Latest CVE Feed
-
6.1
MEDIUMCVE-2025-44182
Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the vehiclename, modelnumber, regnumber, vehiclesubtype, chasisnum, enginenumber' in the /admin/edit-vehicle.php component. This allows attackers to execute a... Read more
Affected Products : vehicle_record_management_system- Published: May. 15, 2025
- Modified: May. 28, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-44183
Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php via the name, email, and mobile parameters.... Read more
Affected Products : vehicle_record_management_system- Published: May. 15, 2025
- Modified: May. 28, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-4699
A vulnerability classified as critical was found in PHPGurukul Apartment Visitors Management System 1.0. This vulnerability affects unknown code of the file /admin/visitors-form.php. The manipulation of the argument Category leads to sql injection. The at... Read more
Affected Products : apartment_visitors_management_system- Published: May. 15, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2025-44185
SourceCodester Best Employee Management System V1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/change_pass.php via the password parameter.... Read more
Affected Products : best_employee_management_system- Published: May. 15, 2025
- Modified: May. 28, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.1
MEDIUMCVE-2019-11843
The MailPoet plugin before 3.23.2 for WordPress allows remote attackers to inject arbitrary web script or HTML using extra parameters in the URL (Reflective Server-Side XSS).... Read more
- Published: Jun. 02, 2020
- Modified: May. 28, 2025
-
9.8
CRITICALCVE-2025-4702
A vulnerability, which was classified as critical, was found in PHPGurukul Vehicle Parking Management System 1.13. Affected is an unknown function of the file /admin/add-category.php. The manipulation of the argument catename leads to sql injection. It is... Read more
Affected Products : vehicle_parking_management_system- Published: May. 15, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4703
A vulnerability has been found in PHPGurukul Vehicle Parking Management System 1.13 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/admin-profile.php. The manipulation of the argument contactnumber... Read more
Affected Products : vehicle_parking_management_system- Published: May. 15, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-4704
A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/edit-category.php. The manipulation of the argument editid leads to sql inje... Read more
Affected Products : vehicle_parking_management_system- Published: May. 15, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4705
A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13. It has been classified as critical. This affects an unknown part of the file /admin/view-incomingvehicle-detail.php. The manipulation of the argument viewid leads to sql injec... Read more
Affected Products : vehicle_parking_management_system- Published: May. 15, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
5.1
MEDIUMCVE-2025-4744
A vulnerability, which was classified as problematic, has been found in code-projects Employee Record System 1.0. Affected by this issue is some unknown functionality of the file dashboard\edit_employee.php. The manipulation of the argument employeed_id/f... Read more
Affected Products : employee_record_system- Published: May. 16, 2025
- Modified: May. 28, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-4743
A vulnerability classified as critical was found in code-projects Employee Record System 1.0. Affected by this vulnerability is an unknown functionality of the file /dashboard/getData.php. The manipulation of the argument keywords leads to sql injection. ... Read more
Affected Products : employee_record_system- Published: May. 16, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4741
A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /pages/purchase_add.php. The manipulation of the argument ID leads to sql injection. The attack ma... Read more
Affected Products : sales_and_inventory_system- Published: May. 16, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-4735
A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /pages/product.php. The manipulation of the argument Picture leads to unrestricte... Read more
Affected Products : sales_and_inventory_system- Published: May. 16, 2025
- Modified: May. 28, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-4719
A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /pages/cash_transaction.php. The manipulation of the argument cid leads to sql injection. Th... Read more
Affected Products : sales_and_inventory_system- Published: May. 15, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4718
A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /pages/customer_add.php. The manipulation of the argument last leads to sql injec... Read more
Affected Products : sales_and_inventory_system- Published: May. 15, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2023-7228
The illi Link Party! WordPress plugin through 1.0 does not sanitise and escape some parameters, which could allow unauthenticated vistors to perform Cross-Site Scripting attacks.... Read more
- Published: May. 15, 2025
- Modified: May. 28, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-4710
A vulnerability, which was classified as critical, has been found in Campcodes Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file /pages/transaction.php. The manipulation of the argument cid leads to sql injec... Read more
Affected Products : sales_and_inventory_system- Published: May. 15, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4709
A vulnerability classified as critical was found in Campcodes Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/transaction_del.php. The manipulation of the argument ID leads to sql injection. Th... Read more
Affected Products : sales_and_inventory_system- Published: May. 15, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4708
A vulnerability classified as critical has been found in Campcodes Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/sales_add.php. The manipulation of the argument discount leads to sql injection. It is possible to launch... Read more
Affected Products : sales_and_inventory_system- Published: May. 15, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2391
A vulnerability classified as critical was found in code-projects Blood Bank Management System 1.0. This vulnerability affects unknown code of the file /admin/admin_login.php of the component Admin Login Page. The manipulation leads to sql injection. The ... Read more
- Published: Mar. 17, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection