CVE Feed

    Dashboard / CVE

    4.6
    Medium

    CVE-2025-53075

    Last Modified: 8 Jul 2025

    Improper Input Validation vulnerability in Samsung Open Source rLottie allows Path Traversal.This issue affects rLottie: V0.2.

    Published: 30 Jun 2025
    5.1
    Medium

    CVE-2025-0634

    Last Modified: 22 Jan 2026

    Use After Free vulnerability in Samsung Open Source rLottie allows Remote Code Inclusion.This issue affects rLottie: V0.2.

    Published: 30 Jun 2025
    7.4
    High

    CVE-2025-6881

    Last Modified: 8 Jul 2025

    A vulnerability was found in D-Link DI-8100 16.07.21. It has been rated as critical. Affected by this issue is some unknown functionality of the file /pppoe_base.asp of the component jhttpd. The manipulation of the argument mschap_en leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jun 2025
    2.1
    Low

    CVE-2025-6880

    Last Modified: 1 Jul 2025

    A vulnerability classified as critical has been found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the file /panel/edit-tax.php. The manipulation of the argument editid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jun 2025
    2.1
    Low

    CVE-2025-6879

    Last Modified: 1 Jul 2025

    A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /panel/add-tax.php. The manipulation of the argument Name leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jun 2025
    2.1
    Low

    CVE-2025-6878

    Last Modified: 1 Jul 2025

    A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /panel/search-appointment.php. The manipulation of the argument searchdata leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Jun 2025
    5.8
    Medium

    CVE-2025-49493

    Last Modified: 15 Apr 2026

    Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection.

    Published: 30 Jun 2025
    7.8
    High

    CVE-2025-38090

    Last Modified: 30 Jul 2026

    In the Linux kernel, the following vulnerability has been resolved: drivers/rapidio/rio_cm.c: prevent possible heap overwrite In riocm_cdev_ioctl(RIO_CM_CHAN_SEND) -> cm_chan_msg_send() -> riocm_ch_send() cm_chan_msg_send() checks that userspace didn't send too much data but riocm_ch_send() failed to check that userspace sent sufficient data. The result is that riocm_ch_send() can write to fields in the rio_ch_chan_hdr which were outside the bounds of the space which cm_chan_msg_send() allocated. Address this by teaching riocm_ch_send() to check that the entire rio_ch_chan_hdr was copied in from userspace.

    Published: 30 Jun 2025
    9.8
    Critical

    CVE-2025-38089

    Last Modified: 30 Jul 2026

    In the Linux kernel, the following vulnerability has been resolved: sunrpc: handle SVC_GARBAGE during svc auth processing as auth error tianshuo han reported a remotely-triggerable crash if the client sends a kernel RPC server a specially crafted packet. If decoding the RPC reply fails in such a way that SVC_GARBAGE is returned without setting the rq_accept_statp pointer, then that pointer can be dereferenced and a value stored there. If it's the first time the thread has processed an RPC, then that pointer will be set to NULL and the kernel will crash. In other cases, it could create a memory scribble. The server sunrpc code treats a SVC_GARBAGE return from svc_authenticate or pg_authenticate as if it should send a GARBAGE_ARGS reply. RFC 5531 says that if authentication fails that the RPC should be rejected instead with a status of AUTH_ERR. Handle a SVC_GARBAGE return as an AUTH_ERROR, with a reason of AUTH_BADCRED instead of returning GARBAGE_ARGS in that case. This sidesteps the whole problem of touching the rpc_accept_statp pointer in this situation and avoids the crash.

    Published: 30 Jun 2025
    9.3
    Critical

    CVE-2025-32463

    Last Modified: 26 Feb 2026

    Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.

    Published: 30 Jun 2025
    6.5
    Medium

    CVE-2023-47310

    Last Modified: 15 Apr 2026

    A misconfiguration in the default settings of MikroTik RouterOS 7 and fixed in v7.14 allows incoming IPv6 UDP traceroute packets.

    Published: 30 Jun 2025
    2.8
    Low

    CVE-2025-32462

    Last Modified: 3 Nov 2025

    Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on unintended machines.

    Published: 30 Jun 2025
    7.5
    High

    CVE-2024-53621

    Last Modified: 15 Apr 2026

    A buffer overflow in the formSetCfm() function of Tenda AC1206 1200M 11ac US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

    Published: 30 Jun 2025
    9.8
    Critical

    CVE-2025-26074

    Last Modified: 15 Apr 2026

    Orkes Conductor v3.21.11 allows remote attackers to execute arbitrary OS commands through unrestricted access to Java classes.

    Published: 30 Jun 2025
    7.8
    High

    CVE-2025-38087

    Last Modified: 19 Nov 2025

    In the Linux kernel, the following vulnerability has been resolved: net/sched: fix use-after-free in taprio_dev_notifier Since taprio’s taprio_dev_notifier() isn’t protected by an RCU read-side critical section, a race with advance_sched() can lead to a use-after-free. Adding rcu_read_lock() inside taprio_dev_notifier() prevents this.

