NA - CVE-2025-49029 - Improper Control of Generation of Code...
Improper Control of Generation of Code ('Code Injection') vulnerability in bitto.Kazi Custom Login And Signup Widget allows Code Injection.This issue affects Custom Login And Signup...
Medium - CVE-2025-6920 - A flaw was found in the authentication...
A flaw was found in the authentication enforcement mechanism of a model inference API in ai-inference-server. All /v1/* endpoints are expected to enforce API key validation. However, the POST...
High - CVE-2025-6953 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, was found in TOTOLINK A3002RU 3.0.0-B20230809.1615. Affected is an unknown function of the file /boafrm/formParentControl of the component HTTP...
High - CVE-2025-6954 - A vulnerability has been found in Campcodes...
A vulnerability has been found in Campcodes Employee Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /applyleave.php. The...
High - CVE-2025-6955 - A vulnerability was found in Campcodes Employee...
A vulnerability was found in Campcodes Employee Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /process/aprocess.php. The...
High - CVE-2025-6956 - A vulnerability was found in Campcodes Employee...
A vulnerability was found in Campcodes Employee Management System 1.0. It has been classified as critical. This affects an unknown part of the file /changepassemp.php. The manipulation of the...
NA - CVE-2025-34050 - A cross-site request forgery (CSRF)...
A cross-site request forgery (CSRF) vulnerability exists in the web interface of AVTECH IP camera, DVR, and NVR devices. An attacker can craft malicious requests that, when executed in the context...
NA - CVE-2025-34051 - A server-side request forgery vulnerability...
A server-side request forgery vulnerability exists in multiple firmware versions of AVTECH DVR devices that exposes the /cgi-bin/nobody/Search.cgi?action=cgi_query endpoint without authentication....