CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2025-41652

    Last Modified: 15 Apr 2026

    The devices are vulnerable to an authentication bypass due to flaws in the authorization mechanism. An unauthenticated remote attacker could exploit this weakness by performing brute-force attacks to guess valid credentials or by using MD5 collision techniques to forge authentication hashes, potentially compromising the device.

    Published: 27 May 2025
    9.8
    Critical

    CVE-2025-41651

    Last Modified: 15 Apr 2026

    Due to missing authentication on a critical function of the devices an unauthenticated remote attacker can execute arbitrary commands, potentially enabling unauthorized upload or download of configuration files and leading to full system compromise.

    Published: 27 May 2025
    7.5
    High

    CVE-2025-41650

    Last Modified: 15 Apr 2026

    An unauthenticated remote attacker can exploit input validation in cmd services of the devices, allowing them to disrupt system operations and potentially cause a denial-of-service.

    Published: 27 May 2025
    7.5
    High

    CVE-2025-41649

    Last Modified: 15 Apr 2026

    An unauthenticated remote attacker can exploit insufficient input validation to write data beyond the bounds of a buffer, potentially leading to a denial-of-service condition for the devices.

    Published: 27 May 2025
    Unknown

    CVE-2025-48847

    Last Modified: 28 May 2025

    Not used

    Published: 27 May 2025
    Unknown

    CVE-2025-48848

    Last Modified: 28 May 2025

    Not used

    Published: 27 May 2025
    Unknown

    CVE-2025-48844

    Last Modified: 28 May 2025

    Not used

    Published: 27 May 2025
    Unknown

    CVE-2025-48845

    Last Modified: 28 May 2025

    Not used

    Published: 27 May 2025
    Unknown

    CVE-2025-48846

    Last Modified: 28 May 2025

    Not used

    Published: 27 May 2025
    Unknown

    CVE-2025-48841

    Last Modified: 28 May 2025

    Not used

    Published: 27 May 2025
    Unknown

    CVE-2025-48842

    Last Modified: 28 May 2025

    Not used

    Published: 27 May 2025
    Unknown

    CVE-2025-48843

    Last Modified: 28 May 2025

    Not used

    Published: 27 May 2025
    9.3
    Critical

    CVE-2025-2407

    Last Modified: 15 Apr 2026

    Missing Authentication & Authorization in Web-API in Mobatime AMX MTAPI v6 on IIS allows adversaries to unrestricted access via the network. The vulnerability is fixed in Version 1.5.

    Published: 27 May 2025
    Unknown

    CVE-2025-5242

    Last Modified: 7 Jun 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 27 May 2025
    5.6
    Medium

    CVE-2025-23393

    Last Modified: 15 Apr 2026

    A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in  spacewalk-java allows execution of arbitrary Javascript code on users machines.This issue affects Container suse/manager/5.0/x86_64/server:5.0.4.7.19.1: from ? before 5.0.24-150600.3.25.1; SUSE Manager Server Module 4.3: from ? before 4.3.85-150400.3.105.3.

    Published: 27 May 2025
    5.1
    Medium

    CVE-2024-47090

    Last Modified: 3 Nov 2025

    Improper neutralization of input in Nagvis before version 1.9.47 which can lead to XSS

    Published: 27 May 2025
    5.3
    Medium

    CVE-2024-38866

    Last Modified: 3 Nov 2025

    Improper neutralization of input in Nagvis before version 1.9.47 which can lead to livestatus injection

    Published: 27 May 2025
    5.1
    Medium

    CVE-2025-5232

    Last Modified: 10 Jun 2025

    A vulnerability, which was classified as critical, has been found in PHPGurukul Student Study Center Management System 1.0. This issue affects some unknown processing of the file /admin/report.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 May 2025
    1.2
    Low

    CVE-2025-48382

    Last Modified: 26 Aug 2025

    Fess is a deployable Enterprise Search Server. Prior to version 14.19.2, the createTempFile() method in org.codelibs.fess.helper.SystemHelper creates temporary files without explicitly setting restrictive permissions. This could lead to potential information disclosure, allowing unauthorized local users to access sensitive data contained in these files. This issue primarily affects environments where Fess is deployed in a shared or multi-user context. Typical single-user or isolated deployments have minimal or negligible practical impact. This issue has been patched in version 14.19.2. A workaround for this issue involves ensuring local access to the environment running Fess is restricted to trusted users only.

