Latest CVE Feed
-
5.4
MEDIUMCVE-2025-53636
Open OnDemand is an open-source HPC portal. Users can flood logs by interacting with the shell app and generating many errors. Users who flood logs can create very large log files causing a Denial of Service (DoS) to the ondemand system. This vulnerabilit... Read more
Affected Products : open_ondemand- Published: Jul. 11, 2025
- Modified: Jul. 15, 2025
-
5.4
MEDIUMCVE-2025-51657
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Link.php.... Read more
Affected Products : semcms- Published: Jul. 14, 2025
- Modified: Jul. 15, 2025
-
5.4
MEDIUMCVE-2025-51659
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Products.php.... Read more
Affected Products : semcms- Published: Jul. 14, 2025
- Modified: Jul. 15, 2025
-
5.4
MEDIUMCVE-2025-54020
Cross-Site Request Forgery (CSRF) vulnerability in Erik AntiSpam for Contact Form 7 allows Cross Site Request Forgery. This issue affects AntiSpam for Contact Form 7: from n/a through 0.6.3.... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 16, 2025
-
5.4
MEDIUMCVE-2025-54037
Missing Authorization vulnerability in blazethemes News Kit Elementor Addons allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects News Kit Elementor Addons: from n/a through 1.3.4.... Read more
Affected Products : news_kit_elementor_addons- Published: Jul. 16, 2025
- Modified: Jul. 16, 2025
-
5.4
MEDIUMCVE-2025-7857
A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file bwdates-passreports-details.php of the component HTTP POST Request Handler... Read more
Affected Products : apartment_visitors_management_system- Published: Jul. 19, 2025
- Modified: Jul. 29, 2025
-
5.4
MEDIUMCVE-2025-7869
A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar 2.9.0. Affected by this issue is some unknown functionality of the file intranet/educar_turma_tipo_det.php?cod_turma_tipo=ID of the component Turma Module. The man... Read more
Affected Products : i-educar- Published: Jul. 20, 2025
- Modified: Aug. 13, 2025
-
5.4
MEDIUMCVE-2025-51396
A stored cross-site scripting (XSS) vulnerability in Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Telegram Bot Username parameter.... Read more
Affected Products : live_helper_chat- Published: Jul. 21, 2025
- Modified: Aug. 07, 2025
-
5.4
MEDIUMCVE-2025-7926
A vulnerability, which was classified as problematic, was found in PHPGurukul Online Banquet Booking System 1.0. This affects an unknown part of the file /admin/booking-search.php. The manipulation of the argument searchdata leads to cross site scripting.... Read more
Affected Products : online_banquet_booking_system- Published: Jul. 21, 2025
- Modified: Jul. 29, 2025
-
5.4
MEDIUMCVE-2025-51400
A stored cross-site scripting (XSS) vulnerability in the Personal Canned Messages of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.... Read more
Affected Products : live_helper_chat- Published: Jul. 21, 2025
- Modified: Aug. 07, 2025
-
5.4
MEDIUMCVE-2025-51479
Authorization bypass in update_user_group in onyx-dot-app Onyx Enterprise Edition 0.27.0 allows remote authenticated attackers to modify arbitrary user groups via crafted PATCH requests to the /api/manage/admin/user-group/id endpoint, bypassing intended c... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 25, 2025
-
5.4
MEDIUMCVE-2025-50477
A URL redirection in lbry-desktop v0.53.9 allows attackers to redirect victim users to attacker-controlled pages.... Read more
Affected Products :- Published: Jul. 23, 2025
- Modified: Jul. 25, 2025
-
5.4
MEDIUMCVE-2025-46993
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more
- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
-
5.4
MEDIUMCVE-2025-47061
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more
- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
-
5.4
MEDIUMCVE-2025-8167
A vulnerability was found in code-projects Church Donation System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/edit_members.php. The manipulation of the argument fname leads to cro... Read more
Affected Products : church_donation_system- Published: Jul. 25, 2025
- Modified: Aug. 05, 2025
-
5.4
MEDIUMCVE-2025-6060
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in DECE Software Geodi allows Cross-Site Scripting (XSS).This issue affects Geodi: before GEODI Setup 9.0.146.... Read more
Affected Products : geodi- Published: Jul. 29, 2025
- Modified: Jul. 29, 2025
-
5.4
MEDIUMCVE-2025-46018
CSC Pay Mobile App 2.19.4 (fixed in version 2.20.0) contains a vulnerability allowing users to bypass payment authorization by disabling Bluetooth at a specific point during a transaction. This could result in unauthorized use of laundry services and pote... Read more
Affected Products :- Published: Aug. 01, 2025
- Modified: Aug. 04, 2025
-
5.4
MEDIUMCVE-2025-54393
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows Static Code Injection. Authenticated users can obtain administrative access.... Read more
Affected Products : directory_manager- Published: Aug. 07, 2025
- Modified: Aug. 11, 2025
-
5.4
MEDIUMCVE-2025-54396
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows SQL Injection. Authenticated users can exploit this.... Read more
Affected Products : directory_manager- Published: Aug. 07, 2025
- Modified: Aug. 11, 2025
-
5.4
MEDIUMCVE-2025-8784
A vulnerability classified as problematic was found in Portabilis i-Educar up to 2.9. This vulnerability affects unknown code of the file /intranet/funcionario_vinculo_cad.php of the component Cadastrar Vínculo Page. The manipulation of the argument nome ... Read more
Affected Products : i-educar- Published: Aug. 09, 2025
- Modified: Aug. 12, 2025