CVE-2025-9937 - Elunez Eladmin Remote File Deletion Authorization Bypass
CVE ID : CVE-2025-9937
Published : Sept. 4, 2025, 1:09 a.m. | 3 hours, 50 minutes ago
Description : A security flaw has been discovered in elunez eladmin 1.1. Impacted is the function deleteFile of the component LocalStorageController. The manipulation results in improper authorization. The attack may be performed from remote. The exploit has been released to the public and may be exploited.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-9937
Published : Sept. 4, 2025, 1:09 a.m. | 3 hours, 50 minutes ago
Description : A security flaw has been discovered in elunez eladmin 1.1. Impacted is the function deleteFile of the component LocalStorageController. The manipulation results in improper authorization. The attack may be performed from remote. The exploit has been released to the public and may be exploited.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-9932 - PHPGurukul Beauty Parlour Management System SQL Injection Vulnerability
CVE ID : CVE-2025-9932
Published : Sept. 4, 2025, 1:09 a.m. | 3 hours, 50 minutes ago
Description : A flaw has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this vulnerability is an unknown functionality of the file /admin/update-image.php. This manipulation of the argument lid causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-9932
Published : Sept. 4, 2025, 1:09 a.m. | 3 hours, 50 minutes ago
Description : A flaw has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this vulnerability is an unknown functionality of the file /admin/update-image.php. This manipulation of the argument lid causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-9933 - PHPGurukul Beauty Parlour Management System SQL Injection
CVE ID : CVE-2025-9933
Published : Sept. 4, 2025, 1:09 a.m. | 3 hours, 50 minutes ago
Description : A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this issue is some unknown functionality of the file /admin/view-appointment.php. Such manipulation of the argument viewid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-9933
Published : Sept. 4, 2025, 1:09 a.m. | 3 hours, 50 minutes ago
Description : A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this issue is some unknown functionality of the file /admin/view-appointment.php. Such manipulation of the argument viewid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-9936 - Fuyang_Lipengjun AdController Remote Authorization Bypass
CVE ID : CVE-2025-9936
Published : Sept. 4, 2025, 1:09 a.m. | 3 hours, 50 minutes ago
Description : A vulnerability was identified in fuyang_lipengjun platform 1.0.0. This issue affects the function AdController of the file /ad/queryAll. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-9936
Published : Sept. 4, 2025, 1:09 a.m. | 3 hours, 50 minutes ago
Description : A vulnerability was identified in fuyang_lipengjun platform 1.0.0. This issue affects the function AdController of the file /ad/queryAll. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-9931 - Jinher OA Cross-Site Scripting Vulnerability
CVE ID : CVE-2025-9931
Published : Sept. 4, 2025, 1:09 a.m. | 3 hours, 50 minutes ago
Description : A vulnerability was detected in Jinher OA 1.0. Affected is an unknown function of the file /jc6/platform/sys/login!changePassWord.action of the component POST Request Handler. The manipulation of the argument Account results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-9931
Published : Sept. 4, 2025, 1:09 a.m. | 3 hours, 50 minutes ago
Description : A vulnerability was detected in Jinher OA 1.0. Affected is an unknown function of the file /jc6/platform/sys/login!changePassWord.action of the component POST Request Handler. The manipulation of the argument Account results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be used.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-36890 - Apache Struts Command Execution
CVE ID : CVE-2025-36890
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : Elevation of Privilege
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-36890
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : Elevation of Privilege
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-36895 - Citrix NetScaler XML External Entity (XXE) Information Disclosure
CVE ID : CVE-2025-36895
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : Information disclosure
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-36895
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : Information disclosure
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-36898 - Apache HTTP Server Privilege Escalation Vulnerability
CVE ID : CVE-2025-36898
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : There is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-36898
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : There is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-36892 - Apache HTTP Server HTTP/2 Server Header Injection
CVE ID : CVE-2025-36892
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : Denial of service
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-36892
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : Denial of service
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-36902 - Syna TCM2 Heap Buffer Overflow Vulnerability
CVE ID : CVE-2025-36902
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : In syna_cdev_ioctl_store_pid() of syna_tcm2_sysfs.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-36902