    Published: 27 May 2025
    6.9
    Medium

    CVE-2025-5231

    Last Modified: 10 Jun 2025

    A vulnerability classified as critical was found in PHPGurukul Company Visitor Management System 1.0. This vulnerability affects unknown code of the file /forgot-password.php. The manipulation of the argument email leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 May 2025
    6.8
    Medium

    CVE-2025-48054

    Last Modified: 15 Apr 2026

    Radashi is a TypeScript utility toolkit. Prior to version 12.5.1, the set function within the Radashi library is vulnerable to prototype pollution. If an attacker can control parts of the path argument to the set function, they could potentially modify the prototype of all objects in the JavaScript runtime, leading to unexpected behavior, denial of service, or even remote code execution in some specific scenarios. This issue has been patched in version 12.5.1. A workaround for this issue involves sanitizing the path argument provided to the set function to ensure that no part of the path string is __proto__, prototype, or constructor.

    Published: 27 May 2025
    6.9
    Medium

    CVE-2025-5230

    Last Modified: 10 Jun 2025

    A vulnerability classified as critical has been found in PHPGurukul Online Nurse Hiring System 1.0. This affects an unknown part of the file /admin/bwdates-report-details.php. The manipulation of the argument fromdate/todate leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 May 2025
    6.9
    Medium

    CVE-2025-5229

    Last Modified: 28 May 2025

    A vulnerability was found in Campcodes Online Hospital Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/view-patient.php. The manipulation of the argument viewid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 May 2025
    8.7
    High

    CVE-2025-5228

    Last Modified: 15 Jul 2025

    A vulnerability was found in D-Link DI-8100 up to 20250523. It has been classified as critical. Affected is the function httpd_get_parm of the file /login.cgi of the component jhttpd. The manipulation of the argument notify leads to stack-based buffer overflow. The attack can only be initiated within the local network. The exploit has been disclosed to the public and may be used.

    Published: 27 May 2025
    6.9
    Medium

    CVE-2025-5227

    Last Modified: 10 Jun 2025

    A vulnerability was found in PHPGurukul Small CRM 3.0 and classified as critical. This issue affects some unknown processing of the file /admin/manage-tickets.php. The manipulation of the argument aremark leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

    Published: 27 May 2025
    6.9
    Medium

    CVE-2025-5226

    Last Modified: 10 Jun 2025

    A vulnerability has been found in PHPGurukul Small CRM 3.0 and classified as critical. This vulnerability affects unknown code of the file /admin/change-password.php. The manipulation of the argument oldpass leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

    Published: 27 May 2025
    6.9
    Medium

    CVE-2025-5225

    Last Modified: 28 May 2025

    A vulnerability, which was classified as critical, was found in Campcodes Advanced Online Voting System 1.0. This affects an unknown part of the file /index.php. The manipulation of the argument voter leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 May 2025
    6.9
    Medium

    CVE-2025-5224

    Last Modified: 28 May 2025

    A vulnerability classified as critical has been found in Campcodes Online Hospital Management System 1.0. Affected is an unknown function of the file /admin/add-doctor.php. The manipulation of the argument Doctorspecialization leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 May 2025
    6.9
    Medium

    CVE-2025-5221

    Last Modified: 24 Jun 2025

    A vulnerability was found in FreeFloat FTP Server 1.0.0. It has been classified as critical. This affects an unknown part of the component QUOTE Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 May 2025
    6.4
    Medium

    CVE-2025-4682

    Last Modified: 20 Apr 2026

    The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML attributes in Slider and Post Carousel widgets in all versions up to, and including, 5.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 27 May 2025
    4.3
    Medium

    CVE-2025-4683

    Last Modified: 20 Apr 2026

    The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create_blog function in all versions up to, and including, 4.17.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create new posts.

    Published: 27 May 2025
    6.9
    Medium

    CVE-2025-5220

    Last Modified: 9 Jun 2025

    A vulnerability was found in FreeFloat FTP Server 1.0.0 and classified as critical. Affected by this issue is some unknown functionality of the component GET Command Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 May 2025
    6.5
    Medium

    CVE-2025-33079

    Last Modified: 26 Aug 2025

    IBM Controller 11.0.0, 11.0.1, and 11.1.0 application could allow an authenticated user to obtain sensitive credentials that may be inadvertently included within the source code.

