Vulnerabilities

Vulnerabilities

  

CVE-2025-33121 | IBM QRadar SIEM up to 7.5.0 Update Package 12 xml external entity reference

A vulnerability was found in IBM QRadar SIEM up to 7.5.0 Update Package 12 and classified as critical. Affected by

  

CVE-2025-36050 | IBM QRadar SIEM up to 7.5.0 Update Package 12 log file

A vulnerability was found in IBM QRadar SIEM up to 7.5.0 Update Package 12. It has been classified as problematic.

  

CVE-2025-50200 | RabbitMQ Server up to 3.13.7 log file

A vulnerability, which was classified as problematic, was found in RabbitMQ Server up to 3.13.7. Affected is an unknown function.

  

CVE-2025-6375 | poco up to 1.14.1 MultipartReader.cpp MultipartInputStream null pointer dereference (Issue 4915)

A vulnerability was found in poco up to 1.14.1. It has been rated as problematic. Affected by this issue is

  

CVE-2025-52464 | Meshtastic Firmware up to 2.6.10 Direct Message entropy

A vulnerability classified as problematic has been found in Meshtastic Firmware up to 2.6.10. This affects an unknown part of

  

CVE-2025-6218 | Rarlab WinRAR path traversal

A vulnerability classified as critical was found in Rarlab WinRAR. This vulnerability affects unknown code. The manipulation leads to path

  

CVE-2025-6216 | Alltena Allegra calculateTokenExpDate password recovery

A vulnerability, which was classified as very critical, has been found in Alltena Allegra. This issue affects the function calculateTokenExpDate.

  

CVE-2025-48886 | cardano-scaling hydra up to 0.21.x exceptional condition

A vulnerability was found in cardano-scaling hydra up to 0.21.x. It has been classified as problematic. Affected is an unknown

  

CVE-2025-49014 | jqlang jq 1.8.0 /src/builtin.c f_strflocaltime use after free (GHSA-rmjp-cr27-wpg2)

A vulnerability was found in jqlang jq 1.8.0. It has been declared as critical. Affected by this vulnerability is the

  

CVE-2025-6357 | code-projects Simple Pizza Ordering System 1.0 /paymentportal.php person sql injection

A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been classified as critical. Affected is an

  

CVE-2025-6356 | code-projects Simple Pizza Ordering System 1.0 /addmem.php sql injection

A vulnerability was found in code-projects Simple Pizza Ordering System 1.0 and classified as critical. This issue affects some unknown

  

CVE-2025-6359 | code-projects Simple Pizza Ordering System 1.0 /cashconfirm.php transactioncode sql injection

A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been rated as critical. Affected by this

  

CVE-2025-6358 | code-projects Simple Pizza Ordering System 1.0 /saveorder.php ID sql injection

A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been declared as critical. Affected by this

  

CVE-2025-6361 | code-projects Simple Pizza Ordering System 1.0 /adds.php userid sql injection

A vulnerability classified as critical was found in code-projects Simple Pizza Ordering System 1.0. This vulnerability affects unknown code of

  

CVE-2025-6360 | code-projects Simple Pizza Ordering System 1.0 /portal.php ID sql injection

A vulnerability classified as critical has been found in code-projects Simple Pizza Ordering System 1.0. This affects an unknown part

  

CVE-2025-6362 | code-projects Simple Pizza Ordering System 1.0 /editpro.php ID sql injection

A vulnerability, which was classified as critical, has been found in code-projects Simple Pizza Ordering System 1.0. This issue affects

  

CVE-2025-6364 | code-projects Simple Pizza Ordering System 1.0 /adduser-exec.php Username sql injection

A vulnerability has been found in code-projects Simple Pizza Ordering System 1.0 and classified as critical. Affected by this vulnerability

  

CVE-2025-6363 | code-projects Simple Pizza Ordering System 1.0 /adding-exec.php ingname sql injection

A vulnerability, which was classified as critical, was found in code-projects Simple Pizza Ordering System 1.0. Affected is an unknown

  

