Vulnerabilities

Vulnerabilities

  

CVE-2025-6420 | code-projects Simple Online Hotel Reservation System 1.0 /admin/add_room.php room_type sql injection

A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been declared as critical. This vulnerability

  

CVE-2025-6421 | code-projects Simple Online Hotel Reservation System 1.0 /admin/add_account.php Name sql injection

A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been rated as critical. This issue

  

CVE-2025-50054 | OpenVPN ovpn-dco-win up to 1.3.0/2.5.8 Kernel Driver heap-based overflow

A vulnerability classified as critical has been found in OpenVPN ovpn-dco-win up to 1.3.0/2.5.8. This affects an unknown part of

  

CVE-2025-5125 | Custom Post Carousels with Owl Plugin up to 1.4.11 on WordPress cross site scripting

A vulnerability was found in Custom Post Carousels with Owl Plugin up to 1.4.11 on WordPress. It has been rated

  

CVE-2025-6393 | TOTOLINK A702R/A3002R/A3002RU/EX1200T HTTP POST Request /boafrm/formIPv6Addr submit-url buffer overflow

A vulnerability was found in TOTOLINK A702R, A3002R, A3002RU and EX1200T 3.0.0-B20230809.1615/4.0.0-B20230531.1404/4.0.0-B20230721.1521/4.1.2cu.5232_B20210713. It has been classified as critical. Affected is

  

CVE-2025-6394 | code-projects Simple Online Hotel Reservation System 1.0 /add_reserve.php firstname sql injection

A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been declared as critical. Affected by

  

Ubuntu 20.04 LTS USN-7585-2 critical: Linux kernel information exposure

Several security issues were fixed in the Linux kernel.LinuxSecurity – Security AdvisoriesRead More

  

Ubuntu 20.04 LTS: USN-7585-1 critical: Linux kernel security flaws

Several security issues were fixed in the Linux kernel.LinuxSecurity – Security AdvisoriesRead More

  

CVE-2025-48058 | powsybl-core up to 6.7.1 redos (GHSA-rqpx-f6rc-7hm5 / EUVD-2025-18708)

A vulnerability classified as problematic was found in powsybl-core up to 6.7.1. Affected by this vulnerability is an unknown functionality.

  

CVE-2025-6264 | Rapid7 Velociraptor up to 0.74.2 VQL Query Admin.Client.UpdateClientConfig default permission

A vulnerability classified as problematic has been found in Rapid7 Velociraptor up to 0.74.2. Affected is the function Admin.Client.UpdateClientConfig of

  

CVE-2025-49715 | Microsoft Dynamics 365 FastTrack Implementation exposure of private personal information to an unauthorized actor

A vulnerability, which was classified as problematic, has been found in Microsoft Dynamics 365 FastTrack Implementation. Affected by this issue

  

CVE-2025-47771 | powsybl-core up to 6.7.1 SparseMatrix read deserialization (GHSA-f5cx-h789-j959 / EUVD-2025-18706)

A vulnerability, which was classified as very critical, was found in powsybl-core up to 6.7.1. This affects the function read

  

CVE-2025-47293 | powsybl-core up to 6.7.1 XML Parser com.powsybl.commons.xml.XmlReader xml external entity reference (GHSA-qpj9-qcwx-8jv2 / EUVD-2025-18700)

A vulnerability has been found in powsybl-core up to 6.7.1 and classified as critical. This vulnerability affects the function com.powsybl.commons.xml.XmlReader

  

CVE-2025-4102 | Beaver Builder Plugin up to 2.9.1 on WordPress save_enabled_icons unrestricted upload

A vulnerability was found in Beaver Builder Plugin up to 2.9.1 on WordPress and classified as critical. This issue affects

  

SUSE: 2025:02028-1 important: apache2-mod_security2 DoS Fix

* bsc#1243976 * bsc#1243978 Cross-References: * CVE-2025-47947LinuxSecurity – Security AdvisoriesRead More

