Aug 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 30 Jul 2025
    5.5
    Medium

    CVE-2025-8332

    Last Modified: 5 Aug 2025

    A vulnerability was found in code-projects Online Farm System 1.0. It has been classified as critical. Affected is an unknown function of the file /register.php. The manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jul 2025
    8.2
    High

    CVE-2025-54585

    Last Modified: 1 Aug 2025

    GitProxy is an application that stands between developers and a Git remote endpoint. In versions 1.19.1 and below, attackers can exploit the way GitProxy handles new branch creation to bypass the approval of prior commits on the parent branch. The vulnerability impacts all users or organizations relying on GitProxy to enforce policy and prevent unapproved changes. It requires no elevated privileges beyond regular push access, and no extra user interaction. It does however, require a GitProxy administrator or designated user (canUserApproveRejectPush) to approve pushes to the child branch. This is fixed in version 1.19.2.

    Published: 30 Jul 2025