CVE-2024-24916 | Check Point SmartConsole R81.10/R81.20 Installer uncontrolled search path (sk183342)

A vulnerability was found in Check Point SmartConsole R81.10/R81.20. It has been classified as critical. This affects an unknown part

  

CVE-2025-6365 | HobbesOSR Kitten up to c4f8b7c3158983d1020af432be1b417b28686736 pgtable.h set_pte_at resource consumption (Issue 17)

A vulnerability was found in HobbesOSR Kitten up to c4f8b7c3158983d1020af432be1b417b28686736 and classified as critical. Affected by this issue is the

  

CVE-2025-6367 | D-Link DIR-619L 2.06B01 formSetDomainFilter curTime/sched_name_%d/url_%d stack-based overflow

A vulnerability was found in D-Link DIR-619L 2.06B01. It has been declared as critical. This vulnerability affects unknown code of

  

CVE-2025-6369 | D-Link DIR-619L 2.06B01 formdumpeasysetup curTime/config.save_network_enabled stack-based overflow

A vulnerability classified as critical has been found in D-Link DIR-619L 2.06B01. Affected is the function formdumpeasysetup of the file

  

CVE-2025-6368 | D-Link DIR-619L 2.06B01 /goform/formSetEmail curTime/config.smtp_email_subject stack-based overflow

A vulnerability was found in D-Link DIR-619L 2.06B01. It has been rated as critical. This issue affects the function formSetEmail

  

CVE-2025-6370 | D-Link DIR-619L 2.06B01 formWlanGuestSetup curTime stack-based overflow

A vulnerability classified as critical was found in D-Link DIR-619L 2.06B01. Affected by this vulnerability is the function formWlanGuestSetup of

  

CVE-2025-6371 | D-Link DIR-619L 2.06B01 formSetEnableWizard curTime stack-based overflow

A vulnerability, which was classified as critical, has been found in D-Link DIR-619L 2.06B01. Affected by this issue is the

  

CVE-2025-6372 | D-Link DIR-619L 2.06B01 /goform/formSetWizard1 curTime stack-based overflow

A vulnerability, which was classified as critical, was found in D-Link DIR-619L 2.06B01. This affects the function formSetWizard1 of the

  

CVE-2025-6373 | D-Link DIR-619L 2.06B01 /goform/formWlSiteSurvey formSetWizard1 curTime stack-based overflow

A vulnerability has been found in D-Link DIR-619L 2.06B01 and classified as critical. This vulnerability affects the function formSetWizard1 of

  

CVE-2025-6374 | D-Link DIR-619L 2.06B01 /goform/formSetACLFilter curTime stack-based overflow

A vulnerability was found in D-Link DIR-619L 2.06B01 and classified as critical. This issue affects the function formSetACLFilter of the

  

CVE-2025-6351 | itsourcecode Employee Record Management System 1.0 /editprofile.php emp1name sql injection

A vulnerability was found in itsourcecode Employee Record Management System 1.0. It has been rated as critical. This issue affects

  

CVE-2025-6352 | code-projects Automated Voting System 1.0 Backend /vote.php direct request

A vulnerability classified as problematic has been found in code-projects Automated Voting System 1.0. Affected is an unknown function of

  

CVE-2025-6353 | code-projects Responsive Blog 1.0 /search.php keyword cross site scripting

A vulnerability classified as problematic was found in code-projects Responsive Blog 1.0. Affected by this vulnerability is an unknown functionality

  

CVE-2025-6354 | code-projects Online Shoe Store 1.0 customer_signup.php email sql injection

A vulnerability, which was classified as critical, has been found in code-projects Online Shoe Store 1.0. Affected by this issue

  

CVE-2025-4738 | Yirmibes MY ERP up to 1.169 sql injection

A vulnerability, which was classified as critical, was found in Yirmibes MY ERP up to 1.169. This affects an unknown

  

CVE-2025-6355 | SourceCodester Online Hotel Reservation System 1.0 /admin/execeditroom.php userid sql injection

A vulnerability has been found in SourceCodester Online Hotel Reservation System 1.0 and classified as critical. This vulnerability affects unknown

