Aggregator
CVE-2025-6155 | PHPGurukul Hostel Management System 1.0 login-hm.inc.php Username sql injection (EUVD-2025-18443)
38 minutes 23 seconds ago
A vulnerability was found in PHPGurukul Hostel Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /includes/login-hm.inc.php. The manipulation of the argument Username leads to sql injection.
This vulnerability is traded as CVE-2025-6155. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-3774 | Wise Chat Plugin up to 3.3.4 on WordPress Header X-Forwarded-For cross site scripting (EUVD-2025-18449)
38 minutes 23 seconds ago
A vulnerability, which was classified as problematic, was found in Wise Chat Plugin up to 3.3.4 on WordPress. Affected is an unknown function of the component Header Handler. The manipulation of the argument X-Forwarded-For leads to cross site scripting.
This vulnerability is traded as CVE-2025-3774. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-6158 | D-Link DIR-665 1.00 HTTP POST Request sub_AC78 stack-based overflow (EUVD-2025-18473)
38 minutes 24 seconds ago
A vulnerability classified as critical has been found in D-Link DIR-665 1.00. This affects the function sub_AC78 of the component HTTP POST Request Handler. The manipulation leads to stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is uniquely identified as CVE-2025-6158. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-6161 | SourceCodester Simple Food Ordering System 1.0 /editproduct.php photo unrestricted upload (EUVD-2025-18477)
38 minutes 24 seconds ago
A vulnerability, which was classified as critical, was found in SourceCodester Simple Food Ordering System 1.0. Affected is an unknown function of the file /editproduct.php. The manipulation of the argument photo leads to unrestricted upload.
This vulnerability is traded as CVE-2025-6161. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-6159 | code-projects Hostel Management System 1.0 /allocate_room.php search_box sql injection (EUVD-2025-18483)
38 minutes 25 seconds ago
A vulnerability classified as critical was found in code-projects Hostel Management System 1.0. This vulnerability affects unknown code of the file /allocate_room.php. The manipulation of the argument search_box leads to sql injection.
This vulnerability was named CVE-2025-6159. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-6164 | TOTOLINK A3002R 4.0.0-B20230531.1404 HTTP POST Request /boafrm/formMultiAP submit-url buffer overflow (EUVD-2025-18482)
38 minutes 25 seconds ago
A vulnerability was found in TOTOLINK A3002R 4.0.0-B20230531.1404. It has been classified as critical. This affects an unknown part of the file /boafrm/formMultiAP of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow.
This vulnerability is uniquely identified as CVE-2025-6164. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-6166 | frdel Agent-Zero up to 0.8.4 /python/api/image_get.py image_get path path traversal (Issue 383 / EUVD-2025-18479)
38 minutes 25 seconds ago
A vulnerability was found in frdel Agent-Zero up to 0.8.4. It has been rated as problematic. This issue affects the function image_get of the file /python/api/image_get.py. The manipulation of the argument path leads to path traversal.
The identification of this vulnerability is CVE-2025-6166. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-5209 | Ivory Search Plugin up to 5.5.9 on WordPress Setting cross site scripting (EUVD-2025-18481)
38 minutes 25 seconds ago
A vulnerability, which was classified as problematic, has been found in Ivory Search Plugin up to 5.5.9 on WordPress. Affected by this issue is some unknown functionality of the component Setting Handler. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-5209. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-6167 | themanojdesai python-a2a up to 0.5.5 api.py create_workflow path traversal (Issue 40 / EUVD-2025-18486)
38 minutes 26 seconds ago
A vulnerability classified as critical has been found in themanojdesai python-a2a up to 0.5.5. Affected is the function create_workflow of the file python_a2a/agent_flow/server/api.py. The manipulation leads to path traversal.
This vulnerability is traded as CVE-2025-6167. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-6173 | Webkul QloApps 1.6.1 ajax_products_list.php packItself sql injection (EUVD-2025-18485)
38 minutes 26 seconds ago
A vulnerability classified as critical was found in Webkul QloApps 1.6.1. Affected by this vulnerability is an unknown functionality of the file /admin/ajax_products_list.php. The manipulation of the argument packItself leads to sql injection.
This vulnerability is known as CVE-2025-6173. The attack can be launched remotely. Furthermore, there is an exploit available.
The vendor confirms the existence of this flaw but considers it a low-level issue due to admin privilege pre-requisites. Still, a fix is planned for a future release.
vuldb.com
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
1 hour 27 minutes ago
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
CVE-2023-0804 | LibTIFF 4.4.0 TIFF File tools/tiffcrop.c tiffcrop out-of-bounds write (Issue 497 / Nessus ID 240052)
2 hours 19 minutes ago
A vulnerability was found in LibTIFF 4.4.0. It has been declared as critical. This vulnerability affects the function tiffcrop of the file tools/tiffcrop.c of the component TIFF File Handler. The manipulation leads to out-of-bounds write.
This vulnerability was named CVE-2023-0804. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-0801 | LibTIFF 4.4.0 TIFF File libtiff/tif_unix.c tiffcrop out-of-bounds write (Issue 498 / Nessus ID 240052)
2 hours 19 minutes ago
A vulnerability has been found in LibTIFF 4.4.0 and classified as critical. Affected by this vulnerability is the function tiffcrop of the file libtiff/tif_unix.c of the component TIFF File Handler. The manipulation leads to out-of-bounds write.
This vulnerability is known as CVE-2023-0801. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-0796 | LibTIFF 4.4.0 TIFF File tools/tiffcrop.c out-of-bounds (Issue 499 / Nessus ID 240052)
2 hours 19 minutes ago
A vulnerability was found in LibTIFF 4.4.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file tools/tiffcrop.c of the component TIFF File Handler. The manipulation leads to out-of-bounds read.
This vulnerability is handled as CVE-2023-0796. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-0802 | LibTIFF 4.4.0 TIFF File tools/tiffcrop.c tiffcrop out-of-bounds write (Issue 500 / Nessus ID 240052)
2 hours 19 minutes ago
A vulnerability was found in LibTIFF 4.4.0 and classified as critical. Affected by this issue is the function tiffcrop of the file tools/tiffcrop.c of the component TIFF File Handler. The manipulation leads to out-of-bounds write.
This vulnerability is handled as CVE-2023-0802. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-21404 | Microsoft Visual Studio/.NET denial of service (Nessus ID 240053)
2 hours 19 minutes ago
A vulnerability classified as critical has been found in Microsoft Visual Studio and .NET. Affected is an unknown function. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2024-21404. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-40745 | LibTIFF up to 4.5.1 tiffcp.c integer overflow (Nessus ID 240052)
2 hours 19 minutes ago
A vulnerability classified as critical has been found in LibTIFF up to 4.5.1. This affects an unknown part of the file tiffcp.c. The manipulation leads to integer overflow.
This vulnerability is uniquely identified as CVE-2023-40745. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-21386 | Microsoft Visual Studio/ASP.NET Core denial of service (Nessus ID 240053)
2 hours 19 minutes ago
A vulnerability was found in Microsoft Visual Studio and ASP.NET Core. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to denial of service.
This vulnerability is known as CVE-2024-21386. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-48988 | Apache Tomcat up to 9.0.105/10.1.41/11.0.7 allocation of resources (EUVD-2025-18409 / Nessus ID 240060)
2 hours 19 minutes ago
A vulnerability, which was classified as problematic, has been found in Apache Tomcat up to 9.0.105/10.1.41/11.0.7. Affected by this issue is some unknown functionality. The manipulation leads to allocation of resources.
This vulnerability is handled as CVE-2025-48988. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com