CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2024-45564

    Last Modified: 26 Feb 2026

    Memory corruption during concurrent access to server info object due to incorrect reference count update.

    Published: 6 May 2025
    6.6
    Medium

    CVE-2024-45563

    Last Modified: 9 May 2025

    Memory corruption while handling schedule request in Camera Request Manager(CRM) due to invalid link count in the corresponding session.

    Published: 6 May 2025
    6.6
    Medium

    CVE-2024-45562

    Last Modified: 11 Aug 2025

    Memory corruption during concurrent access to server info object due to unprotected critical field.

    Published: 6 May 2025
    7.8
    High

    CVE-2024-45554

    Last Modified: 26 Feb 2026

    Memory corruption during concurrent SSR execution due to race condition on the global maps list.

    Published: 6 May 2025
    8.7
    High

    CVE-2025-4342

    Last Modified: 13 May 2025

    A vulnerability, which was classified as critical, has been found in D-Link DIR-600L up to 2.07B01. Affected by this issue is the function formEasySetupWizard3. The manipulation of the argument host leads to buffer overflow. The attack may be launched remotely. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 6 May 2025
    5.3
    Medium

    CVE-2025-4341

    Last Modified: 13 May 2025

    A vulnerability classified as critical was found in D-Link DIR-880L up to 104WWb01. Affected by this vulnerability is the function sub_16570 of the file /htdocs/ssdpcgi of the component Request Header Handler. The manipulation of the argument HTTP_ST/REMOTE_ADDR/REMOTE_PORT/SERVER_ID leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 6 May 2025
    5.4
    Medium

    CVE-2025-3020

    Last Modified: 15 Apr 2026

    An low privileged remote Attacker can execute arbitrary web scripts or HTML via a crafted payload injected into several fields of the configuration webpage with limited impact.

    Published: 6 May 2025
    5.3
    Medium

    CVE-2025-4340

    Last Modified: 13 May 2025

    A vulnerability classified as critical has been found in D-Link DIR-890L and DIR-806A1 up to 100CNb11/108B03. Affected is the function sub_175C8 of the file /htdocs/soap.cgi. The manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 6 May 2025
    5.3
    Medium

    CVE-2025-4333

    Last Modified: 15 Apr 2026

    A vulnerability was found in feng_ha_ha/megagao ssm-erp and production_ssm up to 0.0.1. It has been classified as critical. This affects the function uploadFile of the file src/main/java/com/megagao/production/ssm/service/impl/FileServiceImpl.java. The manipulation of the argument uploadFile leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product is distributed under two entirely different names.

    Published: 6 May 2025
    6.9
    Medium

    CVE-2025-4332

    Last Modified: 30 Sept 2025

    A vulnerability was found in PHPGurukul Company Visitor Management System 2.0 and classified as critical. Affected by this issue is some unknown functionality of the file /visitor-detail.php. The manipulation of the argument editid/remark leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 May 2025
    6.9
    Medium

    CVE-2025-4331

    Last Modified: 27 Sept 2025

    A vulnerability classified as critical was found in SourceCodester Online Student Clearance System 1.0. This vulnerability affects unknown code of the file /Admin/login.php. The manipulation of the argument id/username/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 May 2025
    5.3
    Medium

    CVE-2025-3281

    Last Modified: 15 Apr 2026

    The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.1 via the create_stripe_subscription() function, due to missing validation on the 'member_id' user controlled key. This makes it possible for unauthenticated attackers to delete arbitrary user accounts that have registered through the plugin.

    Published: 6 May 2025
    5.1
    Medium

    CVE-2025-46593

    Last Modified: 26 Sept 2025

    Process residence vulnerability in abnormal scenarios in the print module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 6 May 2025
    4.4
    Medium

    CVE-2025-46592

    Last Modified: 9 May 2025

    Null pointer dereference vulnerability in the USB HDI driver module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 6 May 2025
    6.2
    Medium

    CVE-2025-46591

    Last Modified: 26 Sept 2025

    Out-of-bounds data read vulnerability in the authorization module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 6 May 2025
    6.3
    Medium

    CVE-2025-46590

    Last Modified: 9 May 2025

    Bypass vulnerability in the network search instruction authentication module Impact: Successful exploitation of this vulnerability can bypass authentication and enable access to some network search functions.

    Published: 6 May 2025
    4.4
    Medium

    CVE-2025-46589

    Last Modified: 26 Sept 2025

    Vulnerability of unauthorized access in the app lock module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

    Published: 6 May 2025
    4.4
    Medium

    CVE-2025-46588

    Last Modified: 26 Sept 2025

    Vulnerability of unauthorized access in the app lock module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

    Published: 6 May 2025
    6.2
    Medium

    CVE-2024-58252

    Last Modified: 9 May 2025

    Vulnerability of insufficient information protection in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 6 May 2025
    6.2
    Medium

    CVE-2025-46587

    Last Modified: 9 May 2025

    Permission control vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 6 May 2025
    5.1
    Medium

    CVE-2025-46586

    Last Modified: 26 Sept 2025

    Permission control vulnerability in the contacts module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 6 May 2025
    7.5
    High

    CVE-2025-46585

    Last Modified: 9 May 2025

    Out-of-bounds array read/write vulnerability in the kernel module Impact: Successful exploitation of this vulnerability may affect availability.