    Published: 30 Jun 2025
    7.1
    High

    CVE-2025-38088

    Last Modified: 17 Dec 2025

    In the Linux kernel, the following vulnerability has been resolved: powerpc/powernv/memtrace: Fix out of bounds issue in memtrace mmap memtrace mmap issue has an out of bounds issue. This patch fixes the by checking that the requested mapping region size should stay within the allocated region size.

    Published: 30 Jun 2025
    9.8
    Critical

    CVE-2025-45931

    Last Modified: 13 Jul 2025

    An issue D-Link DIR-816-A2 DIR-816A2_FWv1.10CNB05_R1B011D88210 allows a remote attacker to execute arbitrary code via system() function in the bin/goahead file

    Published: 30 Jun 2025
    8.8
    High

    CVE-2025-46014

    Last Modified: 15 Oct 2025

    Several services in Honor Device Co., Ltd Honor PC Manager v16.0.0.118 was discovered to connect services to the named pipe iMateBookAssistant with default or overly permissive security attributes, leading to a privilege escalation.

    Published: 30 Jun 2025
    5.8
    Medium

    CVE-2025-52491

    Last Modified: 15 Apr 2026

    Akamai CloudTest before 60 2025.06.09 (12989) allows SSRF.

    Published: 30 Jun 2025
    5.3
    Medium

    CVE-2025-6920

    Last Modified: 20 Nov 2025

    A flaw was found in the authentication enforcement mechanism of a model inference API in ai-inference-server. All /v1/* endpoints are expected to enforce API key validation. However, the POST /invocations endpoint failed to do so, resulting in an authentication bypass. This vulnerability allows unauthorized users to access the same inference features available on protected endpoints, potentially exposing sensitive functionality or allowing unintended access to backend resources.

    Published: 30 Jun 2025
    7
    High

    CVE-2025-45143

    Last Modified: 18 Oct 2025

    string-math v1.2.2 was discovered to contain a Regex Denial of Service (ReDoS) which is exploited via a crafted input.

    Published: 30 Jun 2025
    2.1
    Low

    CVE-2025-6877

    Last Modified: 1 Jul 2025

    A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been classified as critical. This affects an unknown part of the file /panel/edit-category.php. The manipulation of the argument editid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Jun 2025
    2.1
    Low

    CVE-2025-6876

    Last Modified: 1 Jul 2025

    A vulnerability was found in SourceCodester Best Salon Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /panel/add-category.php. The manipulation of the argument Name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Jun 2025
    2.1
    Low

    CVE-2025-6875

    Last Modified: 1 Jul 2025

    A vulnerability has been found in SourceCodester Best Salon Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /panel/edit-subscription.php. The manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Jun 2025
    2.1
    Low

    CVE-2025-6874

    Last Modified: 1 Jul 2025

    A vulnerability, which was classified as critical, was found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the file /panel/add_subscribe.php. The manipulation of the argument user_id/plan_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Jun 2025
    2
    Low

    CVE-2025-6873

    Last Modified: 1 Jul 2025

    A vulnerability, which was classified as critical, has been found in SourceCodester Simple Company Website 1.0. This issue affects some unknown processing of the file /classes/Users.php?f=save. The manipulation of the argument img leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Jun 2025
    2
    Low

    CVE-2025-6872

    Last Modified: 1 Jul 2025

    A vulnerability classified as critical was found in SourceCodester Simple Company Website 1.0. This vulnerability affects unknown code of the file /classes/SystemSettings.php?f=update_settings. The manipulation of the argument img leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Jun 2025
    5.5
    Medium

    CVE-2025-6871

    Last Modified: 1 Jul 2025

    A vulnerability classified as critical has been found in SourceCodester Simple Company Website 1.0. This affects an unknown part of the file /classes/Login.php. The manipulation of the argument Username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Jun 2025
    2
    Low

    CVE-2025-6870

    Last Modified: 1 Jul 2025

    A vulnerability was found in SourceCodester Simple Company Website 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /classes/Content.php?f=service. The manipulation of the argument img leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Jun 2025
    2
    Low

    CVE-2025-6869

    Last Modified: 8 Jul 2025

    A vulnerability was found in SourceCodester Simple Company Website 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/testimonials/manage.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Jun 2025
    6.8
    Medium

    CVE-2025-24292

    Last Modified: 15 Apr 2026

    A misconfigured query in UniFi Network (v9.1.120 and earlier) could allow users to authenticate to Enterprise WiFi or VPN Server (l2tp and OpenVPN) using a device’s MAC address from 802.1X or MAC Authentication, if both services are enabled and share the same RADIUS profile.

    Published: 29 Jun 2025
    9.9
    Critical

    CVE-2025-24290

    Last Modified: 15 Apr 2026

    Multiple Authenticated SQL Injection vulnerabilities found in UISP Application (Version 2.4.206 and earlier) could allow a malicious actor with low privileges to escalate privileges.

    Published: 29 Jun 2025
    7.5
    High

    CVE-2025-24289

    Last Modified: 15 Apr 2026

    A Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) vulnerability in the UCRM Client Signup Plugin (v1.3.4 and earlier) could allow privilege escalation if an Administrator is tricked into visiting a crafted malicious page. The plugin is disabled by default.

