Latest CVE Feed
-
5.4
MEDIUMCVE-2025-7148
A vulnerability was found in CodeAstro Simple Hospital Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /patient.html of the component POST Parameter Handler. The manipulation leads to c... Read more
Affected Products : simple_hospital_management_system- Published: Jul. 07, 2025
- Modified: Jul. 09, 2025
-
5.4
MEDIUMCVE-2025-7153
A vulnerability classified as problematic was found in CodeAstro Simple Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /doctor.html of the component POST Parameter Handler. The manipulation of the ar... Read more
Affected Products : simple_hospital_management_system- Published: Jul. 08, 2025
- Modified: Jul. 08, 2025
-
5.4
MEDIUMCVE-2025-5570
The AI Engine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the mwai_chatbot shortcode 'id' parameter in all versions up to, and including, 2.8.4 due to insufficient input sanitization and output escaping. This makes it possible fo... Read more
- Published: Jul. 08, 2025
- Modified: Aug. 13, 2025
-
5.4
MEDIUMCVE-2025-4406
The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.4.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack... Read more
Affected Products : wpforo_forum- Published: Jul. 10, 2025
- Modified: Jul. 10, 2025
-
5.4
MEDIUMCVE-2025-53636
Open OnDemand is an open-source HPC portal. Users can flood logs by interacting with the shell app and generating many errors. Users who flood logs can create very large log files causing a Denial of Service (DoS) to the ondemand system. This vulnerabilit... Read more
Affected Products : open_ondemand- Published: Jul. 11, 2025
- Modified: Jul. 15, 2025
-
5.4
MEDIUMCVE-2025-51657
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Link.php.... Read more
Affected Products : semcms- Published: Jul. 14, 2025
- Modified: Jul. 15, 2025
-
5.4
MEDIUMCVE-2025-51659
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Products.php.... Read more
Affected Products : semcms- Published: Jul. 14, 2025
- Modified: Jul. 15, 2025
-
5.4
MEDIUMCVE-2025-54020
Cross-Site Request Forgery (CSRF) vulnerability in Erik AntiSpam for Contact Form 7 allows Cross Site Request Forgery. This issue affects AntiSpam for Contact Form 7: from n/a through 0.6.3.... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 16, 2025
-
5.4
MEDIUMCVE-2025-54037
Missing Authorization vulnerability in blazethemes News Kit Elementor Addons allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects News Kit Elementor Addons: from n/a through 1.3.4.... Read more
Affected Products : news_kit_elementor_addons- Published: Jul. 16, 2025
- Modified: Jul. 16, 2025
-
5.4
MEDIUMCVE-2025-7857
A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file bwdates-passreports-details.php of the component HTTP POST Request Handler... Read more
Affected Products : apartment_visitors_management_system- Published: Jul. 19, 2025
- Modified: Jul. 29, 2025
-
5.4
MEDIUMCVE-2025-7869
A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar 2.9.0. Affected by this issue is some unknown functionality of the file intranet/educar_turma_tipo_det.php?cod_turma_tipo=ID of the component Turma Module. The man... Read more
Affected Products : i-educar- Published: Jul. 20, 2025
- Modified: Aug. 13, 2025
-
5.4
MEDIUMCVE-2025-51396
A stored cross-site scripting (XSS) vulnerability in Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Telegram Bot Username parameter.... Read more
Affected Products : live_helper_chat- Published: Jul. 21, 2025
- Modified: Aug. 07, 2025
-
5.4
MEDIUMCVE-2025-7926
A vulnerability, which was classified as problematic, was found in PHPGurukul Online Banquet Booking System 1.0. This affects an unknown part of the file /admin/booking-search.php. The manipulation of the argument searchdata leads to cross site scripting.... Read more
Affected Products : online_banquet_booking_system- Published: Jul. 21, 2025
- Modified: Jul. 29, 2025
-
5.4
MEDIUMCVE-2025-51400
A stored cross-site scripting (XSS) vulnerability in the Personal Canned Messages of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.... Read more
Affected Products : live_helper_chat- Published: Jul. 21, 2025
- Modified: Aug. 07, 2025
-
5.4
MEDIUMCVE-2025-51479
Authorization bypass in update_user_group in onyx-dot-app Onyx Enterprise Edition 0.27.0 allows remote authenticated attackers to modify arbitrary user groups via crafted PATCH requests to the /api/manage/admin/user-group/id endpoint, bypassing intended c... Read more
Affected Products :- Published: Jul. 22, 2025
- Modified: Jul. 25, 2025
-
5.4
MEDIUMCVE-2025-50477
A URL redirection in lbry-desktop v0.53.9 allows attackers to redirect victim users to attacker-controlled pages.... Read more
Affected Products :- Published: Jul. 23, 2025
- Modified: Jul. 25, 2025
-
5.4
MEDIUMCVE-2025-46993
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more
- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
-
5.4
MEDIUMCVE-2025-47061
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more
- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
-
5.4
MEDIUMCVE-2025-8167
A vulnerability was found in code-projects Church Donation System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/edit_members.php. The manipulation of the argument fname leads to cro... Read more
Affected Products : church_donation_system- Published: Jul. 25, 2025
- Modified: Aug. 05, 2025
-
5.4
MEDIUMCVE-2025-6060
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in DECE Software Geodi allows Cross-Site Scripting (XSS).This issue affects Geodi: before GEODI Setup 9.0.146.... Read more
Affected Products : geodi- Published: Jul. 29, 2025
- Modified: Jul. 29, 2025