CVE Feed

    Dashboard / CVE

    6.9
    Medium

    CVE-2025-2683

    Last Modified: 27 Mar 2025

    A vulnerability classified as critical was found in PHPGurukul Bank Locker Management System 1.0. This vulnerability affects unknown code of the file /profile.php. The manipulation of the argument mobilenumber leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 24 Mar 2025
    6.9
    Medium

    CVE-2025-2682

    Last Modified: 27 Mar 2025

    A vulnerability classified as critical has been found in PHPGurukul Bank Locker Management System 1.0. This affects an unknown part of the file /edit-subadmin.php?said=3. The manipulation of the argument mobilenumber leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 24 Mar 2025
    6.9
    Medium

    CVE-2025-2681

    Last Modified: 27 Mar 2025

    A vulnerability was found in PHPGurukul Bank Locker Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /edit-locker.php?ltid=6. The manipulation of the argument lockersize leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 24 Mar 2025
    6.9
    Medium

    CVE-2025-2680

    Last Modified: 4 Jun 2025

    A vulnerability was found in PHPGurukul Bank Locker Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /edit-assign-locker.php?ltid=1. The manipulation of the argument mobilenumber leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 24 Mar 2025
    6.9
    Medium

    CVE-2025-2679

    Last Modified: 4 Jun 2025

    A vulnerability was found in PHPGurukul Bank Locker Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /contact-us.php. The manipulation of the argument pagetitle leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 24 Mar 2025
    6.9
    Medium

    CVE-2025-2678

    Last Modified: 4 Jun 2025

    A vulnerability was found in PHPGurukul Bank Locker Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /changeimage1.php. The manipulation of the argument editid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 24 Mar 2025
    3.5
    Low

    CVE-2024-13124

    Last Modified: 13 May 2025

    The Photo Gallery by 10Web WordPress plugin before 1.8.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 24 Mar 2025
    3.5
    Low

    CVE-2024-10558

    Last Modified: 13 May 2025

    The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 24 Mar 2025
    6.9
    Medium

    CVE-2025-2677

    Last Modified: 4 Jun 2025

    A vulnerability has been found in PHPGurukul Bank Locker Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /changeidproof.php. The manipulation of the argument editid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 24 Mar 2025
    6.9
    Medium

    CVE-2025-2676

    Last Modified: 4 Jun 2025

    A vulnerability, which was classified as critical, was found in PHPGurukul Bank Locker Management System 1.0. This affects an unknown part of the file /add-subadmin.php. The manipulation of the argument sadminusername leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 24 Mar 2025
    6.9
    Medium

    CVE-2025-2675

    Last Modified: 26 Mar 2025

    A vulnerability, which was classified as critical, has been found in PHPGurukul Bank Locker Management System 1.0. Affected by this issue is some unknown functionality of the file /add-lockertype.php. The manipulation of the argument lockerprice leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 24 Mar 2025
    6.9
    Medium

    CVE-2025-2674

    Last Modified: 27 Mar 2025

    A vulnerability classified as critical was found in PHPGurukul Bank Locker Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /aboutus.php. The manipulation of the argument pagetitle leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 24 Mar 2025
    8.1
    High

    CVE-2025-29314

    Last Modified: 15 Apr 2026

    Insecure Shiro cookie configurations in OpenDaylight Service Function Chaining (SFC) Subproject SFC Sodium-SR4 and below allow attackers to access sensitive information via a man-in-the-middle attack.

    Published: 24 Mar 2025
    7.1
    High

    CVE-2025-30112

    Last Modified: 15 Apr 2026

    On 70mai Dash Cam 1S devices, by connecting directly to the dashcam's network and accessing the API on port 80 and RTSP on port 554, an attacker can bypass the device authorization mechanism from the official mobile app that requires a user to physically press on the power button during a connection.

    Published: 24 Mar 2025
    9.8
    Critical

    CVE-2025-29310

    Last Modified: 1 Apr 2025

    An issue in onos v2.7.0 allows attackers to trigger a packet deserialization problem when supplying a crafted LLDP packet. This vulnerability allows attackers to execute arbitrary commands or access network information.

    Published: 24 Mar 2025
    6
    Medium

    CVE-2024-55279

    Last Modified: 29 Apr 2025

    Uguu through 1.8.9 allows Cross Site Scripting (XSS) via JavaScript in XML files.

    Published: 24 Mar 2025
    9.8
    Critical

    CVE-2025-29100

    Last Modified: 1 Apr 2025

    Tenda AC8 V16.03.34.06 is vulnerable to Buffer Overflow in the fromSetRouteStatic function via the parameter list.