    Published: 6 May 2025
    7.8
    High

    CVE-2025-46584

    Last Modified: 9 May 2025

    Vulnerability of improper authentication logic implementation in the file system module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 6 May 2025
    5.3
    Medium

    CVE-2025-4329

    Last Modified: 12 Jun 2025

    A vulnerability was found in 74CMS up to 3.33.0. It has been rated as problematic. Affected by this issue is the function index of the file /index.php/index/download/index. The manipulation of the argument url leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 May 2025
    5.1
    Medium

    CVE-2025-4328

    Last Modified: 15 Apr 2026

    A vulnerability was found in fp2952 spring-cloud-base up to 7f050dc6db9afab82c5ce1d41cd74ed255ec9bfa. It has been declared as problematic. Affected by this vulnerability is the function sendBack of the file /spring-cloud-base-master/auth-center/auth-center-provider/src/main/java/com/peng/auth/provider/config/web/MvcController.java of the component HTTP Header Handler. The manipulation of the argument Referer leads to open redirect. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available.

    Published: 6 May 2025
    5.3
    Medium

    CVE-2025-4327

    Last Modified: 12 Jun 2025

    A vulnerability was found in MRCMS 3.1.2. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Multiple endpoints might be affected.

    Published: 6 May 2025
    8
    High

    CVE-2025-30165

    Last Modified: 31 Jul 2025

    vLLM is an inference and serving engine for large language models. In a multi-node vLLM deployment using the V0 engine, vLLM uses ZeroMQ for some multi-node communication purposes. The secondary vLLM hosts open a `SUB` ZeroMQ socket and connect to an `XPUB` socket on the primary vLLM host. When data is received on this `SUB` socket, it is deserialized with `pickle`. This is unsafe, as it can be abused to execute code on a remote machine. Since the vulnerability exists in a client that connects to the primary vLLM host, this vulnerability serves as an escalation point. If the primary vLLM host is compromised, this vulnerability could be used to compromise the rest of the hosts in the vLLM deployment. Attackers could also use other means to exploit the vulnerability without requiring access to the primary vLLM host. One example would be the use of ARP cache poisoning to redirect traffic to a malicious endpoint used to deliver a payload with arbitrary code to execute on the target machine. Note that this issue only affects the V0 engine, which has been off by default since v0.8.0. Further, the issue only applies to a deployment using tensor parallelism across multiple hosts, which we do not expect to be a common deployment pattern. Since V0 is has been off by default since v0.8.0 and the fix is fairly invasive, the maintainers of vLLM have decided not to fix this issue. Instead, the maintainers recommend that users ensure their environment is on a secure network in case this pattern is in use. The V1 engine is not affected by this issue.

    Published: 6 May 2025
    4.8
    Medium

    CVE-2025-4326

    Last Modified: 17 Jun 2025

    A vulnerability was found in MRCMS 3.1.2 and classified as problematic. This issue affects some unknown processing of the file /admin/chip/add.do of the component Add Fragment Page. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 May 2025
    4.8
    Medium

    CVE-2025-4325

    Last Modified: 17 Jun 2025

    A vulnerability has been found in MRCMS 3.1.2 and classified as problematic. This vulnerability affects unknown code of the file /admin/category/add.do of the component Category Management Page. The manipulation of the argument Name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 May 2025
    4.8
    Medium

    CVE-2025-4324

    Last Modified: 17 Jun 2025

    A vulnerability, which was classified as problematic, was found in MRCMS 3.1.2. This affects an unknown part of the file /admin/link/edit.do of the component External Link Management Page. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 May 2025
    4.8
    Medium

    CVE-2025-4323

    Last Modified: 17 Jun 2025

    A vulnerability, which was classified as problematic, has been found in MRCMS 3.1.2. Affected by this issue is some unknown functionality of the component Edit Article Page. The manipulation of the argument Title leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 May 2025
    6.9
    Medium

    CVE-2025-4314

    Last Modified: 14 May 2025

    A vulnerability has been found in SourceCodester Advanced Web Store 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/index.php. The manipulation of the argument txtLogin leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 May 2025
    6.9
    Medium

    CVE-2025-4313

    Last Modified: 14 May 2025

    A vulnerability, which was classified as critical, was found in SourceCodester Advanced Web Store 1.0. Affected is an unknown function of the file /admin/admin_addnew_product.php. The manipulation of the argument txtProdId leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 May 2025
    7.3
    High

    CVE-2025-2802

    Last Modified: 21 Apr 2026

    The LayoutBoxx plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 0.3.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

    Published: 6 May 2025
    4.3
    Medium

    CVE-2025-4337

    Last Modified: 20 Apr 2026

    The AHAthat Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6. This is due to missing or incorrect nonce validation on the aha_plugin_page() function. This makes it possible for unauthenticated attackers to delete AHA pages via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 6 May 2025
    6.9
    Medium

