Loading HuntDB...

Recently Updated CVEs

Latest Updates

Most recently updated vulnerabilities, including new information, EPSS scores, and exploit discoveries.

CVE-2025-5628 Updated 3 days, 17 hours ago

A vulnerability, which was classified as problematic, has been found in SourceCodester Food Menu Manager 1.0. Affected by this issue is some unknown functionality of the file /index.php of the component Add Menu Handler. The manipulation of the argument name/description leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

UNKNOWN (3.5)
CVE-2025-5627 Updated 3 days, 18 hours ago

A vulnerability classified as critical was found in code-projects Patient Record Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /sputum_form.php. The manipulation of the argument itr_no leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

UNKNOWN (6.3)
CVE-2025-5626 Updated 3 days, 18 hours ago

A vulnerability classified as critical has been found in Campcodes Online Teacher Record Management System 1.0. Affected is an unknown function of the file /admin/edit-subjects-detail.php. The manipulation of the argument editid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

UNKNOWN (7.3)
CVE-2025-5621 Updated 3 days, 19 hours ago

A vulnerability has been found in D-Link DIR-816 1.10CNB05 and classified as critical. Affected by this vulnerability is the function qosClassifier of the file /goform/qosClassifier. The manipulation of the argument dip_address/sip_address leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

UNKNOWN (7.3)
CVE-2025-5620 Updated 3 days, 19 hours ago

A vulnerability, which was classified as critical, was found in D-Link DIR-816 1.10CNB05. Affected is the function setipsec_config of the file /goform/setipsec_config. The manipulation of the argument localIP/remoteIP leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

UNKNOWN (7.3)
CVE-2025-49007 Updated 3 days, 20 hours ago

Rack is a modular Ruby web server interface. Starting in version 3.1.0 and prior to version 3.1.16, there is a denial of service vulnerability in the Content-Disposition parsing component of Rack. This is very similar to the previous security issue CVE-2022-44571. Carefully crafted input can cause Content-Disposition header parsing in Rack to take an unexpected amount of time, possibly resulting in a denial of service attack vector. This header is used typically used in multipart parsing. Any applications that parse multipart posts using Rack (virtually all Rails applications) are impacted. Version 3.1.16 contains a patch for the vulnerability.

UNKNOWN (0.0)
CVE-2020-14477 Updated 3 days, 21 hours ago

In Philips Ultrasound ClearVue Versions 3.2 and prior, Ultrasound CX Versions 5.0.2 and prior, Ultrasound EPIQ/Affiniti Versions VM5.0 and prior, Ultrasound Sparq Version 3.0.2 and prior and Ultrasound Xperius all versions, an attacker may use an alternate path or channel that does not require authentication of the alternate service login to view or modify information.

LOW (3.6) EPSS: 0.0%
CVE-2025-5612 Updated 3 days, 22 hours ago

A vulnerability has been found in PHPGurukul Online Fire Reporting System 1.2 and classified as critical. This vulnerability affects unknown code of the file /reporting.php. The manipulation of the argument fullname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

UNKNOWN (6.3)
CVE-2025-46011 Updated 3 days, 23 hours ago

Listmonk v2.4.0 through v4.1.0 is vulnerable to SQL Injection in the QuerySubscribers function which allows attackers to escalate privileges.

UNKNOWN (0.0)
CVE-2025-31482 Updated 3 days, 23 hours ago

FreshRSS is a self-hosted RSS feed aggregator. A vulnerability in versions prior to 1.26.2 causes a user to be repeatedly logged out after fetching a malicious feed entry, effectively causing that user to suffer denial of service. Version 1.26.2 contains a patch for the issue.

MEDIUM (4.3)
CVE-2025-5606 Updated 4 days ago

A vulnerability was found in Tenda AC18 15.03.05.05. It has been declared as critical. This vulnerability affects the function formSetIptv of the file /goform/SetIPTVCfg. The manipulation of the argument list leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

UNKNOWN (6.3)
CVE-2025-33074 Updated 4 days, 1 hour ago

No description available

HIGH (7.5)
CVE-2025-32726 Updated 4 days, 1 hour ago

No description available

MEDIUM (6.8)
CVE-2025-30392 Updated 4 days, 1 hour ago

No description available

CRITICAL (9.8)
CVE-2025-30391 Updated 4 days, 1 hour ago

No description available

HIGH (8.1)
CVE-2025-30390 Updated 4 days, 1 hour ago

No description available

CRITICAL (9.9)
CVE-2025-30389 Updated 4 days, 1 hour ago

No description available

HIGH (8.7)
CVE-2025-29834 Updated 4 days, 1 hour ago

No description available

HIGH (7.5)
CVE-2025-29824 Updated 4 days, 1 hour ago

No description available

HIGH (7.8)
CVE-2025-29823 Updated 4 days, 1 hour ago

No description available

HIGH (7.8)