    Published: 24 Mar 2025
    9.8
    Critical

    CVE-2025-29135

    Last Modified: 1 Apr 2025

    A stack-based buffer overflow vulnerability in Tenda AC7 V15.03.06.44 allows a remote attacker to execute arbitrary code through a stack overflow attack using the security parameter of the formWifiBasicSet function.

    Published: 24 Mar 2025
    —
    Unknown

    CVE-2025-29294

    Last Modified: 24 Mar 2025

    DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 24 Mar 2025
    7.5
    High

    CVE-2025-29313

    Last Modified: 15 Apr 2026

    Use of incorrectly resolved name or reference in OpenDaylight Service Function Chaining (SFC) Subproject SFC Sodium-SR4 and below allows attackers to cause a Denial of Service (DoS).

    Published: 24 Mar 2025
    9.8
    Critical

    CVE-2025-29315

    Last Modified: 15 Apr 2026

    An issue in the Shiro-based RBAC (Role-based Access Control) mechanism of OpenDaylight Service Function Chaining (SFC) Subproject SFC Sodium-SR4 and below allows attackers to execute privileged operations via a crafted request.

    Published: 24 Mar 2025
    7.5
    High

    CVE-2025-29311

    Last Modified: 1 Apr 2025

    Limited secret space in LLDP packets used in onos v2.7.0 allows attackers to obtain the private key via a bruteforce attack. Attackers are able to leverage this vulnerability into creating crafted LLDP packets.

    Published: 24 Mar 2025
    9.1
    Critical

    CVE-2025-29312

    Last Modified: 1 Apr 2025

    An issue in onos v2.7.0 allows attackers to trigger unexpected behavior within a device connected to a legacy switch via changing the link type from indirect to direct.

    Published: 24 Mar 2025
    5.1
    Medium

    CVE-2025-2673

    Last Modified: 14 May 2025

    A vulnerability classified as problematic has been found in code-projects Payroll Management System 1.0. Affected is an unknown function of the file /home_employee.php. The manipulation of the argument division leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

    Published: 23 Mar 2025
    5.3
    Medium

    CVE-2025-2672

    Last Modified: 14 May 2025

    A vulnerability was found in code-projects Payroll Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /add_deductions.php. The manipulation of the argument bir leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

    Published: 23 Mar 2025
    5.4
    Medium

    CVE-2018-25109

    Last Modified: 15 Apr 2026

    A vulnerability has been found in Nintendo Animal Crossing, Doubutsu no Mori+ and Doubutsu no Mori e+ 1.00/1.01 on GameCube and classified as critical. Affected by this vulnerability is an unknown functionality of the component Letter Trigram Handler. The manipulation leads to memory corruption. It is possible to launch the attack on the physical device. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.

    Published: 23 Mar 2025
    5.3
    Medium

    CVE-2025-2671

    Last Modified: 15 Apr 2026

    A vulnerability was found in Yue Lao Blind Box 月老盲盒 up to 4.0. It has been declared as critical. This vulnerability affects the function base64image of the file /app/controller/Upload.php. The manipulation of the argument data leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 23 Mar 2025
    6.9
    Medium

    CVE-2025-2665

    Last Modified: 13 May 2025

    A vulnerability was found in PHPGurukul Online Security Guards Hiring System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/bwdates-reports-details.php. The manipulation of the argument fromdate/todate leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 23 Mar 2025
    5.1
    Medium

    CVE-2025-2664

    Last Modified: 13 May 2025

    A vulnerability was found in CodeZips Hospital Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /suadpeted.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 23 Mar 2025
    6.9
    Medium

    CVE-2025-2663

    Last Modified: 13 May 2025

    A vulnerability has been found in PHPGurukul Bank Locker Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /search-locker-details.php. The manipulation of the argument searchinput leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 23 Mar 2025
    5.3
    Medium

    CVE-2025-2662

    Last Modified: 9 Jul 2025

    A vulnerability was found in Project Worlds Online Time Table Generator 1.0. It has been classified as critical. Affected is an unknown function of the file student/studentdashboard.php. The manipulation of the argument course leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 23 Mar 2025
    6.9
    Medium

    CVE-2025-2661

    Last Modified: 9 Jul 2025

    A vulnerability was found in Project Worlds Online Time Table Generator 1.0 and classified as critical. This issue affects some unknown processing of the file /staff/index.php. The manipulation of the argument e leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 23 Mar 2025
    6.9
    Medium

    CVE-2025-2660

    Last Modified: 9 Jul 2025

    A vulnerability has been found in Project Worlds Online Time Table Generator 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/index.php. The manipulation of the argument e leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 23 Mar 2025
    6.9
    Medium

    CVE-2025-2659

    Last Modified: 9 Jul 2025

    A vulnerability, which was classified as critical, was found in Project Worlds Online Time Table Generator 1.0. This affects an unknown part of the file /student/index.php. The manipulation of the argument e leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 23 Mar 2025
    6.9
    Medium