    Published: 29 Jun 2025
    2
    Low

    CVE-2025-6868

    Last Modified: 8 Jul 2025

    A vulnerability was found in SourceCodester Simple Company Website 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/clients/manage.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Jun 2025
    2
    Low

    CVE-2025-6867

    Last Modified: 8 Jul 2025

    A vulnerability was found in SourceCodester Simple Company Website 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/services/manage.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Jun 2025
    2.1
    Low

    CVE-2025-6866

    Last Modified: 23 Oct 2025

    A vulnerability has been found in code-projects Simple Forum 1.0 and classified as critical. This vulnerability affects unknown code of the file /forum_downloadfile.php. The manipulation of the argument filename leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Jun 2025
    2.1
    Low

    CVE-2025-6865

    Last Modified: 6 Jul 2025

    A vulnerability, which was classified as problematic, was found in DaiCuo up to 1.3.13. This affects an unknown part of the file /admin.php/addon/index. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Jun 2025
    2.1
    Low

    CVE-2025-6864

    Last Modified: 6 Jul 2025

    A vulnerability, which was classified as problematic, has been found in SeaCMS up to 13.2. Affected by this issue is some unknown functionality of the file /admin_type.php. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Jun 2025
    5.5
    Medium

    CVE-2025-6863

    Last Modified: 6 Jul 2025

    A vulnerability classified as critical was found in PHPGurukul Local Services Search Engine Management System 2.1. Affected by this vulnerability is an unknown functionality of the file /admin/edit-category-detail.php. The manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Jun 2025
    2.1
    Low

    CVE-2025-6862

    Last Modified: 1 Jul 2025

    A vulnerability classified as critical has been found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the file /panel/edit_plan.php. The manipulation of the argument editid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Jun 2025
    2.1
    Low

    CVE-2025-6861

    Last Modified: 1 Jul 2025

    A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /panel/add_plan.php. The manipulation of the argument plan_name/description/duration_days/price leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Jun 2025
    2.1
    Low

    CVE-2025-6860

    Last Modified: 1 Jul 2025

    A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /panel/staff_commision.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Jun 2025
    2.1
    Low

    CVE-2025-6859

    Last Modified: 8 Jul 2025

    A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been classified as critical. This affects an unknown part of the file /panel/pro_sale.php. The manipulation of the argument fromdate/todate leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Jun 2025
    6.1
    Medium

    CVE-2024-24915

    Last Modified: 3 Sept 2025

    Credentials are not cleared from memory after being used. A user with Administrator permissions can execute memory dump for SmartConsole process and fetch them.

    Published: 29 Jun 2025
    5.5
    Medium

    CVE-2025-5878

    Last Modified: 15 Apr 2026

    A vulnerability was found in ESAPI esapi-java-legacy and classified as problematic. This issue affects the interface Encoder.encodeForSQL of the SQL Injection Defense. An attack leads to an improper neutralization of special elements. The attack may be initiated remotely and an exploit has been disclosed to the public. The project was contacted early about this issue and handled it with an exceptional level of professionalism. Upgrading to version 2.7.0.0 is able to address this issue. Commit ID f75ac2c2647a81d2cfbdc9c899f8719c240ed512 is disabling the feature by default and any attempt to use it will trigger a warning. And commit ID e2322914304d9b1c52523ff24be495b7832f6a56 is updating the misleading Java class documentation to warn about the risks.

    Published: 29 Jun 2025
    1.9
    Low

    CVE-2025-6858

    Last Modified: 8 Jul 2025

    A vulnerability was found in HDF5 1.14.6 and classified as problematic. Affected by this issue is the function H5C__flush_single_entry of the file src/H5Centry.c. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.

    Published: 29 Jun 2025
    1.9
    Low

    CVE-2025-6857

    Last Modified: 8 Jul 2025

    A vulnerability has been found in HDF5 1.14.6 and classified as problematic. Affected by this vulnerability is the function H5G__node_cmp3 of the file src/H5Gnode.c. The manipulation leads to stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.

    Published: 29 Jun 2025
    1.9
    Low

    CVE-2025-6856

    Last Modified: 8 Jul 2025

    A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5FL__reg_gc_list of the file src/H5FL.c. The manipulation leads to use after free. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

    Published: 29 Jun 2025
    2
    Low

    CVE-2025-6855

    Last Modified: 31 Oct 2025

    A vulnerability, which was classified as critical, has been found in chatchat-space Langchain-Chatchat up to 0.3.1. This issue affects some unknown processing of the file /v1/file. The manipulation of the argument flag leads to path traversal. The exploit has been disclosed to the public and may be used.

    Published: 29 Jun 2025
    2.1
    Low

    CVE-2025-6854

    Last Modified: 31 Oct 2025

    A vulnerability classified as problematic was found in chatchat-space Langchain-Chatchat up to 0.3.1. This vulnerability affects unknown code of the file /v1/files?purpose=assistants. The manipulation leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 29 Jun 2025