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : In syna_cdev_ioctl_store_pid() of syna_tcm2_sysfs.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-36904 - Apache Tomcat Remote Code Execution
CVE ID : CVE-2025-36904
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : N/A
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-36904
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : N/A
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-9517 - Atlassian Confluence Debug Plugin Remote Code Execution Vulnerability
CVE ID : CVE-2025-9517
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : The atec Debug plugin for WordPress is vulnerable to remote code execution in all versions up to, and including, 1.2.22 via the 'custom_log' parameter. This is due to insufficient sanitization when saving the custom log path. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute code on the server.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-9517
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : The atec Debug plugin for WordPress is vulnerable to remote code execution in all versions up to, and including, 1.2.22 via the 'custom_log' parameter. This is due to insufficient sanitization when saving the custom log path. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute code on the server.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-36906 - Darwinn MLIR Converter AIDL Heap Buffer Overflow (EoP)
CVE ID : CVE-2025-36906
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : In ConvertReductionOp of darwinn_mlir_converter_aidl.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-36906
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : In ConvertReductionOp of darwinn_mlir_converter_aidl.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-36901 - Apache Struts Remote Code Execution
CVE ID : CVE-2025-36901
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : N/A
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-36901
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : N/A
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-36897 - Apache cd_CnMsgCodec Remote Code Execution Vulnerability
CVE ID : CVE-2025-36897
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : In unknown of cd_CnMsgCodecUserApi.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-36897
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : In unknown of cd_CnMsgCodecUserApi.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-36905 - Apache GIS Local Privilege Escalation Vulnerability
CVE ID : CVE-2025-36905
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : In gxp_mapping_create of gxp_mapping.c, there is a possible privilege escalation due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-36905
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : In gxp_mapping_create of gxp_mapping.c, there is a possible privilege escalation due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-43772 - Liferay Portal Liferay DXP DoS Memory Consumption Vulnerability
CVE ID : CVE-2025-43772
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : Kaleo Forms Admin in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 27, and older unsupported versions does not restrict the saving of request parameters in the portlet session, which allows remote attackers to consume system memory leading to denial-of-service (DoS) conditions via crafted HTTP request.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-43772
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : Kaleo Forms Admin in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 27, and older unsupported versions does not restrict the saving of request parameters in the portlet session, which allows remote attackers to consume system memory leading to denial-of-service (DoS) conditions via crafted HTTP request.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-56189 - SAEMM Radio Message Codec Out-of-Bounds Read Vulnerability
CVE ID : CVE-2024-56189
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : In SAEMM_DiscloseMsId of SAEMM_RadioMessageCodec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure post authentication with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2024-56189
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : In SAEMM_DiscloseMsId of SAEMM_RadioMessageCodec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure post authentication with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-56190 - Linksys Wireless Router Out-of-Bounds Write Vulnerability
CVE ID : CVE-2024-56190
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : In wl_update_hidden_ap_ie() of wl_cfgscan.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2024-56190
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : In wl_update_hidden_ap_ie() of wl_cfgscan.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-36903 - Lwis Buffer Write OOB Read/Write Vulnerability
CVE ID : CVE-2025-36903
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : In lwis_io_buffer_write, there is a possible OOB read/write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-36903
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : In lwis_io_buffer_write, there is a possible OOB read/write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-36894 - Apache TBD HTTP Denial of Service
CVE ID : CVE-2025-36894
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : In TBD of TBD, there is a possible DoS due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-36894
Published : Sept. 4, 2025, 7:10 a.m. | 1 hour, 50 minutes ago
Description : In TBD of TBD, there is a possible DoS due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...