  

SUSE: 2025:02027-1 moderate risk of DoS vulnerability in Perl

* bsc#1244079 Cross-References: * CVE-2025-40909LinuxSecurity – Security AdvisoriesRead More

  

SUSE: 2025:02026-1 important: pam_pkcs11 security issue

* bsc#1243226 Cross-References: * CVE-2025-6018LinuxSecurity – Security AdvisoriesRead More

  

Ubuntu 25.04: USN-7583-1 important: python file overwrite

Python could be made to overwrite files.LinuxSecurity – Security AdvisoriesRead More

  

CVE-2025-6384 | CrafterCMS up to 4.2.x dynamically-managed code resources (EUVD-2025-18697)

A vulnerability was found in CrafterCMS up to 4.2.x. It has been declared as problematic. This vulnerability affects unknown code.

  

CVE-2025-6257 | Euro FxRef Currency Converter Plugin up to 2.0.2 on WordPress Shortcode currency cross site scripting

A vulnerability was found in Euro FxRef Currency Converter Plugin up to 2.0.2 on WordPress. It has been rated as

  

CVE-2025-33117 | IBM QRadar SIEM up to 7.5.0 Update Package 12 file inclusion

A vulnerability has been found in IBM QRadar SIEM up to 7.5.0 Update Package 12 and classified as critical. Affected

  

CVE-2025-33121 | IBM QRadar SIEM up to 7.5.0 Update Package 12 xml external entity reference

A vulnerability was found in IBM QRadar SIEM up to 7.5.0 Update Package 12 and classified as critical. Affected by

  

CVE-2025-36050 | IBM QRadar SIEM up to 7.5.0 Update Package 12 log file

A vulnerability was found in IBM QRadar SIEM up to 7.5.0 Update Package 12. It has been classified as problematic.

  

CVE-2025-50200 | RabbitMQ Server up to 3.13.7 log file

A vulnerability, which was classified as problematic, was found in RabbitMQ Server up to 3.13.7. Affected is an unknown function.

  

CVE-2025-6375 | poco up to 1.14.1 MultipartReader.cpp MultipartInputStream null pointer dereference (Issue 4915)

A vulnerability was found in poco up to 1.14.1. It has been rated as problematic. Affected by this issue is

  

CVE-2025-52464 | Meshtastic Firmware up to 2.6.10 Direct Message entropy

A vulnerability classified as problematic has been found in Meshtastic Firmware up to 2.6.10. This affects an unknown part of

  

CVE-2025-6218 | Rarlab WinRAR path traversal

A vulnerability classified as critical was found in Rarlab WinRAR. This vulnerability affects unknown code. The manipulation leads to path

  

CVE-2025-6216 | Alltena Allegra calculateTokenExpDate password recovery

A vulnerability, which was classified as very critical, has been found in Alltena Allegra. This issue affects the function calculateTokenExpDate.

  

CVE-2025-48886 | cardano-scaling hydra up to 0.21.x exceptional condition

A vulnerability was found in cardano-scaling hydra up to 0.21.x. It has been classified as problematic. Affected is an unknown

  

CVE-2025-49014 | jqlang jq 1.8.0 /src/builtin.c f_strflocaltime use after free (GHSA-rmjp-cr27-wpg2)

A vulnerability was found in jqlang jq 1.8.0. It has been declared as critical. Affected by this vulnerability is the

  

CVE-2025-6357 | code-projects Simple Pizza Ordering System 1.0 /paymentportal.php person sql injection

A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been classified as critical. Affected is an

  

CVE-2025-6356 | code-projects Simple Pizza Ordering System 1.0 /addmem.php sql injection

A vulnerability was found in code-projects Simple Pizza Ordering System 1.0 and classified as critical. This issue affects some unknown

  

CVE-2025-6359 | code-projects Simple Pizza Ordering System 1.0 /cashconfirm.php transactioncode sql injection

