CVE Feed

    Dashboard / CVE

    4.6
    Medium

    CVE-2024-12915

    Last Modified: 1 Jun 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Devinim Software Library Software allows Reflected XSS. This issue affects Library Software: before 24.11.02.

    Published: 30 Jun 2025
    2.1
    Low

    CVE-2025-6913

    Last Modified: 8 Jul 2025

    A vulnerability classified as critical has been found in PHPGurukul Student Record System 3.2. Affected is an unknown function of the file /admin-profile.php. The manipulation of the argument aemailid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jun 2025
    2.1
    Low

    CVE-2025-6912

    Last Modified: 8 Jul 2025

    A vulnerability was found in PHPGurukul Student Record System 3.2. It has been rated as critical. This issue affects some unknown processing of the file /manage-students.php. The manipulation of the argument del leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jun 2025
    5.4
    Medium

    CVE-2025-2895

    Last Modified: 24 Aug 2025

    IBM Cloud Pak System 2.3.3.6, 2.3.36 iFix1, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, 2.3.4.1, and 2.3.4.1 iFix1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.

    Published: 30 Jun 2025
    2.1
    Low

    CVE-2025-6911

    Last Modified: 8 Jul 2025

    A vulnerability was found in PHPGurukul Student Record System 3.2. It has been declared as critical. This vulnerability affects unknown code of the file /manage-subjects.php. The manipulation of the argument del leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jun 2025
    2.1
    Low

    CVE-2025-6910

    Last Modified: 8 Jul 2025

    A vulnerability was found in PHPGurukul Student Record System 3.2. It has been classified as critical. This affects an unknown part of the file /session.php. The manipulation of the argument session leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jun 2025
    2.1
    Low

    CVE-2025-6909

    Last Modified: 8 Jul 2025

    A vulnerability has been found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/add-scdetails.php. The manipulation of the argument emeradd leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jun 2025
    2.1
    Low

    CVE-2025-6908

    Last Modified: 8 Jul 2025

    A vulnerability, which was classified as critical, was found in PHPGurukul Old Age Home Management System 1.0. Affected is an unknown function of the file /admin/edit-services.php. The manipulation of the argument sertitle leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jun 2025
    5.5
    Medium

    CVE-2025-6907

    Last Modified: 1 Jul 2025

    A vulnerability classified as critical was found in code-projects Car Rental System 1.0. This vulnerability affects unknown code of the file /book_car.php. The manipulation of the argument fname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jun 2025
    5.5
    Medium

    CVE-2025-6906

    Last Modified: 1 Jul 2025

    A vulnerability classified as critical has been found in code-projects Car Rental System 1.0. This affects an unknown part of the file /login.php. The manipulation of the argument uname leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jun 2025
    5.5
    Medium

    CVE-2025-6905

    Last Modified: 11 Jul 2025

    A vulnerability, which was classified as critical, has been found in code-projects Car Rental System 1.0. This issue affects some unknown processing of the file /signup.php. The manipulation of the argument fname leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jun 2025
    6.8
    Medium

    CVE-2025-4407

    Last Modified: 15 Apr 2026

    Insufficient Session Expiration vulnerability in ABB Lite Panel Pro.This issue affects Lite Panel Pro: through 1.0.1.

    Published: 30 Jun 2025
    5.5
    Medium

    CVE-2025-6904

    Last Modified: 11 Jul 2025

    A vulnerability was found in code-projects Car Rental System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/add_cars.php. The manipulation of the argument car_name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jun 2025
    2.3
    Low

    CVE-2025-40710

    Last Modified: 15 Apr 2026

    Host Header Injection (HHI) vulnerability in the Hotspot Shield VPN client, which can induce unexpected behaviour when accessing third-party web applications through the VPN tunnel. Although such applications do not present this vulnerability per se, the use of the tunnel, together with a forged Host header, can cause the VPN client to redirect or forward HTTP requests to servers other than those originally intended, leading to consequences such as open redirects or delivery of traffic to infrastructure controlled by an attacker. This does not imply a flaw in the target applications, but in how the VPN client internally handles outgoing headers and requests.

    Published: 30 Jun 2025
    5.5
    Medium

    CVE-2025-6903

    Last Modified: 11 Jul 2025

    A vulnerability was found in code-projects Car Rental System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/approve.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jun 2025
    5.5
    Medium

    CVE-2025-6902

    Last Modified: 8 Jul 2025

    A vulnerability was found in code-projects Inventory Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /php_action/editUser.php. The manipulation of the argument edituserName leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jun 2025
    7.5
    High

    CVE-2024-8419

    Last Modified: 15 Apr 2026

    The endpoint hosts a script that allows an unauthorized remote attacker to put the system in a fail-safe state over the network due to missing authentication.

