Vulnerabilities
Vulnerable Software
Security Vulnerabilities
A missing critical step in authentication vulnerability [CWE-304] in Fortinet FortiOS version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.10, and before 7.0.16 & FortiProxy version 7.6.0 through 7.6.1, 7.4.0 through 7.4.8, 7.2.0 through 7.2.13 and before 7.0.20 allows an API-user using api-key + PKI user certificate authentication to login even if the certificate is invalid.
CVSS Score
7.2
EPSS Score
0.0
Published
2025-07-08
A vulnerability, which was classified as critical, was found in code-projects Staff Audit System 1.0. Affected is an unknown function of the file /test.php. The manipulation of the argument uploadedfile leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVSS Score
6.3
EPSS Score
0.001
Published
2025-07-08
A vulnerability, which was classified as critical, has been found in code-projects Staff Audit System 1.0. This issue affects some unknown processing of the file /login.php. The manipulation of the argument User leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVSS Score
7.3
EPSS Score
0.0
Published
2025-07-08
A vulnerability classified as critical was found in code-projects Library System 1.0. This vulnerability affects unknown code of the file /add-teacher.php. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVSS Score
7.3
EPSS Score
0.0
Published
2025-07-08
Memory corruption while processing packet data with exceedingly large packet.
CVSS Score
7.8
EPSS Score
0.0
Published
2025-07-08
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.
CVSS Score
7.8
EPSS Score
0.0
Published
2025-07-08
A vulnerability classified as critical has been found in code-projects Food Distributor Site 1.0. This affects an unknown part of the file /admin/login.php. The manipulation of the argument Username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVSS Score
7.3
EPSS Score
0.0
Published
2025-07-08
Memory corruption while processing event close when client process terminates abruptly.
CVSS Score
7.8
EPSS Score
0.0
Published
2025-07-08
Memory corruption while processing command message in WLAN Host.
CVSS Score
7.8
EPSS Score
0.0
Published
2025-07-08
Memory corruption while processing data packets in diag received from Unix clients.
CVSS Score
7.8
EPSS Score
0.0
Published
2025-07-08


Contact Us

Shodan ® - All rights reserved