  

CVE-2025-6335 | DedeCMS up to 5.7.2 Template dedetag.class.php notes command injection

A vulnerability was found in DedeCMS up to 5.7.2 and classified as critical. This issue affects some unknown processing of

  

CVE-2025-6337 | TOTOLINK A3002R/A3002RU 3.0.0-B20230809.1615/4.0.0-B20230531.1404 HTTP POST Request /boafrm/formTmultiAP submit-url buffer overflow

A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615/4.0.0-B20230531.1404. It has been declared as critical. Affected by this vulnerability

  

CVE-2025-6336 | TOTOLINK EX1200T 4.1.2cu.5232_B20210713 HTTP POST Request /boafrm/formTmultiAP submit-url buffer overflow

A vulnerability was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. It has been classified as critical. Affected is an unknown function of

  

CVE-2025-6339 | ponaravindb Hospital Management System 1.0 /func3.php username1 sql injection

A vulnerability was found in ponaravindb Hospital Management System 1.0. It has been rated as critical. Affected by this issue

  

CVE-2025-6341 | code-projects School Fees Payment System 1.0 cross-site request forgery

A vulnerability classified as problematic was found in code-projects School Fees Payment System 1.0. This vulnerability affects unknown code. The

  

CVE-2025-6340 | code-projects School Fees Payment System 1.0 /branch.php Branch/Address/Detail cross site scripting

A vulnerability classified as problematic has been found in code-projects School Fees Payment System 1.0. This affects an unknown part

  

CVE-2025-6343 | code-projects Online Shoe Store 1.0 /admin/admin_product.php pid sql injection

A vulnerability, which was classified as critical, was found in code-projects Online Shoe Store 1.0. Affected is an unknown function

  

CVE-2025-6342 | code-projects Online Shoe Store 1.0 admin_football.php pid sql injection

A vulnerability, which was classified as critical, has been found in code-projects Online Shoe Store 1.0. This issue affects some

  

CVE-2025-6344 | code-projects Online Shoe Store 1.0 /contactus.php email sql injection

A vulnerability has been found in code-projects Online Shoe Store 1.0 and classified as critical. Affected by this vulnerability is

  

CVE-2025-6346 | SourceCodester Advance Charity Management System 1.0 /members/fundDetails.php m06 sql injection

A vulnerability was found in SourceCodester Advance Charity Management System 1.0. It has been classified as critical. This affects an

  

CVE-2025-6345 | SourceCodester My Food Recipe 1.0 Add Recipe Page /endpoint/add-recipe.php addRecipeModal Name cross site scripting

A vulnerability was found in SourceCodester My Food Recipe 1.0 and classified as problematic. Affected by this issue is the

  

CVE-2025-6347 | code-projects Responsive Blog 1.0/1.12.4/3.3.4 pageViewMembers.php cross site scripting

A vulnerability was found in code-projects Responsive Blog 1.0/1.12.4/3.3.4. It has been declared as problematic. This vulnerability affects unknown code

  

CVE-2025-6311 | Campcodes Sales and Inventory System 1.0 /pages/account_add.php id/amount sql injection

A vulnerability, which was classified as critical, was found in Campcodes Sales and Inventory System 1.0. This affects an unknown

  

CVE-2025-6313 | Campcodes Sales and Inventory System 1.0 /pages/cat_add.php Category sql injection

A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. This issue affects some unknown

  

CVE-2025-6312 | Campcodes Sales and Inventory System 1.0 cash_transaction.php cid sql injection

A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. This vulnerability affects unknown

  

CVE-2025-6315 | code-projects Online Shoe Store 1.0 /cart2.php ID sql injection

A vulnerability was found in code-projects Online Shoe Store 1.0. It has been declared as critical. Affected by this vulnerability

  

CVE-2025-6314 | Campcodes Sales and Inventory System 1.0 /pages/cat_update.php ID sql injection

A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been classified as critical. Affected is an

  