A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been rated as critical. Affected by this

  

CVE-2025-6358 | code-projects Simple Pizza Ordering System 1.0 /saveorder.php ID sql injection

A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been declared as critical. Affected by this

  

CVE-2025-6361 | code-projects Simple Pizza Ordering System 1.0 /adds.php userid sql injection

A vulnerability classified as critical was found in code-projects Simple Pizza Ordering System 1.0. This vulnerability affects unknown code of

  

CVE-2025-6360 | code-projects Simple Pizza Ordering System 1.0 /portal.php ID sql injection

A vulnerability classified as critical has been found in code-projects Simple Pizza Ordering System 1.0. This affects an unknown part

  

CVE-2025-6362 | code-projects Simple Pizza Ordering System 1.0 /editpro.php ID sql injection

A vulnerability, which was classified as critical, has been found in code-projects Simple Pizza Ordering System 1.0. This issue affects

  

CVE-2025-6364 | code-projects Simple Pizza Ordering System 1.0 /adduser-exec.php Username sql injection

A vulnerability has been found in code-projects Simple Pizza Ordering System 1.0 and classified as critical. Affected by this vulnerability

  

CVE-2025-6363 | code-projects Simple Pizza Ordering System 1.0 /adding-exec.php ingname sql injection

A vulnerability, which was classified as critical, was found in code-projects Simple Pizza Ordering System 1.0. Affected is an unknown

  

CVE-2024-24916 | Check Point SmartConsole R81.10/R81.20 Installer uncontrolled search path (sk183342)

A vulnerability was found in Check Point SmartConsole R81.10/R81.20. It has been classified as critical. This affects an unknown part

  

CVE-2025-6365 | HobbesOSR Kitten up to c4f8b7c3158983d1020af432be1b417b28686736 pgtable.h set_pte_at resource consumption (Issue 17)

A vulnerability was found in HobbesOSR Kitten up to c4f8b7c3158983d1020af432be1b417b28686736 and classified as critical. Affected by this issue is the

  

CVE-2025-6367 | D-Link DIR-619L 2.06B01 formSetDomainFilter curTime/sched_name_%d/url_%d stack-based overflow

A vulnerability was found in D-Link DIR-619L 2.06B01. It has been declared as critical. This vulnerability affects unknown code of

  

CVE-2025-6369 | D-Link DIR-619L 2.06B01 formdumpeasysetup curTime/config.save_network_enabled stack-based overflow

A vulnerability classified as critical has been found in D-Link DIR-619L 2.06B01. Affected is the function formdumpeasysetup of the file

  

CVE-2025-6368 | D-Link DIR-619L 2.06B01 /goform/formSetEmail curTime/config.smtp_email_subject stack-based overflow

A vulnerability was found in D-Link DIR-619L 2.06B01. It has been rated as critical. This issue affects the function formSetEmail

  

CVE-2025-6370 | D-Link DIR-619L 2.06B01 formWlanGuestSetup curTime stack-based overflow

A vulnerability classified as critical was found in D-Link DIR-619L 2.06B01. Affected by this vulnerability is the function formWlanGuestSetup of

  

CVE-2025-6371 | D-Link DIR-619L 2.06B01 formSetEnableWizard curTime stack-based overflow

A vulnerability, which was classified as critical, has been found in D-Link DIR-619L 2.06B01. Affected by this issue is the

  

CVE-2025-6372 | D-Link DIR-619L 2.06B01 /goform/formSetWizard1 curTime stack-based overflow

A vulnerability, which was classified as critical, was found in D-Link DIR-619L 2.06B01. This affects the function formSetWizard1 of the

  

CVE-2025-6373 | D-Link DIR-619L 2.06B01 /goform/formWlSiteSurvey formSetWizard1 curTime stack-based overflow

A vulnerability has been found in D-Link DIR-619L 2.06B01 and classified as critical. This vulnerability affects the function formSetWizard1 of

