6.9
CVE-2025-6935 - Campcodes Sales and Inventory System payment_add.php sql injection
A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /pages/payment_add.php. The manipulation of the argument cid leads to sql injection. The attack may be launched remotely. The exploit haโฆ
6.3
CVE-2025-6932 - D-Link DCS-7517 Qlync Password Generation httpd g_F_n_GenPassForQlync hard-coded password
A vulnerability, which was classified as problematic, was found in D-Link DCS-7517 up to 2.02.0. This affects the function g_F_n_GenPassForQlync of the file /bin/httpd of the component Qlync Password Generation Handler. The manipulation leads to use of hard-coded password. It is possible to initiatโฆ
6.3
CVE-2025-6931 - D-Link DCS-6517/DCS-7517 Root Password Generation httpd generate_pass_from_mac entropy
A vulnerability classified as problematic was found in D-Link DCS-6517 and DCS-7517 up to 2.02.0. Affected by this vulnerability is the function generate_pass_from_mac of the file /bin/httpd of the component Root Password Generation Handler. The manipulation leads to insufficient entropy. The attacโฆ
5.3
CVE-2025-6930 - PHPGurukul Zoo Management System manage-foreigners-ticket.php sql injection
A vulnerability classified as critical has been found in PHPGurukul Zoo Management System 2.1. Affected is an unknown function of the file /admin/manage-foreigners-ticket.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has bโฆ
8.1
CVE-2025-6554 - chromium: Chrome V8 Type Confusion Read/Write
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
5.3
CVE-2025-6929 - PHPGurukul Zoo Management System view-normal-ticket.php sql injection
A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been rated as critical. This issue affects some unknown processing of the file /admin/view-normal-ticket.php. The manipulation of the argument viewid leads to sql injection. The attack may be initiated remotely. The exploit hโฆ
8.8
CVE-2025-49521 - Event-driven-ansible: template injection via git branch and refspec in eda projects
A flaw was found in the EDA component of the Ansible Automation Platform, where user-supplied Git branch or refspec values are evaluated as Jinja2 templates. This vulnerability allows authenticated users to inject expressions that execute commands or access sensitive files on the EDA worker. In Opeโฆ
8.8
CVE-2025-49520 - Event-driven-ansible: authenticated argument injection in git url in eda project creation
A flaw was found in Ansible Automation Platformโs EDA component where user-supplied Git URLs are passed unsanitized to the git ls-remote command. This vulnerability allows an authenticated attacker to inject arguments and execute arbitrary commands on the EDA worker. In Kubernetes/OpenShift environโฆ
8.9
CVE-2025-53004 - Dataease Redshift Data Source JDBC Connection Parameters Bypass Vulnerability
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, there is a bypass vulnerability in Dataease's Redshift Data Source JDBC Connection Parameters. The sslfactory and sslfactoryarg parameters could trigger a bypass vulnerability. This issue has beeโฆ
5.9
CVE-2025-52997 - File Browser Insecurely Handles Passwords
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.34.1, a missing password policy and brute-force protection makes the authentication process insecure. Attackers could mount a brute-fโฆ