Latest CVEs
Updates on the latest vulnerabilities detected.
-
CVE-2025-7525 - TOTOLINK T6 HTTP POST Request Handler Command Injection Vulnerability
CVE ID :CVE-2025-7525
Published : July 13, 2025, 10:15 a.m. | 24 minutes ago
Description :A vulnerability was found in TOTOLINK T6 4.1.5cu.748_B20211015. It has been declared as critical. This vulnerability affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request Handler. The manipulation of the argument command leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more... -
CVE-2025-7524 - "TOTOLINK T6 HTTP POST Request Handler Command Injection Vulnerability"
CVE ID :CVE-2025-7524
Published : July 13, 2025, 9:15 a.m. | 1 hour, 24 minutes ago
Description :A vulnerability was found in TOTOLINK T6 4.1.5cu.748_B20211015. It has been classified as critical. This affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request Handler. The manipulation of the argument ip leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more... -
CVE-2025-7012 - Cato Networks CatoClient Local Privilege Escalation Vulnerability
CVE ID :CVE-2025-7012
Published : July 13, 2025, 8:15 a.m. | 2 hours, 24 minutes ago
Description :An issue in Cato Networks' CatoClient for Linux, before version 5.5, allows a local attacker to escalate privileges to root by exploiting improper symbolic link handling.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more... -
CVE-2025-7523 - Jinher OA XXE Vulnerability
CVE ID :CVE-2025-7523
Published : July 13, 2025, 7:15 a.m. | 3 hours, 24 minutes ago
Description :A vulnerability was found in Jinher OA 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /c6/Jhsoft.Web.message/ToolBar/DelTemp.aspx. The manipulation leads to xml external entity reference. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more... -
CVE-2025-7522 - PHPGurukul Vehicle Parking Management System SQL Injection Vulnerability
CVE ID :CVE-2025-7522
Published : July 13, 2025, 7:15 a.m. | 3 hours, 24 minutes ago
Description :A vulnerability has been found in PHPGurukul Vehicle Parking Management System 1.13 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/bwdates-reports-details.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more... -
CVE-2025-7521 - PHPGurukul Vehicle Parking Management System SQL Injection Vulnerability
CVE ID :CVE-2025-7521
Published : July 13, 2025, 6:15 a.m. | 4 hours, 24 minutes ago
Description :A vulnerability, which was classified as critical, was found in PHPGurukul Vehicle Parking Management System 1.13. Affected is an unknown function of the file /admin/index.php. The manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more... -
CVE-2025-7520 - PHPGurukul Vehicle Parking Management System SQL Injection Vulnerability
CVE ID :CVE-2025-7520
Published : July 13, 2025, 5:15 a.m. | 5 hours, 24 minutes ago
Description :A vulnerability, which was classified as critical, has been found in PHPGurukul Vehicle Parking Management System 1.13. This issue affects some unknown processing of the file /admin/manage-category.php. The manipulation of the argument del leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more... -
CVE-2025-7517 - Code-projects Online Appointment Booking System SQL Injection Vulnerability
CVE ID :CVE-2025-7517
Published : July 13, 2025, 5:15 a.m. | 5 hours, 24 minutes ago
Description :A vulnerability, which was classified as critical, has been found in code-projects Online Appointment Booking System 1.0. This issue affects some unknown processing of the file /getDay.php. The manipulation of the argument cidval leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more... -
CVE-2025-7516 - Code-projects Online Appointment Booking System SQL Injection Vulnerability
CVE ID :CVE-2025-7516
Published : July 13, 2025, 4:15 a.m. | 6 hours, 24 minutes ago
Description :A vulnerability classified as critical was found in code-projects Online Appointment Booking System 1.0. This vulnerability affects unknown code of the file /cancelbookingpatient.php. The manipulation of the argument appointment leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more... -
CVE-2025-7515 - Code-projects Online Appointment Booking System SQL Injection Vulnerability
CVE ID :CVE-2025-7515
Published : July 13, 2025, 4:15 a.m. | 6 hours, 24 minutes ago
