Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.3

    CVSS31
    CVE-2025-3208

    A vulnerability was found in code-projects Patient Record Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /xray_print.php. The manipulation of the argument itr_no leads to sql injection. It is possibl... Read more

    Affected Products : patient_record_management_system
    • Published: Apr. 04, 2025
    • Modified: Apr. 04, 2025
  • 6.3

    CVSS31
    CVE-2025-3296

    A vulnerability, which was classified as critical, has been found in SourceCodester Online Eyewear Shop 1.0. This issue affects some unknown processing of the file /classes/Users.php?f=delete_customer. The manipulation of the argument ID leads to sql inje... Read more

    Affected Products :
    • Published: Apr. 05, 2025
    • Modified: Apr. 05, 2025
  • 6.3

    CVSS31
    CVE-2025-3215

    A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/add-subadmin.php. The manipulation of the argument fullname leads to sql inject... Read more

    Affected Products : restaurant_table_booking_system
    • Published: Apr. 04, 2025
    • Modified: Apr. 04, 2025
  • 6.3

    CVSS31
    CVE-2025-3235

    A vulnerability was found in PHPGurukul Old Age Home Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/profile.php. The manipulation of the argument adminname leads to sql injection. It is possible ... Read more

    Affected Products : old_age_home_management_system
    • Published: Apr. 04, 2025
    • Modified: Apr. 04, 2025
  • 6.3

    CVSS31
    CVE-2025-3204

    A vulnerability, which was classified as critical, has been found in CodeAstro Car Rental System 1.0. Affected by this issue is some unknown functionality of the file /returncar.php. The manipulation of the argument ID leads to sql injection. The attack m... Read more

    Affected Products : car_rental_system
    • Published: Apr. 04, 2025
    • Modified: Apr. 04, 2025
  • 6.3

    CVSS31
    CVE-2025-3211

    A vulnerability classified as critical has been found in code-projects Patient Record Management System 1.0. This affects an unknown part of the file /birthing_print.php. The manipulation of the argument itr_no leads to sql injection. It is possible to in... Read more

    Affected Products : patient_record_management_system
    • Published: Apr. 04, 2025
    • Modified: Apr. 04, 2025
  • 6.3

    CVSS31
    CVE-2025-3267

    A vulnerability, which was classified as critical, was found in qinguoyi TinyWebServer up to 1.0. This affects an unknown part of the file /http/http_conn.cpp. The manipulation of the argument name/password leads to sql injection. It is possible to initia... Read more

    Affected Products :
    • Published: Apr. 04, 2025
    • Modified: Apr. 04, 2025
  • 6.3

    CVSS31
    CVE-2025-3242

    A vulnerability has been found in PHPGurukul e-Diary Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /search-result.php. The manipulation of the argument searchdata leads to sql injection. The attack c... Read more

    Affected Products :
    • Published: Apr. 04, 2025
    • Modified: Apr. 04, 2025
  • 6.3

    CVSS31
    CVE-2025-3241

    A vulnerability, which was classified as problematic, was found in zhangyanbo2007 youkefu up to 4.2.0. This affects an unknown part of the file src/main/java/com/ukefu/webim/web/handler/admin/callcenter/CallCenterRouterController.java of the component XML... Read more

    Affected Products :
    • Published: Apr. 04, 2025
    • Modified: Apr. 04, 2025
  • 6.3

    CVSS31
    CVE-2025-3207

    A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /birthing_form.php. The manipulation of the argument birth_id leads to sql injection. The at... Read more

    Affected Products : patient_record_management_system
    • Published: Apr. 04, 2025
    • Modified: Apr. 04, 2025
  • 6.3

    CVSS31
    CVE-2025-3244

    A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /add-admin.php of the component Create User Page. The ma... Read more

    Affected Products :
    • Published: Apr. 04, 2025
    • Modified: Apr. 04, 2025
  • 6.3

    CVSS31
    CVE-2025-3243

    A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /dental_form.php. The manipulation of the argument itr_no leads to sql injection. The attack... Read more

    Affected Products : patient_record_management_system
    • Published: Apr. 04, 2025
    • Modified: Apr. 04, 2025
  • 6.3

    CVSS31
    CVE-2025-3206

    A vulnerability has been found in code-projects Hospital Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/doctor-specilization.php. The manipulation of the argument doctorspecilization leads to s... Read more

    Affected Products : hospital_management_system
    • Published: Apr. 04, 2025
    • Modified: Apr. 04, 2025
  • 6.3

    CVSS31
    CVE-2025-3205

    A vulnerability, which was classified as critical, was found in CodeAstro Student Grading System 1.0. This affects an unknown part of the file studentsubject.php. The manipulation of the argument studentId leads to sql injection. It is possible to initiat... Read more

    Affected Products :
    • Published: Apr. 04, 2025
    • Modified: Apr. 04, 2025
  • 6.3

    CVSS31
    CVE-2025-3209

    A vulnerability was found in code-projects Patient Record Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /add_patient.php. The manipulation of the argument itr_no leads to sq... Read more

    Affected Products : patient_record_management_system
    • Published: Apr. 04, 2025
    • Modified: Apr. 04, 2025
  • 6.3

    CVSS31
    CVE-2025-3249

    A vulnerability classified as critical was found in TOTOLINK A6000R 1.0.1-B20201211.2000. Affected by this vulnerability is the function apcli_cancel_wps of the file /usr/lib/lua/luci/controller/mtkwifi.lua. The manipulation leads to command injection. Th... Read more

    Affected Products :
    • Published: Apr. 04, 2025
    • Modified: Apr. 04, 2025
  • 6.3

    CVSS31
    CVE-2025-3245

    A vulnerability was found in itsourcecode Library Management System 1.0. It has been rated as critical. Affected by this issue is the function Search of the file library_management/src/Library_Management/Forgot.java. The manipulation of the argument txtun... Read more

    Affected Products :
    • Published: Apr. 04, 2025
    • Modified: Apr. 04, 2025
  • 6.3

    CVSS31
    CVE-2025-3256

    A vulnerability was found in xujiangfei admintwo 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /user/updateSet. The manipulation of the argument email leads to improper access controls. The attack may... Read more

    Affected Products :
    • Published: Apr. 04, 2025
    • Modified: Apr. 04, 2025
  • 6.3

    CVSS31
    CVE-2025-3254

    A vulnerability was found in xujiangfei admintwo 1.0. It has been classified as critical. Affected is an unknown function of the file /resource/add. The manipulation of the argument description leads to server-side request forgery. It is possible to launc... Read more

    Affected Products :
    • Published: Apr. 04, 2025
    • Modified: Apr. 04, 2025
  • 6.1

    CVSS31
    CVE-2025-3191

    All versions of the package react-draft-wysiwyg are vulnerable to Cross-site Scripting (XSS) via the Embedded button which will then result in saving the payload in the <iframe> tag.... Read more

    Affected Products :
    • Published: Apr. 04, 2025
    • Modified: Apr. 04, 2025
Showing 20 of 307 Results
© cvefeed.io
Latest DB Update: Apr. 05, 2025 16:44