    Published: 30 Jun 2025
    5.5
    Medium

    CVE-2025-6901

    Last Modified: 8 Jul 2025

    A vulnerability was found in code-projects Inventory Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /php_action/removeUser.php. The manipulation of the argument userid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jun 2025
    5.1
    Medium

    CVE-2025-41439

    Last Modified: 15 Apr 2026

    A reflected cross-site scripting vulnerability via a specific parameter exists in SLNX Help Documentation of RICOH Streamline NX. If this vulnerability is exploited, an arbitrary script may be executed in the web browser of the user who accessed the product.

    Published: 30 Jun 2025
    7.8
    High

    CVE-2025-53416

    Last Modified: 15 Apr 2026

    Delta Electronics DTN Soft Project File Parsing Deserialization of Untrusted Data Remote Code Execution

    Published: 30 Jun 2025
    7.8
    High

    CVE-2025-53415

    Last Modified: 15 Apr 2026

    Delta Electronics DTM Soft Project File Parsing Deserialization of Untrusted Data Remote Code Execution

    Published: 30 Jun 2025
    2.1
    Low

    CVE-2025-6900

    Last Modified: 6 Jul 2025

    A vulnerability has been found in code-projects Library System 1.0 and classified as critical. This vulnerability affects unknown code of the file /add-book.php. The manipulation of the argument image leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jun 2025
    2.1
    Low

    CVE-2025-6899

    Last Modified: 14 Jul 2025

    A vulnerability, which was classified as critical, was found in D-Link DI-7300G+ and DI-8200G 17.12.20A1/19.12.25A1. This affects an unknown part of the file msp_info.htm. The manipulation of the argument flag/cmd/iface leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jun 2025
    5.1
    Medium

    CVE-2025-40734

    Last Modified: 7 Jul 2025

    Reflected Cross-Site Scripting (XSS) vulnerability in Daily Expense Manager v1.0. This vulnerability allows an attacker to execute JavaScript code by sending a POST request through the password and confirm_password parameters in /register.php.

    Published: 30 Jun 2025
    5.1
    Medium

    CVE-2025-40733

    Last Modified: 7 Jul 2025

    Reflected Cross-Site Scripting (XSS) vulnerability in Daily Expense Manager v1.0. This vulnerability allows an attacker to execute JavaScript code by sending a POST request through the username parameter in /login.php.

    Published: 30 Jun 2025
    8.7
    High

    CVE-2025-40732

    Last Modified: 7 Jul 2025

    user enumeration vulnerability in Daily Expense Manager v1.0. To exploit this vulnerability a POST request must be sent using the name parameter in /check.php

    Published: 30 Jun 2025
    8.7
    High

    CVE-2025-40731

    Last Modified: 7 Jul 2025

    SQL injection vulnerability in Daily Expense Manager v1.0. This vulnerability allows an attacker to retrieve, create, update and delete databases through the pname, pprice and id parameters in /update.php.

    Published: 30 Jun 2025
    2.1
    Low

    CVE-2025-6898

    Last Modified: 14 Jul 2025

    A vulnerability, which was classified as critical, has been found in D-Link DI-7300G+ 19.12.25A1. Affected by this issue is some unknown functionality of the file in proxy_client.asp. The manipulation of the argument proxy_srv/proxy_lanport/proxy_lanip/proxy_srvport leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jun 2025
    2
    Low

    CVE-2025-6897

    Last Modified: 1 Jul 2025

    A vulnerability classified as critical was found in D-Link DI-7300G+ 19.12.25A1. Affected by this vulnerability is an unknown functionality of the file httpd_debug.asp. The manipulation of the argument Time leads to os command injection. The exploit has been disclosed to the public and may be used.

    Published: 30 Jun 2025
    2.1
    Low

    CVE-2025-6896

    Last Modified: 14 Jul 2025

    A vulnerability classified as critical has been found in D-Link DI-7300G+ 19.12.25A1. Affected is an unknown function of the file wget_test.asp. The manipulation of the argument url leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jun 2025
    5.5
    Medium

    CVE-2025-6891

    Last Modified: 8 Jul 2025

    A vulnerability classified as critical has been found in code-projects Inventory Management System 1.0. Affected is an unknown function of the file /php_action/createUser.php. The manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jun 2025
    2.1
    Low

    CVE-2025-6890

    Last Modified: 8 Jul 2025

    A vulnerability was found in code-projects Movie Ticketing System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /ticketConfirmation.php. The manipulation of the argument Date leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jun 2025
    4.3
    Medium

    CVE-2025-5730

    Last Modified: 1 Jul 2025

    The Contact Form Plugin WordPress plugin before 1.1.29 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks.