CVE-2025-6316 | code-projects Online Shoe Store 1.0 /admin/admin_running.php qty sql injection

A vulnerability was found in code-projects Online Shoe Store 1.0. It has been rated as critical. Affected by this issue

  

CVE-2025-6317 | code-projects Online Shoe Store 1.0 /admin/confirm.php ID sql injection

A vulnerability classified as critical has been found in code-projects Online Shoe Store 1.0. This affects an unknown part of

  

CVE-2025-6319 | PHPGurukul Pre-School Enrollment System 1.0 /admin/add-teacher.php tsubject sql injection

A vulnerability, which was classified as critical, has been found in PHPGurukul Pre-School Enrollment System 1.0. This issue affects some

  

CVE-2025-6318 | PHPGurukul Pre-School Enrollment System 1.0 check_availability.php Username sql injection

A vulnerability classified as critical was found in PHPGurukul Pre-School Enrollment System 1.0. This vulnerability affects unknown code of the

  

CVE-2025-6321 | PHPGurukul Pre-School Enrollment System 1.0 /admin/add-subadmin.php sadminusername sql injection

A vulnerability has been found in PHPGurukul Pre-School Enrollment System 1.0 and classified as critical. Affected by this vulnerability is

  

CVE-2025-6320 | PHPGurukul Pre-School Enrollment System 1.0 /admin/add-class.php classname sql injection

A vulnerability, which was classified as critical, was found in PHPGurukul Pre-School Enrollment System 1.0. Affected is an unknown function

  

CVE-2025-6323 | PHPGurukul Pre-School Enrollment System 1.0 /enrollment.php fathername sql injection

A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0. It has been classified as critical. This affects an unknown

  

CVE-2025-6322 | PHPGurukul Pre-School Enrollment System 1.0 /visit.php gname sql injection

A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0 and classified as critical. Affected by this issue is some

  

CVE-2025-6328 | D-Link DIR-815 1.01 hedwig.cgi sub_403794 stack-based overflow

A vulnerability was found in D-Link DIR-815 1.01. It has been declared as critical. This vulnerability affects the function sub_403794

  

CVE-2025-6329 | ScriptAndTools Real Estate Management System 1.0 User Delete userdelete.php ID resource injection

A vulnerability was found in ScriptAndTools Real Estate Management System 1.0. It has been rated as critical. This issue affects

  

CVE-2025-6330 | PHPGurukul Directory Management System 1.0 /searchdata.php searchdata sql injection

A vulnerability classified as critical has been found in PHPGurukul Directory Management System 1.0. Affected is an unknown function of

  

CVE-2025-6331 | PHPGurukul Directory Management System 1.0 search-directory.php searchdata sql injection

A vulnerability classified as critical was found in PHPGurukul Directory Management System 1.0. Affected by this vulnerability is an unknown

  

CVE-2025-6332 | PHPGurukul Directory Management System 2.0 manage-directory.php del sql injection

A vulnerability, which was classified as critical, has been found in PHPGurukul Directory Management System 2.0. Affected by this issue

  

CVE-2025-6333 | PHPGurukul Directory Management System 2.0 /admin/admin-profile.php adminname sql injection

A vulnerability, which was classified as critical, was found in PHPGurukul Directory Management System 2.0. This affects an unknown part

  

CVE-2025-6334 | D-Link DIR-867 1.0 Query String strncpy stack-based overflow

A vulnerability has been found in D-Link DIR-867 1.0 and classified as critical. This vulnerability affects the function strncpy of

  

CVE-2025-6285 | PHPGurukul COVID19 Testing Management System 2021 search-report-result.php q cross site scripting

A vulnerability was found in PHPGurukul COVID19 Testing Management System 2021. It has been rated as problematic. This issue affects

  

CVE-2025-6286 | PHPGurukul COVID19 Testing Management System 2021 search-report-result.php q redirect

A vulnerability classified as problematic has been found in PHPGurukul COVID19 Testing Management System 2021. Affected is an unknown function

  

CVE-2025-6287 | PHPGurukul COVID19 Testing Management System 1.0 Take Action /test-details.php remark cross site scripting