Description :A vulnerability classified as critical has been found in code-projects Online Appointment Booking System 1.0. This affects an unknown part of the file /ulocateus.php. The manipulation of the argument doctorname leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more... -
CVE-2025-7514 - Modern Bag SQL Injection Vulnerability
CVE ID :CVE-2025-7514
Published : July 13, 2025, 4:15 a.m. | 6 hours, 24 minutes ago
Description :A vulnerability was found in code-projects Modern Bag 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/contact-list.php. The manipulation of the argument idStatus leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more... -
CVE-2025-7513 - "Modern Bag SQL Injection Vulnerability"
CVE ID :CVE-2025-7513
Published : July 13, 2025, 3:15 a.m. | 7 hours, 24 minutes ago
Description :A vulnerability was found in code-projects Modern Bag 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/slideupdate.php. The manipulation of the argument idSlide leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more... -
CVE-2025-7512 - "Modern Bag SQL Injection Vulnerability"
CVE ID :CVE-2025-7512
Published : July 13, 2025, 3:15 a.m. | 7 hours, 24 minutes ago
Description :A vulnerability was found in code-projects Modern Bag 1.0. It has been classified as critical. Affected is an unknown function of the file /contact-back.php. The manipulation of the argument contact-name leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more... -
CVE-2025-7511 - Code-projects Chat System SQL Injection Vulnerability
CVE ID :CVE-2025-7511
Published : July 13, 2025, 2:15 a.m. | 8 hours, 24 minutes ago
Description :A vulnerability was found in code-projects Chat System 1.0 and classified as critical. This issue affects some unknown processing of the file /user/update_account.php. The manipulation of the argument musername leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more... -
CVE-2025-7510 - Code-projects Modern Bag SQL Injection Vulnerability
CVE ID :CVE-2025-7510
Published : July 13, 2025, 1:15 a.m. | 9 hours, 24 minutes ago
Description :A vulnerability has been found in code-projects Modern Bag 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/productadd_back.php. The manipulation of the argument namepro leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more... -
CVE-2025-7509 - "Modern Bag SQL Injection Vulnerability"
CVE ID :CVE-2025-7509
Published : July 13, 2025, 1:15 a.m. | 9 hours, 24 minutes ago
Description :A vulnerability, which was classified as critical, was found in code-projects Modern Bag 1.0. This affects an unknown part of the file /admin/slide.php. The manipulation of the argument idSlide leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more... -
CVE-2025-7508 - Modern Bag SQL Injection Vulnerability
CVE ID :CVE-2025-7508
Published : July 13, 2025, 12:15 a.m. | 10 hours, 24 minutes ago
Description :A vulnerability, which was classified as critical, has been found in code-projects Modern Bag 1.0. Affected by this issue is some unknown functionality of the file /admin/product-update.php. The manipulation of the argument idProduct leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more... -
CVE-2025-7506 - Tenda FH451 HTTP POST Request Handler Stack-Based Buffer Overflow
CVE ID :CVE-2025-7506
Published : July 12, 2025, 11:15 p.m. | 11 hours, 24 minutes ago
Description :A vulnerability classified as critical was found in Tenda FH451 1.0.0.9. Affected by this vulnerability is the function fromNatlimit of the file /goform/Natlimit of the component HTTP POST Request Handler. The manipulation of the argument page leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more... -
CVE-2025-7505 - Tenda FH451 HTTP POST Request Handler Stack-Based Buffer Overflow Vulnerability
CVE ID :CVE-2025-7505
Published : July 12, 2025, 11:15 p.m. | 11 hours, 24 minutes ago
Description :A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. Affected is the function frmL7ProtForm of the file /goform/L7Prot of the component HTTP POST Request Handler. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more... -
CVE-2025-7492 - PHPGurukul Vehicle Parking Management System SQL Injection Vulnerability
CVE ID :CVE-2025-7492
Published : July 12, 2025, 10:15 p.m. | 12 hours, 24 minutes ago
Description :A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/manage-incomingvehicle.php. The manipulation of the argument del leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...