Latest CVE Feed
-
9.8
CRITICALCVE-2025-5057
A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/insert-product.php. The manipulation of the argument Category leads to sql injection.... Read more
Affected Products : online_shopping_portal- Published: May. 21, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
7.2
HIGHCVE-2025-5059
A vulnerability classified as critical has been found in Campcodes Online Shopping Portal 1.0. This affects an unknown part of the file /admin/edit-subcategory.php. The manipulation of the argument productimage1/productimage2/productimage3 leads to unrest... Read more
Affected Products : online_shopping_portal- Published: May. 21, 2025
- Modified: May. 28, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-5077
A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been classified as critical. This affects an unknown part of the file /admin/edit-subcategory.php. The manipulation of the argument Category leads to sql injection. It is possible t... Read more
Affected Products : online_shopping_portal- Published: May. 22, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5081
A vulnerability classified as critical was found in Campcodes Cybercafe Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /adminprofile.php. The manipulation of the argument mobilenumber leads to sql injection. ... Read more
Affected Products : cybercafe_management_system- Published: May. 22, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4938
A vulnerability was found in PHPGurukul Employee Record Management System 1.3. It has been rated as critical. Affected by this issue is some unknown functionality of the file /registererms.php. The manipulation of the argument Email leads to sql injection... Read more
Affected Products : employee_record_management_system- Published: May. 19, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-4939
A vulnerability classified as problematic was found in PHPGurukul Credit Card Application Management System 1.0. This vulnerability affects unknown code of the file /admin/new-ccapplication.php. The manipulation leads to cross site scripting. The attack c... Read more
Affected Products : credit_card_application_management_system- Published: May. 19, 2025
- Modified: May. 28, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-4941
A vulnerability, which was classified as critical, was found in PHPGurukul Credit Card Application Management System 1.0. Affected is an unknown function of the file /admin/index.php. The manipulation of the argument Username leads to sql injection. It is... Read more
Affected Products : credit_card_application_management_system- Published: May. 19, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5002
A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file /user_proposal_update_order.php. The manipulation of the argument order_id leads to sql injectio... Read more
- Published: May. 20, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5006
A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/category.php. The manipulation of the argument Category leads to sql injection. It is possible to lau... Read more
Affected Products : online_shopping_portal- Published: May. 20, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
4.6
MEDIUMCVE-2024-51106
A cross-site scripting (XSS) vulnerability in the component mcgs/admin/aboutus.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the pag... Read more
Affected Products : medical_card_generation_system- Published: May. 19, 2025
- Modified: May. 28, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-4816
A vulnerability was found in SourceCodester Doctor's Appointment System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/appointment.php of the component GET Parameter Handler. The manipulation of the argument ID le... Read more
Affected Products : doctors_appointment_system- Published: May. 17, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4817
A vulnerability was found in Sourcecodester Doctor's Appointment System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/delete-appointment.php of the component GET Parameter Handler. The manipulation of th... Read more
Affected Products : doctors_appointment_system- Published: May. 17, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4818
A vulnerability was found in SourceCodester Doctor's Appointment System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/delete-doctor.php of the component GET Parameter Handler. The manipulation of the arg... Read more
Affected Products : doctors_appointment_system- Published: May. 17, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
6.8
MEDIUMCVE-2024-3669
The Web Directory Free WordPress plugin before 1.7.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more
Affected Products : web_directory_free- Published: Jul. 30, 2024
- Modified: May. 28, 2025
-
5.9
MEDIUMCVE-2024-4096
The Responsive Tabs WordPress plugin through 4.0.8 does not sanitise and escape some of its Tab settings, which could allow high privilege users such as Contributors and above to perform Stored Cross-Site Scripting attacks... Read more
Affected Products : responsive_tabs- Published: Jul. 30, 2024
- Modified: May. 28, 2025
-
7.2
HIGHCVE-2024-5807
The Business Card WordPress plugin through 1.0.0 does not prevent high privilege users like administrators from uploading malicious PHP files, which could allow them to run arbitrary code on servers hosting their site, even in MultiSite configurations.... Read more
Affected Products : business_card- Published: Jul. 30, 2024
- Modified: May. 28, 2025
-
4.3
MEDIUMCVE-2024-5808
The WP Ajax Contact Form WordPress plugin through 2.2.2 does not have CSRF check in place when deleting emails from the email list, which could allow attackers to make a logged in admin perform such action via a CSRF attack... Read more
Affected Products : wp_ajax_contact_form- Published: Jul. 30, 2024
- Modified: May. 28, 2025
-
6.1
MEDIUMCVE-2024-5809
The WP Ajax Contact Form WordPress plugin through 2.2.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against admin users... Read more
Affected Products : wp_ajax_contact_form- Published: Jul. 30, 2024
- Modified: May. 28, 2025
-
9.1
CRITICALCVE-2024-5975
The CZ Loan Management WordPress plugin through 1.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection... Read more
Affected Products : cz_loan_management- Published: Jul. 30, 2024
- Modified: May. 28, 2025
-
7.6
HIGHCVE-2025-31213
A logging issue was addressed with improved data redaction. This issue is fixed in iPadOS 17.7.7, macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. An app may be able to access associated usernames and websites in a user's iCloud Keychain.... Read more
- Published: May. 12, 2025
- Modified: May. 27, 2025
- Vuln Type: Information Disclosure