    Published: 30 Jun 2025
    6.3
    Medium

    CVE-2025-3745

    Last Modified: 1 Jul 2025

    The WP Lightbox 2 WordPress plugin before 3.0.6.8 does not correctly sanitize the value of the title attribute of links before using them, which may allow malicious users to conduct XSS attacks.

    Published: 30 Jun 2025
    5.5
    Medium

    CVE-2025-6889

    Last Modified: 8 Jul 2025

    A vulnerability was found in code-projects Movie Ticketing System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /logIn.php. The manipulation of the argument postName leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jun 2025
    5.5
    Medium

    CVE-2025-6888

    Last Modified: 8 Jul 2025

    A vulnerability was found in PHPGurukul Teachers Record Management System 2.1. It has been classified as critical. This affects an unknown part of the file /admin/changeimage.php. The manipulation of the argument tid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jun 2025
    7.4
    High

    CVE-2025-6887

    Last Modified: 6 Jul 2025

    A vulnerability was found in Tenda AC5 15.03.06.47 and classified as critical. Affected by this issue is some unknown functionality of the file /goform/SetSysTimeCfg. The manipulation of the argument time/timeZone leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jun 2025
    7.4
    High

    CVE-2025-6886

    Last Modified: 6 Jul 2025

    A vulnerability has been found in Tenda AC5 15.03.06.47 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /goform/openSchedWifi. The manipulation of the argument schedStartTime/schedEndTime leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jun 2025
    5.5
    Medium

    CVE-2025-6885

    Last Modified: 8 Jul 2025

    A vulnerability, which was classified as critical, was found in PHPGurukul Teachers Record Management System 2.1. Affected is an unknown function of the file /admin/edit-teacher-detail.php. The manipulation of the argument tid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jun 2025
    2.1
    Low

    CVE-2025-6884

    Last Modified: 13 Nov 2025

    A vulnerability, which was classified as critical, has been found in code-projects Staff Audit System 1.0. This issue affects some unknown processing of the file /search_index.php. The manipulation of the argument Search leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jun 2025
    2.1
    Low

    CVE-2025-6883

    Last Modified: 13 Nov 2025

    A vulnerability classified as critical was found in code-projects Staff Audit System 1.0. This vulnerability affects unknown code of the file /update_index.php. The manipulation of the argument updateid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jun 2025
    7.4
    High

    CVE-2025-6882

    Last Modified: 14 Jul 2025

    A vulnerability classified as critical has been found in D-Link DIR-513 1.0. This affects an unknown part of the file /goform/formSetWanPPTP. The manipulation of the argument curTime leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 30 Jun 2025
    5.1
    Medium

    CVE-2025-53074

    Last Modified: 3 Jul 2025

    Out-of-bounds Read vulnerability in Samsung Open Source rLottie allows Overflow Buffers.This issue affects rLottie: V0.2.

    Published: 30 Jun 2025
    5.1
    Medium

    CVE-2025-53076

    Last Modified: 3 Jul 2025

    Improper Input Validation vulnerability in Samsung Open Source rLottie allows Overread Buffers.This issue affects rLottie: V0.2.

    Published: 30 Jun 2025
    4.6
    Medium

    CVE-2025-53075

    Last Modified: 8 Jul 2025

    Improper Input Validation vulnerability in Samsung Open Source rLottie allows Path Traversal.This issue affects rLottie: V0.2.

    Published: 30 Jun 2025
    5.1
    Medium

    CVE-2025-0634

    Last Modified: 22 Jan 2026

    Use After Free vulnerability in Samsung Open Source rLottie allows Remote Code Inclusion.This issue affects rLottie: V0.2.

    Published: 30 Jun 2025
    7.4
    High

    CVE-2025-6881

    Last Modified: 8 Jul 2025

    A vulnerability was found in D-Link DI-8100 16.07.21. It has been rated as critical. Affected by this issue is some unknown functionality of the file /pppoe_base.asp of the component jhttpd. The manipulation of the argument mschap_en leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jun 2025
    2.1
    Low

    CVE-2025-6880

    Last Modified: 1 Jul 2025

    A vulnerability classified as critical has been found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the file /panel/edit-tax.php. The manipulation of the argument editid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jun 2025
    2.1
    Low

    CVE-2025-6879

    Last Modified: 1 Jul 2025

    A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /panel/add-tax.php. The manipulation of the argument Name leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jun 2025
    2.1
    Low

    CVE-2025-6878

    Last Modified: 1 Jul 2025

    A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /panel/search-appointment.php. The manipulation of the argument searchdata leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jun 2025