  

CVE-2025-6374 | D-Link DIR-619L 2.06B01 /goform/formSetACLFilter curTime stack-based overflow

A vulnerability was found in D-Link DIR-619L 2.06B01 and classified as critical. This issue affects the function formSetACLFilter of the

  

CVE-2025-6351 | itsourcecode Employee Record Management System 1.0 /editprofile.php emp1name sql injection

A vulnerability was found in itsourcecode Employee Record Management System 1.0. It has been rated as critical. This issue affects

  

CVE-2025-6352 | code-projects Automated Voting System 1.0 Backend /vote.php direct request

A vulnerability classified as problematic has been found in code-projects Automated Voting System 1.0. Affected is an unknown function of

  

CVE-2025-6353 | code-projects Responsive Blog 1.0 /search.php keyword cross site scripting

A vulnerability classified as problematic was found in code-projects Responsive Blog 1.0. Affected by this vulnerability is an unknown functionality

  

CVE-2025-6354 | code-projects Online Shoe Store 1.0 customer_signup.php email sql injection

A vulnerability, which was classified as critical, has been found in code-projects Online Shoe Store 1.0. Affected by this issue

  

CVE-2025-4738 | Yirmibes MY ERP up to 1.169 sql injection

A vulnerability, which was classified as critical, was found in Yirmibes MY ERP up to 1.169. This affects an unknown

  

CVE-2025-6355 | SourceCodester Online Hotel Reservation System 1.0 /admin/execeditroom.php userid sql injection

A vulnerability has been found in SourceCodester Online Hotel Reservation System 1.0 and classified as critical. This vulnerability affects unknown

  

CVE-2025-6335 | DedeCMS up to 5.7.2 Template dedetag.class.php notes command injection

A vulnerability was found in DedeCMS up to 5.7.2 and classified as critical. This issue affects some unknown processing of

  

CVE-2025-6337 | TOTOLINK A3002R/A3002RU 3.0.0-B20230809.1615/4.0.0-B20230531.1404 HTTP POST Request /boafrm/formTmultiAP submit-url buffer overflow

A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615/4.0.0-B20230531.1404. It has been declared as critical. Affected by this vulnerability

  

CVE-2025-6336 | TOTOLINK EX1200T 4.1.2cu.5232_B20210713 HTTP POST Request /boafrm/formTmultiAP submit-url buffer overflow

A vulnerability was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. It has been classified as critical. Affected is an unknown function of

  

CVE-2025-6339 | ponaravindb Hospital Management System 1.0 /func3.php username1 sql injection

A vulnerability was found in ponaravindb Hospital Management System 1.0. It has been rated as critical. Affected by this issue

  

CVE-2025-6341 | code-projects School Fees Payment System 1.0 cross-site request forgery

A vulnerability classified as problematic was found in code-projects School Fees Payment System 1.0. This vulnerability affects unknown code. The

  

CVE-2025-6340 | code-projects School Fees Payment System 1.0 /branch.php Branch/Address/Detail cross site scripting

A vulnerability classified as problematic has been found in code-projects School Fees Payment System 1.0. This affects an unknown part

  

CVE-2025-6343 | code-projects Online Shoe Store 1.0 /admin/admin_product.php pid sql injection

A vulnerability, which was classified as critical, was found in code-projects Online Shoe Store 1.0. Affected is an unknown function

  

CVE-2025-6342 | code-projects Online Shoe Store 1.0 admin_football.php pid sql injection

A vulnerability, which was classified as critical, has been found in code-projects Online Shoe Store 1.0. This issue affects some

  

CVE-2025-6344 | code-projects Online Shoe Store 1.0 /contactus.php email sql injection

A vulnerability has been found in code-projects Online Shoe Store 1.0 and classified as critical. Affected by this vulnerability is

  

CVE-2025-6346 | SourceCodester Advance Charity Management System 1.0 /members/fundDetails.php m06 sql injection

