Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.3

    HIGH
    CVE-2025-56295

    code-projects Computer Laboratory System 1.0 has a file upload vulnerability. Staff can upload malicious files by uploading PHP backdoor files when modifying personal avatar information and use web shell connection tools to obtain server permissions.... Read more

    Affected Products : computer_laboratory_system
    • Published: Sep. 16, 2025
    • Modified: Sep. 18, 2025
    • Vuln Type: Misconfiguration
  • 5.4

    MEDIUM
    CVE-2025-56293

    code-projects Human Resource Integrated System 1.0 is vulnerable to Cross Site Scripting (XSS) in the Add Child Information section in the Childs Name field.... Read more

    Affected Products : human_resource_integrated_system
    • Published: Sep. 16, 2025
    • Modified: Sep. 18, 2025
    • Vuln Type: Cross-Site Scripting
  • 5.4

    MEDIUM
    CVE-2025-56289

    code-projects Document Management System 1.0 has a Cross Site Scripting (XSS) vulnerability, where attackers can leak admin's cookie information by entering malicious XSS code in the Company field when adding files.... Read more

    Affected Products : document_management_system
    • Published: Sep. 16, 2025
    • Modified: Sep. 18, 2025
    • Vuln Type: Cross-Site Scripting
  • 9.8

    CRITICAL
    CVE-2025-10562

    A flaw has been found in Campcodes Grocery Sales and Inventory System 1.0. This affects an unknown function of the file /ajax.php?action=save_product. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible... Read more

    • Published: Sep. 16, 2025
    • Modified: Sep. 18, 2025
    • Vuln Type: Injection
  • 5.4

    MEDIUM
    CVE-2025-56280

    code-projects Food Ordering Review System 1.0 is vulnerable to Cross Site Scripting (XSS) in the area where users submit reservation information.... Read more

    Affected Products : food_ordering_review_system
    • Published: Sep. 16, 2025
    • Modified: Sep. 18, 2025
    • Vuln Type: Cross-Site Scripting
  • 9.8

    CRITICAL
    CVE-2025-57119

    An issue in Online Library Management System v.3.0 allows an attacker to escalate privileges via the adminlogin.php component and the Login function... Read more

    Affected Products : online_library_management_system
    • Published: Sep. 16, 2025
    • Modified: Sep. 18, 2025
    • Vuln Type: Authentication
  • 5.4

    MEDIUM
    CVE-2025-56276

    code-projects Food Ordering Review System 1.0 is vulnerable to Cross Site Scripting (XSS) in the registration function. An attacker enters malicious JavaScript code as a username, which triggers the XSS vulnerability when the admin views user information,... Read more

    Affected Products : food_ordering_review_system
    • Published: Sep. 16, 2025
    • Modified: Sep. 18, 2025
    • Vuln Type: Cross-Site Scripting
  • 6.1

    MEDIUM
    CVE-2025-56697

    A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the /users/adminpanel/admin/home.php?page=feedbacks file of Kashipara Computer Base Test v1.0. Attackers can inject malicious scripts via the smyFeedbacks POST parameter in /users/home.ph... Read more

    Affected Products : computer_base_test
    • Published: Sep. 16, 2025
    • Modified: Sep. 18, 2025
    • Vuln Type: Cross-Site Scripting
  • 9.8

    CRITICAL
    CVE-2025-57118

    An issue in PHPGurukul Online-Library-Management-System v3.0 allows an attacker to escalate privileges via the index.php... Read more

    Affected Products : online_library_management_system
    • Published: Sep. 15, 2025
    • Modified: Sep. 18, 2025
    • Vuln Type: Authorization
  • 5.4

    MEDIUM
    CVE-2025-57117

    A Clickjacking vulnerability exists in Rems' Employee Management System 1.0. This flaw allows remote attackers to execute arbitrary JavaScript on the department.php page by injecting a malicious payload into the Department Name field under Add Department.... Read more

    Affected Products : employee_management_system
    • Published: Sep. 15, 2025
    • Modified: Sep. 18, 2025
    • Vuln Type: Cross-Site Scripting
  • 8.1

    HIGH
    CVE-2025-56274

    SourceCodester Web-based Pharmacy Product Management System 1.0 is vulnerable to Incorrect Access Control, which allows low-privileged users to forge high privileged (such as admin) sessions and perform sensitive operations such as adding new users.... Read more

    • Published: Sep. 15, 2025
    • Modified: Sep. 18, 2025
    • Vuln Type: Authentication
  • 9.8

    CRITICAL
    CVE-2024-28423

    Airflow-Diagrams v2.1.0 was discovered to contain an arbitrary file upload vulnerability in the unsafe_load function at cli.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted YML file.... Read more

    Affected Products : airflow-diagrams
    • Published: Mar. 14, 2024
    • Modified: Sep. 18, 2025
  • 7.5

    HIGH
    CVE-2024-28425

    greykite v1.0.0 was discovered to contain an arbitrary file upload vulnerability in the load_obj function at /templates/pickle_utils.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted file.... Read more

    Affected Products : greykite
    • Published: Mar. 14, 2024
    • Modified: Sep. 18, 2025
  • 7.4

    HIGH
    CVE-2024-29154

    danielmiessler fabric through 1.3.0 allows installer/client/gui/static/js/index.js XSS because of innerHTML mishandling, such as in htmlToPlainText.... Read more

    Affected Products : fabric
    • Published: Mar. 18, 2024
    • Modified: Sep. 18, 2025
  • 9.8

    CRITICAL
    CVE-2025-55241

    Azure Entra Elevation of Privilege Vulnerability... Read more

    Affected Products : microsoft_entra_id entra_id
    • Published: Sep. 04, 2025
    • Modified: Sep. 18, 2025
  • 9.8

    CRITICAL
    CVE-2024-28392

    SQL injection vulnerability in pscartabandonmentpro v.2.0.11 and before allows a remote attacker to escalate privileges via the pscartabandonmentproFrontCAPUnsubscribeJobModuleFrontController::setEmailVisualized() method.... Read more

    Affected Products : abandoned_cart_reminder_pro
    • Published: Mar. 20, 2024
    • Modified: Sep. 18, 2025
  • 9.8

    CRITICAL
    CVE-2024-28395

    SQL injection vulnerability in Best-Kit bestkit_popup v.1.7.2 and before allows a remote attacker to escalate privileges via the bestkit_popup.php component.... Read more

    Affected Products : bestkit_popup
    • Published: Mar. 20, 2024
    • Modified: Sep. 18, 2025
  • 8.8

    HIGH
    CVE-2024-23755

    ClickUp Desktop before 3.3.77 on macOS and Windows allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings such as RunAsNode.... Read more

    Affected Products : macos windows clickup
    • Published: Mar. 23, 2024
    • Modified: Sep. 18, 2025
  • 9.8

    CRITICAL
    CVE-2024-28386

    An issue in Home-Made.io fastmagsync v.1.7.51 and before allows a remote attacker to execute arbitrary code via the getPhpBin() component.... Read more

    Affected Products : fastmag_sync
    • Published: Mar. 25, 2024
    • Modified: Sep. 18, 2025
  • 7.5

    HIGH
    CVE-2024-28387

    An issue in axonaut v.3.1.23 and before allows a remote attacker to obtain sensitive information via the log.txt component.... Read more

    Affected Products : axonaut
    • Published: Mar. 25, 2024
    • Modified: Sep. 18, 2025
Showing 20 of 294695 Results