Latest CVE Feed
-
9.8
CRITICALCVE-2025-3183
A vulnerability has been found in projectworlds Online Doctor Appointment Booking System 1.0 and classified as critical. This vulnerability affects unknown code of the file /patient/patientupdateprofile.php. The manipulation of the argument patientFirstNa... Read more
Affected Products : doctor_appointment_system online_doctor_appointment_booking_system_php_and_mysql- Published: Apr. 03, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3185
A vulnerability was found in projectworlds Online Doctor Appointment Booking System 1.0. It has been classified as critical. Affected is an unknown function of the file /patient/patientupdateprofile.php. The manipulation of the argument patientFirstName l... Read more
Affected Products : doctor_appointment_system online_doctor_appointment_booking_system_php_and_mysql- Published: Apr. 03, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3186
A vulnerability was found in projectworlds Online Doctor Appointment Booking System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /patient/invoice.php. The manipulation of the argument appid ... Read more
Affected Products : doctor_appointment_system online_doctor_appointment_booking_system_php_and_mysql- Published: Apr. 04, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3199
A vulnerability was found in ageerle ruoyi-ai up to 2.0.1 and classified as critical. Affected by this issue is some unknown functionality of the file ruoyi-modules/ruoyi-system/src/main/java/org/ruoyi/system/controller/system/SysModelController.java of t... Read more
Affected Products : ruoyi-ai- Published: Apr. 04, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-3213
A vulnerability classified as critical was found in PHPGurukul e-Diary Management System 1.0. This vulnerability affects unknown code of the file /view-note.php?noteid=11. The manipulation of the argument remark leads to sql injection. The attack can be i... Read more
Affected Products : e-diary_management_system- Published: Apr. 04, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3216
A vulnerability was found in PHPGurukul e-Diary Management System 1.0. It has been classified as critical. This affects an unknown part of the file /password-recovery.php. The manipulation of the argument username/contactno leads to sql injection. It is p... Read more
Affected Products : e-diary_management_system- Published: Apr. 04, 2025
- Modified: May. 08, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3220
A vulnerability was found in PHPGurukul e-Diary Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /dashboard.php. The manipulation of the argument Category leads to sql injectio... Read more
Affected Products : e-diary_management_system- Published: Apr. 04, 2025
- Modified: May. 08, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3231
A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been rated as critical. This issue affects some unknown processing of the file /aboutus.php. The manipulation of the argument pagetitle/pagedes leads to sql injection. The attack ma... Read more
Affected Products : zoo_management_system- Published: Apr. 04, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2244
A vulnerability in the sendMailFromRemoteSource method in Emails.php as used in Bitdefender GravityZone Console unsafely uses php unserialize() on user-supplied input without validation. By crafting a malicious serialized payload, an attacker can trigger... Read more
Affected Products : gravityzone- Published: Apr. 04, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3239
A vulnerability classified as critical was found in PHPGurukul Online Fire Reporting System 1.2. Affected by this vulnerability is an unknown functionality of the file /admin/edit-guard-detail.php. The manipulation of the argument editid leads to sql inje... Read more
Affected Products : online_fire_reporting_system- Published: Apr. 04, 2025
- Modified: May. 16, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3240
A vulnerability, which was classified as critical, has been found in PHPGurukul Online Fire Reporting System 1.2. Affected by this issue is some unknown functionality of the file /admin/search.php. The manipulation of the argument searchdata leads to sql ... Read more
Affected Products : online_fire_reporting_system- Published: Apr. 04, 2025
- Modified: May. 16, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3242
A vulnerability has been found in PHPGurukul e-Diary Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /search-result.php. The manipulation of the argument id/searchdata leads to sql injection. The attac... Read more
Affected Products : e-diary_management_system- Published: Apr. 04, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-28146
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via fota_url in /boafrm/formLtefotaUpgradeQuectel... Read more
- Published: Apr. 04, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3249
A vulnerability classified as critical was found in TOTOLINK A6000R 1.0.1-B20201211.2000. Affected by this vulnerability is the function apcli_cancel_wps of the file /usr/lib/lua/luci/controller/mtkwifi.lua. The manipulation leads to command injection. Th... Read more
- Published: Apr. 04, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3258
A vulnerability classified as critical was found in PHPGurukul Old Age Home Management System 1.0. This vulnerability affects unknown code of the file /search.php. The manipulation of the argument searchdata leads to sql injection. The attack can be initi... Read more
Affected Products : old_age_home_management_system- Published: Apr. 04, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3268
A vulnerability has been found in qinguoyi TinyWebServer up to 1.0 and classified as critical. This vulnerability affects unknown code of the file http/http_conn.cpp. The manipulation of the argument m_url_real leads to improper authentication. The attack... Read more
Affected Products : tinywebserver- Published: Apr. 04, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2019-19450
paraparser in ReportLab before 3.5.31 allows remote code execution because start_unichar in paraparser.py evaluates untrusted user input in a unichar element in a crafted XML document with '<unichar code="' followed by arbitrary Python code, a similar iss... Read more
- Published: Sep. 20, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-3307
A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /reset.php. The manipulation of the argument useremail leads to sql injection. It is possible to l... Read more
- Published: Apr. 06, 2025
- Modified: Apr. 08, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3310
A vulnerability classified as critical has been found in code-projects Blood Bank Management System 1.0. This affects an unknown part of the file /admin/delete.php. The manipulation of the argument Search leads to sql injection. It is possible to initiate... Read more
- Published: Apr. 06, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-32370
Kentico Xperience before 13.0.178 has a specific set of allowed ContentUploader file extensions for unauthenticated uploads; however, because .zip is processed through TryZipProviderSafe, there is additional functionality to create files with other extens... Read more
Affected Products : xperience- Published: Apr. 06, 2025
- Modified: Apr. 08, 2025
- Vuln Type: Misconfiguration