A vulnerability classified as problematic was found in PHPGurukul COVID19 Testing Management System 1.0. Affected by this vulnerability is an

  

CVE-2025-6291 | D-Link DIR-825 2.03 HTTP POST Request do_file stack-based overflow

A vulnerability, which was classified as critical, was found in D-Link DIR-825 2.03. This affects the function do_file of the

  

CVE-2025-6288 | PHPGurukul Bus Pass Management System 1.0 Profile Page /admin/admin-profile.php profile name cross site scripting

A vulnerability, which was classified as problematic, has been found in PHPGurukul Bus Pass Management System 1.0. Affected by this

  

CVE-2025-6293 | code-projects Hostel Management System 1.0 /contact_manager.php student_roll_no sql injection

A vulnerability was found in code-projects Hostel Management System 1.0 and classified as critical. This issue affects some unknown processing

  

CVE-2025-6292 | D-Link DIR-825 2.03 HTTP POST Request sub_4091AC stack-based overflow

A vulnerability has been found in D-Link DIR-825 2.03 and classified as critical. This vulnerability affects the function sub_4091AC of

  

CVE-2025-6295 | code-projects Hostel Management System 1.0 /allocated_rooms.php search_box sql injection

A vulnerability was found in code-projects Hostel Management System 1.0. It has been declared as critical. Affected by this vulnerability

  

CVE-2025-6294 | code-projects Hostel Management System 1.0 /contact.php hostel_name sql injection

A vulnerability was found in code-projects Hostel Management System 1.0. It has been classified as critical. Affected is an unknown

  

CVE-2025-6299 | TOTOLINK N150RT 3.4.0-B20190525 /boa/formWSC targetAPSsid os command injection

A vulnerability classified as critical has been found in TOTOLINK N150RT 3.4.0-B20190525. This affects an unknown part of the file

  

CVE-2025-6296 | code-projects Hostel Management System 1.0 /empty_rooms.php search_box sql injection

A vulnerability was found in code-projects Hostel Management System 1.0. It has been rated as critical. Affected by this issue

  

CVE-2025-6300 | PHPGurukul Employee Record Management System 1.3 editempeducation.php yopgra sql injection

A vulnerability classified as critical was found in PHPGurukul Employee Record Management System 1.3. This vulnerability affects unknown code of

  

CVE-2025-6302 | TOTOLINK EX1200T 4.1.2cu.5232_B20210713 /cgi-bin/cstecgi.cgi setStaticDhcpConfig Comment stack-based overflow

A vulnerability, which was classified as critical, was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. Affected is the function setStaticDhcpConfig of the

  

CVE-2025-6301 | PHPGurukul Notice Board System 1.0 Add Notice manage-notices.php Title/Description cross site scripting

A vulnerability, which was classified as problematic, has been found in PHPGurukul Notice Board System 1.0. This issue affects some

  

CVE-2025-6304 | code-projects Online Shoe Store 1.0 /cart.php qty[] sql injection

A vulnerability was found in code-projects Online Shoe Store 1.0 and classified as critical. Affected by this issue is some

  

CVE-2025-6303 | code-projects Online Shoe Store 1.0 /contactus1.php Message sql injection

A vulnerability has been found in code-projects Online Shoe Store 1.0 and classified as critical. Affected by this vulnerability is

  

CVE-2025-6305 | code-projects Online Shoe Store 1.0 /admin/admin_feature.php product_code sql injection

A vulnerability was found in code-projects Online Shoe Store 1.0. It has been classified as critical. This affects an unknown

  

CVE-2025-6306 | code-projects Online Shoe Store 1.0 /admin/admin_index.php Username sql injection

A vulnerability was found in code-projects Online Shoe Store 1.0. It has been declared as critical. This vulnerability affects unknown

  

CVE-2025-6307 | code-projects Online Shoe Store 1.0 edit_customer.php firstname sql injection

A vulnerability was found in code-projects Online Shoe Store 1.0. It has been rated as critical. This issue affects some

  

