CVE-2025-3351
published 2025-04-07CVE-2025-3351: A vulnerability has been found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown…
PriorityP353critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.48%
38.0th percentile
A vulnerability has been found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/login.php. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| msrc | microsoft_edge | — | — |
| phpgurukul | old_age_home_management_system | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
risc0 vulnerable to arbitrary code execution in guest via memory safety failure in `sys_read`
ghsa·2025-10-01
CVE-2025-61588 [CRITICAL] CWE-94 risc0 vulnerable to arbitrary code execution in guest via memory safety failure in `sys_read`
risc0 vulnerable to arbitrary code execution in guest via memory safety failure in `sys_read`
# Arbitrary code execution in guest via memory safety failure in `sys_read`
In affected versions of `risc0-zkvm-platform`, when the zkVM guest calls `sys_read`, the host is able to use a crafted response to write to an arbitrary memory location in the guest. This capability can be leveraged to execute arbitrary code within the guest. As `sys_read` is the mechanism by which input is requested by the guest, all guest programs built with the affected versions are vulnerable. This critically compromises the soundness guarantees of the guest program.
A fix was applied in [\#3351](https://github.com/risc0/risc0/pull/3351). The vulnerable pointer arithmetic was removed, and replaced with a simplified
GHSA
GHSA-rw9m-2gw8-75r7: A vulnerability has been found in PHPGurukul Old Age Home Management System 1
ghsa_unreviewed·2025-04-07
CVE-2025-3351 [MEDIUM] CWE-74 GHSA-rw9m-2gw8-75r7: A vulnerability has been found in PHPGurukul Old Age Home Management System 1
A vulnerability has been found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/login.php. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Microsoft
Chromium: CVE-2025-8010 Type Confusion in V8
vendor_msrc·2025-07-08·CVSS 8.8
CVE-2025-8010 [HIGH] Chromium: CVE-2025-8010 Type Confusion in V8
Chromium: CVE-2025-8010 Type Confusion in V8
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
138.0.3351.109
7/25/2025
138.0.7204.168/.169
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In
Microsoft
Chromium: CVE-2025-8011 Type Confusion in V8
vendor_msrc·2025-07-08·CVSS 8.8
CVE-2025-8011 [HIGH] Chromium: CVE-2025-8011 Type Confusion in V8
Chromium: CVE-2025-8011 Type Confusion in V8
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
138.0.3351.109
7/25/2025
138.0.7204.168/.169
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In
Microsoft
Chromium: CVE-2025-6556 Insufficient policy enforcement in Loader
vendor_msrc·2025-06-10·CVSS 5.4
CVE-2025-6556 [MEDIUM] Chromium: CVE-2025-6556 Insufficient policy enforcement in Loader
Chromium: CVE-2025-6556 Insufficient policy enforcement in Loader
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
138.0.3351.55
6/26/2025
138.0.7204.49/.50
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of
Microsoft
Chromium: CVE-2025-6555 Use after free in Animation
vendor_msrc·2025-06-10·CVSS 5.4
CVE-2025-6555 [MEDIUM] Chromium: CVE-2025-6555 Use after free in Animation
Chromium: CVE-2025-6555 Use after free in Animation
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
138.0.3351.55
6/26/2025
138.0.7204.49/.50
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
Microsoft
Chromium: CVE-2025-6557 Insufficient data validation in DevTools
vendor_msrc·2025-06-10·CVSS 5.4
CVE-2025-6557 [MEDIUM] Chromium: CVE-2025-6557 Insufficient data validation in DevTools
Chromium: CVE-2025-6557 Insufficient data validation in DevTools
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
138.0.3351.55
6/26/2025
138.0.7204.49/.50
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of
Microsoft
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
vendor_msrc·2025-06-10·CVSS 5.6
CVE-2025-47182 [MEDIUM] CWE-20 Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Description: Improper input validation in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
To successfully exploit this vulnerability, an attacker would need existing ability to execute Javascript in the impacted process.
FAQ: According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?
This vulnerability could lead to a browser sandbox escape.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
138.0.3351.55
6
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-04-07
Published