    CVE-2025-2658

    Last Modified: 13 May 2025

    A vulnerability, which was classified as critical, has been found in PHPGurukul Online Security Guards Hiring System 1.0. Affected by this issue is some unknown functionality of the file /search-request.php. The manipulation of the argument searchdata leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 23 Mar 2025
    6.9
    Medium

    CVE-2025-2657

    Last Modified: 13 May 2025

    A vulnerability classified as critical was found in projectworlds Apartment Visitors Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /front.php. The manipulation of the argument rid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 23 Mar 2025
    6.9
    Medium

    CVE-2025-2656

    Last Modified: 13 May 2025

    A vulnerability classified as critical has been found in PHPGurukul Zoo Management System 2.1. Affected is an unknown function of the file /admin/login.php. The manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 23 Mar 2025
    5.5
    Medium

    CVE-2025-2655

    Last Modified: 22 Nov 2025

    A vulnerability was detected in SourceCodester AC Repair and Services System 1.0. The affected element is the function save_users/delete_users of the file /classes/Users.php. Performing manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. Other parameters might be affected as well.

    Published: 23 Mar 2025
    7.8
    High

    CVE-2025-29795

    Last Modified: 26 Feb 2026

    Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.

    Published: 23 Mar 2025
    6.5
    Medium

    CVE-2025-29806

    Last Modified: 26 Feb 2026

    No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

    Published: 23 Mar 2025
    6.9
    Medium

    CVE-2025-2654

    Last Modified: 26 Mar 2025

    A vulnerability was found in SourceCodester AC Repair and Services System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/services/manage_service.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 23 Mar 2025
    5.3
    Medium

    CVE-2025-2653

    Last Modified: 16 Jul 2025

    A vulnerability was found in FoxCMS 1.25 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 23 Mar 2025
    5.5
    Medium

    CVE-2025-0927

    Last Modified: 22 Jan 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Filesystem bugs due to corrupt images are not considered a CVE for any filesystem that is only mountable by CAP_SYS_ADMIN in the initial user namespace. That includes delegated mounting.

    Published: 23 Mar 2025
    6.9
    Medium

    CVE-2025-2652

    Last Modified: 26 Mar 2025

    A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to exposure of information through directory listing. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to change the configuration settings. Multiple sub-directories are affected.

    Published: 23 Mar 2025
    6.9
    Medium

    CVE-2025-2651

    Last Modified: 14 May 2025

    A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /oews/admin/. The manipulation leads to exposure of information through directory listing. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to change the configuration settings. Multiple sub-directories are affected.

    Published: 23 Mar 2025
    7.8
    High

    CVE-2025-2691

    Last Modified: 26 Mar 2025

    Versions of the package nossrf before 1.0.4 are vulnerable to Server-Side Request Forgery (SSRF) where an attacker can provide a hostname that resolves to a local or reserved IP address space and bypass the SSRF protection mechanism.

    Published: 23 Mar 2025
    7.5
    High

    CVE-2025-27553

    Last Modified: 2 Apr 2025

    Relative Path Traversal vulnerability in Apache Commons VFS before 2.10.0. The FileObject API in Commons VFS has a 'resolveFile' method that takes a 'scope' parameter. Specifying 'NameScope.DESCENDENT' promises that "an exception is thrown if the resolved file is not a descendent of the base file". However, when the path contains encoded ".." characters (for example, "%2E%2E/bar.txt"), it might return file objects that are not a descendent of the base file, without throwing an exception. This issue affects Apache Commons VFS: before 2.10.0. Users are recommended to upgrade to version 2.10.0, which fixes the issue.

    Published: 23 Mar 2025
    5
    Medium

    CVE-2025-30474

    Last Modified: 14 Jul 2025

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Commons VFS. The FtpFileObject class can throw an exception when a file is not found, revealing the original URI in its message, which may include a password. The fix is to mask the password in the exception message This issue affects Apache Commons VFS: before 2.10.0. Users are recommended to upgrade to version 2.10.0, which fixes the issue.

    Published: 23 Mar 2025
    5.1
    Medium

    CVE-2025-2650

    Last Modified: 27 Mar 2025

    A vulnerability, which was classified as problematic, has been found in PHPGurukul Medical Card Generation System 1.0. This issue affects some unknown processing of the file /download-medical-cards.php. The manipulation of the argument searchdata leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 23 Mar 2025
    6.9
    Medium

    CVE-2025-2649

    Last Modified: 27 Mar 2025

    A vulnerability classified as critical was found in PHPGurukul Doctor Appointment Management System 1.0. This vulnerability affects unknown code of the file /check-appointment.php. The manipulation of the argument searchdata leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 23 Mar 2025