A vulnerability was found in SourceCodester Advance Charity Management System 1.0. It has been classified as critical. This affects an

  

CVE-2025-6345 | SourceCodester My Food Recipe 1.0 Add Recipe Page /endpoint/add-recipe.php addRecipeModal Name cross site scripting

A vulnerability was found in SourceCodester My Food Recipe 1.0 and classified as problematic. Affected by this issue is the

  

CVE-2025-6347 | code-projects Responsive Blog 1.0/1.12.4/3.3.4 pageViewMembers.php cross site scripting

A vulnerability was found in code-projects Responsive Blog 1.0/1.12.4/3.3.4. It has been declared as problematic. This vulnerability affects unknown code

  

CVE-2025-6311 | Campcodes Sales and Inventory System 1.0 /pages/account_add.php id/amount sql injection

A vulnerability, which was classified as critical, was found in Campcodes Sales and Inventory System 1.0. This affects an unknown

  

CVE-2025-6313 | Campcodes Sales and Inventory System 1.0 /pages/cat_add.php Category sql injection

A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. This issue affects some unknown

  

CVE-2025-6312 | Campcodes Sales and Inventory System 1.0 cash_transaction.php cid sql injection

A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. This vulnerability affects unknown

  

CVE-2025-6315 | code-projects Online Shoe Store 1.0 /cart2.php ID sql injection

A vulnerability was found in code-projects Online Shoe Store 1.0. It has been declared as critical. Affected by this vulnerability

  

CVE-2025-6314 | Campcodes Sales and Inventory System 1.0 /pages/cat_update.php ID sql injection

A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been classified as critical. Affected is an

  

CVE-2025-6316 | code-projects Online Shoe Store 1.0 /admin/admin_running.php qty sql injection

A vulnerability was found in code-projects Online Shoe Store 1.0. It has been rated as critical. Affected by this issue

  

CVE-2025-6317 | code-projects Online Shoe Store 1.0 /admin/confirm.php ID sql injection

A vulnerability classified as critical has been found in code-projects Online Shoe Store 1.0. This affects an unknown part of

  

CVE-2025-6319 | PHPGurukul Pre-School Enrollment System 1.0 /admin/add-teacher.php tsubject sql injection

A vulnerability, which was classified as critical, has been found in PHPGurukul Pre-School Enrollment System 1.0. This issue affects some

  

CVE-2025-6318 | PHPGurukul Pre-School Enrollment System 1.0 check_availability.php Username sql injection

A vulnerability classified as critical was found in PHPGurukul Pre-School Enrollment System 1.0. This vulnerability affects unknown code of the

  

CVE-2025-6321 | PHPGurukul Pre-School Enrollment System 1.0 /admin/add-subadmin.php sadminusername sql injection

A vulnerability has been found in PHPGurukul Pre-School Enrollment System 1.0 and classified as critical. Affected by this vulnerability is

  

CVE-2025-6320 | PHPGurukul Pre-School Enrollment System 1.0 /admin/add-class.php classname sql injection

A vulnerability, which was classified as critical, was found in PHPGurukul Pre-School Enrollment System 1.0. Affected is an unknown function

  

CVE-2025-6323 | PHPGurukul Pre-School Enrollment System 1.0 /enrollment.php fathername sql injection

A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0. It has been classified as critical. This affects an unknown

  

CVE-2025-6322 | PHPGurukul Pre-School Enrollment System 1.0 /visit.php gname sql injection

A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0 and classified as critical. Affected by this issue is some

  

CVE-2025-6328 | D-Link DIR-815 1.01 hedwig.cgi sub_403794 stack-based overflow

A vulnerability was found in D-Link DIR-815 1.01. It has been declared as critical. This vulnerability affects the function sub_403794

  

CVE-2025-6330 | PHPGurukul Directory Management System 1.0 /searchdata.php searchdata sql injection

