Latest CVE Feed
- 
                                
                                9.8CRITICALCVE-2025-11469A weakness has been identified in SourceCodester Hotel and Lodge Management System 1.0. The affected element is an unknown function of the file /pages/save_customer.php. Executing manipulation of the argument Contact can lead to sql injection. The attack ... Read more Affected Products : hotel_and_lodge_management_system- Published: Oct. 08, 2025
- Modified: Oct. 09, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-11079A security flaw has been discovered in Campcodes Farm Management System 1.0. Affected by this issue is some unknown functionality. The manipulation results in file and directory information exposure. The attack may be performed from remote. The exploit ha... Read more Affected Products : farm_management_system- Published: Sep. 27, 2025
- Modified: Oct. 03, 2025
- Vuln Type: Information Disclosure
 
- 
                                
                                9.8CRITICALCVE-2025-7634The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 6.6.7 via the mode parameter. This makes it possible for unauthenticated attackers to incl... Read more Affected Products : wp_travel_engine- Published: Oct. 09, 2025
- Modified: Oct. 09, 2025
- Vuln Type: Path Traversal
 
- 
                                
                                9.8CRITICALCVE-2025-11710A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the compromised process. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Thunder... Read more - Published: Oct. 14, 2025
- Modified: Oct. 17, 2025
- Vuln Type: Information Disclosure
 
- 
                                
                                9.8CRITICALCVE-2025-11344A vulnerability was detected in ILIAS up to 8.23/9.13/10.1. Affected by this vulnerability is an unknown functionality of the component Certificate Import Handler. The manipulation results in Remote Code Execution. The attack may be performed from remote.... Read more Affected Products : ilias- Published: Oct. 06, 2025
- Modified: Oct. 14, 2025
- Vuln Type: Denial of Service
 
- 
                                
                                9.8CRITICALCVE-2025-59735Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a POST request. The relationship between parameter and assigned identifier is a... Read more Affected Products : e-tms- Published: Oct. 02, 2025
- Modified: Oct. 02, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-11033A vulnerability has been found in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. Impacted is an unknown function of the file /Profilers/PriProfile/COUNT3s7.php. The manipulation of the argument cbe leads to sql injection. It ... Read more Affected Products : courseselectionsystem- Published: Sep. 26, 2025
- Modified: Oct. 08, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-11403A vulnerability was found in SourceCodester Hotel and Lodge Management System 1.0. Affected by this issue is some unknown functionality of the file /del_booking.php. Performing manipulation of the argument ID results in sql injection. It is possible to in... Read more Affected Products : hotel_and_lodge_management_system- Published: Oct. 07, 2025
- Modified: Oct. 09, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-59737Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a POST request. The relationship between parameter and assigned identifier is a... Read more Affected Products : e-tms- Published: Oct. 02, 2025
- Modified: Oct. 02, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2017-20208The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 3.7.9.3 (exclusive) via deserialization of untrusted input from the is_expired_b... Read more Affected Products : registrationmagic- Published: Oct. 18, 2025
- Modified: Oct. 21, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-11077A vulnerability was determined in Campcodes Online Learning Management System 1.0. Affected is an unknown function of the file /admin/add_content.php. Executing manipulation of the argument Title can lead to sql injection. The attack can be executed remot... Read more Affected Products : online_learning_management_system- Published: Sep. 27, 2025
- Modified: Oct. 03, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-11053A weakness has been identified in PHPGurukul Small CRM 4.0. This affects an unknown function of the file /forgot-password.php. Executing manipulation of the argument email can lead to sql injection. The attack can be launched remotely. The exploit has bee... Read more Affected Products : small_crm- Published: Sep. 27, 2025
- Modified: Oct. 03, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-59738Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a POST request. The relationship between parameter and assigned identifier is a... Read more Affected Products : e-tms- Published: Oct. 02, 2025
- Modified: Oct. 02, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-59954Knowage is an open source analytics and business intelligence suite. Versions 8.1.26 and below are vulnerable to Remote Code Exection through using an unsafe org.apache.commons.jxpath.JXPathContext in MetaService.java service. This issue is fixed in versi... Read more Affected Products : knowage- Published: Sep. 30, 2025
- Modified: Oct. 08, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-11601A vulnerability was detected in SourceCodester Online Student Result System 1.0. Affected by this vulnerability is an unknown functionality of the file /login.php. Performing manipulation of the argument Username results in sql injection. The attack can b... Read more Affected Products : online_student_result_system- Published: Oct. 11, 2025
- Modified: Oct. 20, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-11662A security flaw has been discovered in SourceCodester Best Salon Management System 1.0. Impacted is an unknown function of the file /booking.php. The manipulation of the argument serv_id results in sql injection. It is possible to launch the attack remote... Read more Affected Products : best_salon_management_system- Published: Oct. 13, 2025
- Modified: Oct. 17, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-11558A vulnerability was found in code-projects E-Commerce Website 1.0. Impacted is an unknown function of the file /pages/user_index_search.php. Performing manipulation of the argument Search results in sql injection. The attack is possible to be carried out ... Read more - Published: Oct. 09, 2025
- Modified: Oct. 23, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-11479A security vulnerability has been detected in SourceCodester Wedding Reservation Management System 1.0. Impacted is the function insertReservation of the file function.php. Such manipulation of the argument number leads to sql injection. The attack can be... Read more Affected Products : wedding_reservation_management_system- Published: Oct. 08, 2025
- Modified: Oct. 09, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-8868In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in the compliance service via improperly neutralized inputs used in an SQL command usin... Read more - Published: Sep. 29, 2025
- Modified: Oct. 16, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-11480A vulnerability was detected in SourceCodester Simple E-Commerce Bookstore 1.0. The affected element is an unknown function of the file /register.php. Performing manipulation of the argument register_username results in sql injection. The attack is possib... Read more Affected Products : simple_e-commerce_bookstore- Published: Oct. 08, 2025
- Modified: Oct. 09, 2025
- Vuln Type: Injection
 
 
                         
                         
                         
                                             
                                            