CVE-2025-6270 | HDF5 up to 1.14.6 H5FSsection.c H5FS__sect_find_node heap-based overflow (Issue 5580)

A vulnerability, which was classified as critical, has been found in HDF5 up to 1.14.6. Affected by this issue is

  

CVE-2025-6269 | HDF5 up to 1.14.6 H5Cimage.c H5C__reconstruct_cache_entry heap-based overflow (Issue 5579)

A vulnerability classified as critical was found in HDF5 up to 1.14.6. Affected by this vulnerability is the function H5C__reconstruct_cache_entry

  

CVE-2025-6271 | swftools up to 0.9.2 wav2swf lib/wav.c wav_convert2mono out-of-bounds (Issue 239)

A vulnerability, which was classified as problematic, was found in swftools up to 0.9.2. This affects the function wav_convert2mono in

  

CVE-2025-6273 | WebAssembly wabt up to 1.0.37 binary-reader-objdump.cc LogOpcode assertion (Issue 2574)

A vulnerability was found in WebAssembly wabt up to 1.0.37 and classified as problematic. This issue affects the function LogOpcode

  

CVE-2025-6272 | wasm3 0.5.0 source/m3_compile.c MarkSlotAllocated out-of-bounds write

A vulnerability has been found in wasm3 0.5.0 and classified as problematic. This vulnerability affects the function MarkSlotAllocated of the

  

CVE-2025-6275 | WebAssembly wabt up to 1.0.37 binary-reader-interp.cc GetFuncOffset use after free (Issue 2614)

A vulnerability was found in WebAssembly wabt up to 1.0.37. It has been declared as problematic. Affected by this vulnerability

  

CVE-2025-6274 | WebAssembly wabt up to 1.0.37 binary-reader-interp.cc OnDataCount resource consumption (Issue 2598)

A vulnerability was found in WebAssembly wabt up to 1.0.37. It has been classified as problematic. Affected is the function

  

CVE-2025-6276 | Brilliance Golden Link Secondary System up to 20250609 rentTakeInfoPage.htm custTradeName sql injection

A vulnerability was found in Brilliance Golden Link Secondary System up to 20250609. It has been rated as critical. Affected

  

CVE-2025-6278 | Upsonic up to 0.55.6 markdown/server.py os.path.join file.filename path traversal (Issue 356)

A vulnerability classified as critical was found in Upsonic up to 0.55.6. This vulnerability affects the function os.path.join of the

  

CVE-2025-6277 | Brilliance Golden Link Secondary System up to 20250609 custTakeInfoPage.htm custTradeName sql injection

A vulnerability classified as critical has been found in Brilliance Golden Link Secondary System up to 20250609. This affects an

  

CVE-2025-6279 | Upsonic up to 0.55.6 Pickle /tools/add_tool cloudpickle.loads deserialization (Issue 353)

A vulnerability, which was classified as critical, has been found in Upsonic up to 0.55.6. This issue affects the function

  

CVE-2025-6280 | TransformerOptimus SuperAGI up to 0.0.14 EmailToolKit read_email.py download_attachment filename path traversal (Issue 1466)

A vulnerability, which was classified as critical, was found in TransformerOptimus SuperAGI up to 0.0.14. Affected is the function download_attachment

  

CVE-2025-6281 | OpenBMB XAgent up to 1.0.0 /conv/community path traversal (Issue 415)

A vulnerability has been found in OpenBMB XAgent up to 1.0.0 and classified as critical. Affected by this vulnerability is

  

CVE-2025-6282 | xlang-ai OpenAgents up to ff2e46440699af1324eb25655b622c4a131265bb backend/api/file.py create_upload_file path traversal (Issue 141)

A vulnerability was found in xlang-ai OpenAgents up to ff2e46440699af1324eb25655b622c4a131265bb and classified as critical. Affected by this issue is the

  

CVE-2025-6283 | xataio Xata Agent up to 0.3.0 route.ts GET passed path traversal

A vulnerability was found in xataio Xata Agent up to 0.3.0. It has been classified as problematic. This affects the