    Published: 27 May 2025
    6.9
    Medium

    CVE-2025-5219

    Last Modified: 9 Jun 2025

    A vulnerability has been found in FreeFloat FTP Server 1.0.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the component ASCII Command Handler. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 May 2025
    6.9
    Medium

    CVE-2025-5218

    Last Modified: 5 Jun 2025

    A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0.0. Affected is an unknown function of the component LITERAL Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 May 2025
    6.9
    Medium

    CVE-2025-5217

    Last Modified: 5 Jun 2025

    A vulnerability, which was classified as critical, has been found in FreeFloat FTP Server 1.0.0. This issue affects some unknown processing of the component RMDIR Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 May 2025
    6.9
    Medium

    CVE-2025-5216

    Last Modified: 5 Jun 2025

    A vulnerability classified as critical was found in PHPGurukul Student Record System 3.20. This vulnerability affects unknown code of the file /login.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 May 2025
    8.7
    High

    CVE-2025-5215

    Last Modified: 5 Jun 2025

    A vulnerability classified as critical has been found in D-Link DCS-5020L 1.01_B2. This affects the function websReadEvent of the file /rame/ptdc.cgi. The manipulation of the argument Authorization leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 27 May 2025
    4.4
    Medium

    CVE-2025-5278

    Last Modified: 22 Sept 2026

    A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.

    Published: 27 May 2025
    7.5
    High

    CVE-2025-5262

    Last Modified: 19 Sept 2025

    A double-free could have occurred in `vpx_codec_enc_init_multi` after a failed allocation when initializing the encoder for WebRTC. This could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 139 and Thunderbird < 128.11.

    Published: 27 May 2025
    6.5
    Medium

    CVE-2024-49197

    Last Modified: 25 Jun 2025

    An issue was discovered in Wi-Fi in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, W920, W930, and W1000. Lack of a boundary check in STOP_KEEP_ALIVE_OFFLOAD leads to out-of-bounds access.

    Published: 27 May 2025
    6.5
    Medium

    CVE-2025-22377

    Last Modified: 25 Jun 2025

    An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. A Heap-based Out-of-Bounds Write exists in the GPRS protocol implementation because of a mismatch between the actual length of the payload and the length declared within the payload.

    Published: 27 May 2025
    6.4
    Medium

    CVE-2025-48744

    Last Modified: 9 Jun 2025

    In SIGB PMB before 8.0.1.2, attackers can achieve Local File Inclusion and remote code execution.

    Published: 27 May 2025
    7.5
    High

    CVE-2024-49196

    Last Modified: 20 Jun 2025

    An issue was discovered in the GPU in Samsung Mobile Processor Exynos 1480 and 2400. Type confusion leads to a Denial of Service.

    Published: 27 May 2025
    3.7
    Low

    CVE-2025-26211

    Last Modified: 18 Jul 2025

    Gibbon before 29.0.00 allows CSRF.

    Published: 27 May 2025
    5.4
    Medium

    CVE-2025-45475

    Last Modified: 24 Jun 2025

    maccms10 v2025.1000.4047 is vulnerable to Server-Side request forgery (SSRF) in Friend Link Management.

    Published: 27 May 2025
    7.1
    High

    CVE-2025-45529

    Last Modified: 30 Jun 2025

    An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSCMS v7.3.1 allows attackers to read arbitrary files via sending a crafted GET request to /cms/templates/templatesAssetsEditor.

    Published: 27 May 2025
    6.1
    Medium

    CVE-2025-46173

    Last Modified: 10 Jun 2025

    code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) via the name field in the feedback form.

    Published: 27 May 2025
    5.4
    Medium

    CVE-2025-48742

    Last Modified: 26 Nov 2025

    The installer in SIGB PMB before and fixed in v.8.0.1.2 allows remote code execution.

    Published: 27 May 2025
    5.3
    Medium

    CVE-2025-48743

    Last Modified: 9 Jun 2025

    SIGB PMB before 8.0.1.2 allows SQL injection.

    Published: 27 May 2025