A vulnerability classified as critical has been found in PHPGurukul Directory Management System 1.0. Affected is an unknown function of

  

CVE-2025-6329 | ScriptAndTools Real Estate Management System 1.0 User Delete userdelete.php ID resource injection

A vulnerability was found in ScriptAndTools Real Estate Management System 1.0. It has been rated as critical. This issue affects

  

CVE-2025-6331 | PHPGurukul Directory Management System 1.0 search-directory.php searchdata sql injection

A vulnerability classified as critical was found in PHPGurukul Directory Management System 1.0. Affected by this vulnerability is an unknown

  

CVE-2025-6332 | PHPGurukul Directory Management System 2.0 manage-directory.php del sql injection

A vulnerability, which was classified as critical, has been found in PHPGurukul Directory Management System 2.0. Affected by this issue

  

CVE-2025-6333 | PHPGurukul Directory Management System 2.0 /admin/admin-profile.php adminname sql injection

A vulnerability, which was classified as critical, was found in PHPGurukul Directory Management System 2.0. This affects an unknown part

  

CVE-2025-6334 | D-Link DIR-867 1.0 Query String strncpy stack-based overflow

A vulnerability has been found in D-Link DIR-867 1.0 and classified as critical. This vulnerability affects the function strncpy of

  

CVE-2025-6285 | PHPGurukul COVID19 Testing Management System 2021 search-report-result.php q cross site scripting

A vulnerability was found in PHPGurukul COVID19 Testing Management System 2021. It has been rated as problematic. This issue affects

  

CVE-2025-6286 | PHPGurukul COVID19 Testing Management System 2021 search-report-result.php q redirect

A vulnerability classified as problematic has been found in PHPGurukul COVID19 Testing Management System 2021. Affected is an unknown function

  

CVE-2025-6287 | PHPGurukul COVID19 Testing Management System 1.0 Take Action /test-details.php remark cross site scripting

A vulnerability classified as problematic was found in PHPGurukul COVID19 Testing Management System 1.0. Affected by this vulnerability is an

  

CVE-2025-6291 | D-Link DIR-825 2.03 HTTP POST Request do_file stack-based overflow

A vulnerability, which was classified as critical, was found in D-Link DIR-825 2.03. This affects the function do_file of the

  

CVE-2025-6288 | PHPGurukul Bus Pass Management System 1.0 Profile Page /admin/admin-profile.php profile name cross site scripting

A vulnerability, which was classified as problematic, has been found in PHPGurukul Bus Pass Management System 1.0. Affected by this

  

CVE-2025-6293 | code-projects Hostel Management System 1.0 /contact_manager.php student_roll_no sql injection

A vulnerability was found in code-projects Hostel Management System 1.0 and classified as critical. This issue affects some unknown processing

  

CVE-2025-6292 | D-Link DIR-825 2.03 HTTP POST Request sub_4091AC stack-based overflow

A vulnerability has been found in D-Link DIR-825 2.03 and classified as critical. This vulnerability affects the function sub_4091AC of

  

CVE-2025-6295 | code-projects Hostel Management System 1.0 /allocated_rooms.php search_box sql injection

A vulnerability was found in code-projects Hostel Management System 1.0. It has been declared as critical. Affected by this vulnerability

  

CVE-2025-6294 | code-projects Hostel Management System 1.0 /contact.php hostel_name sql injection

A vulnerability was found in code-projects Hostel Management System 1.0. It has been classified as critical. Affected is an unknown

  

CVE-2025-6299 | TOTOLINK N150RT 3.4.0-B20190525 /boa/formWSC targetAPSsid os command injection

A vulnerability classified as critical has been found in TOTOLINK N150RT 3.4.0-B20190525. This affects an unknown part of the file

  

CVE-2025-6296 | code-projects Hostel Management System 1.0 /empty_rooms.php search_box sql injection

A vulnerability was found in code-projects Hostel Management System 1.0. It has been rated as critical. Affected by this issue