    CVE-2025-4312

    Last Modified: 14 May 2025

    A vulnerability, which was classified as critical, has been found in SourceCodester Advanced Web Store 1.0. This issue affects some unknown processing of the file /productdetail.php. The manipulation of the argument prodid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 May 2025
    6.9
    Medium

    CVE-2025-4311

    Last Modified: 13 May 2025

    A vulnerability classified as critical was found in itsourcecode Content Management System 1.0. This vulnerability affects unknown code of the file /admin/update_main_topic_img.php?topic_id=529. The manipulation of the argument stopic_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 May 2025
    5.1
    Medium

    CVE-2025-4310

    Last Modified: 13 May 2025

    A vulnerability classified as critical has been found in itsourcecode Content Management System 1.0. This affects an unknown part of the file /admin/add_topic.php?category=BBS. The manipulation of the argument Cover Image leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 May 2025
    6.9
    Medium

    CVE-2025-4309

    Last Modified: 9 May 2025

    A vulnerability was found in PHPGurukul Art Gallery Management System 1.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/add-art-type.php. The manipulation of the argument arttype leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 May 2025
    6.9
    Medium

    CVE-2025-4308

    Last Modified: 13 May 2025

    A vulnerability was found in PHPGurukul Art Gallery Management System 1.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/add-art-type.php. The manipulation of the argument arttype leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 May 2025
    6.9
    Medium

    CVE-2025-4307

    Last Modified: 13 May 2025

    A vulnerability was found in PHPGurukul Art Gallery Management System 1.1. It has been classified as critical. Affected is an unknown function of the file /admin/add-art-medium.php. The manipulation of the argument artmed leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 May 2025
    6.9
    Medium

    CVE-2025-4306

    Last Modified: 13 May 2025

    A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /edit-phlebotomist.php. The manipulation of the argument mobilenumber leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

    Published: 6 May 2025
    5.3
    Medium

    CVE-2025-3609

    Last Modified: 20 Apr 2026

    The Reales WP STPT plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 2.1.2. This is due to the 'reales_user_signup_form' AJAX action not verifying if user registration is enabled, prior to registering a user. This makes it possible for unauthenticated attackers to create new user accounts, which can be leveraged with CVE-XX to achieve privilege escalation.

    Published: 6 May 2025
    8.8
    High

    CVE-2025-3610

    Last Modified: 21 Apr 2026

    The Reales WP STPT plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.1.2. This is due to the plugin not properly validating a user's identity prior to updating their details like password. This makes it possible for authenticated attackers, with subscriber-level access and above, to change arbitrary user's passwords and email addresses, including administrators, and leverage that to gain access to their account. This can be combined with CVE-2025-3609 to achieve remote code execution as an originally unauthenticated user with no account.

    Published: 6 May 2025
    5.3
    Medium

    CVE-2025-4305

    Last Modified: 15 Apr 2026

    A vulnerability has been found in kefaming mayi up to 1.3.9 and classified as critical. This vulnerability affects the function Upload of the file app/tools/controller/File.php. The manipulation of the argument File leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 May 2025
    6.9
    Medium

    CVE-2025-4304

    Last Modified: 13 May 2025

    A vulnerability, which was classified as critical, was found in PHPGurukul Cyber Cafe Management System 1.0. This affects an unknown part of the file /adminprofile.php. The manipulation of the argument mobilenumber leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

    Published: 6 May 2025
    6.2
    Medium

    CVE-2024-39442

    Last Modified: 15 Apr 2026

    In sprd ssense service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

    Published: 6 May 2025
    6.9
    Medium

    CVE-2025-4303

    Last Modified: 8 May 2025

    A vulnerability, which was classified as critical, has been found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. Affected by this issue is some unknown functionality of the file /add-phlebotomist.php. The manipulation of the argument empid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 May 2025
    7.8
    High

    CVE-2025-2509

    Last Modified: 26 Feb 2026

    Out-of-Bounds Read in Virglrenderer in ChromeOS 16093.57.0 allows a malicious guest VM to achieve arbitrary address access within the crosvm sandboxed process, potentially leading to VM escape via crafted vertex elements data triggering an out-of-bounds read in util_format_description.

    Published: 6 May 2025
    7.5
    High

    CVE-2025-46728

    Last Modified: 1 Aug 2025

    cpp-httplib is a C++ header-only HTTP/HTTPS server and client library. Prior to version 0.20.1, the library fails to enforce configured size limits on incoming request bodies when `Transfer-Encoding: chunked` is used or when no `Content-Length` header is provided. A remote attacker can send a chunked request without the terminating zero-length chunk, causing uncontrolled memory allocation on the server. This leads to potential exhaustion of system memory and results in a server crash or unresponsiveness. Version 0.20.1 fixes the issue by enforcing limits during parsing. If the limit is exceeded at any point during reading, the connection is terminated immediately. A short-term workaround through a Reverse Proxy is available. If updating the library immediately is not feasible, deploy a reverse proxy (e.g., Nginx, HAProxy) in front of the `cpp-httplib` application. Configure the proxy to enforce maximum request body size limits, thereby stopping excessively large requests before they reach the vulnerable library code.

    Published: 6 May 2025