Latest CVE Feed
-
7.5
HIGHCVE-2024-22640
TCPDF version <=6.6.5 is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted HTML page with a crafted color.... Read more
- Published: Apr. 19, 2024
- Modified: May. 21, 2025
-
7.5
HIGHCVE-2024-22641
TCPDF version 6.6.5 and before is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted SVG file.... Read more
Affected Products : tcpdf- Published: May. 28, 2024
- Modified: May. 21, 2025
-
6.1
MEDIUMCVE-2024-30885
Reflected Cross-Site Scripting (XSS) vulnerability in HadSky v7.6.3, allows remote attackers to execute arbitrary code and obtain sensitive information via the chklogin.php component .... Read more
Affected Products : hadsky- Published: Apr. 11, 2024
- Modified: May. 21, 2025
-
5.4
MEDIUMCVE-2024-30886
A stored cross-site scripting (XSS) vulnerability in the remotelink function of HadSky v7.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the url parameter.... Read more
Affected Products : hadsky- Published: Apr. 23, 2024
- Modified: May. 21, 2025
-
9.1
CRITICALCVE-2024-33661
Portainer before 2.20.0 allows redirects when the target is not index.yaml.... Read more
Affected Products : portainer- Published: Apr. 26, 2024
- Modified: May. 21, 2025
-
7.5
HIGHCVE-2024-33662
Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function.... Read more
Affected Products : portainer- Published: Oct. 02, 2024
- Modified: May. 21, 2025
-
9.8
CRITICALCVE-2024-50919
Jpress until v5.1.1 has arbitrary file uploads on the windows platform, and the construction of non-standard file formats such as .jsp. can lead to arbitrary command execution... Read more
- Published: Nov. 18, 2024
- Modified: May. 21, 2025
-
4.8
MEDIUMCVE-2025-2211
A vulnerability was found in aitangbao springboot-manager 3.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /sysDictDetail/add. The manipulation of the argument name leads to cross site scripting. The atta... Read more
Affected Products : springboot-manager- Published: Mar. 11, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-2210
A vulnerability has been found in aitangbao springboot-manager 3.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /sysJob/add. The manipulation of the argument name leads to cross site scripting. The ... Read more
Affected Products : springboot-manager- Published: Mar. 11, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-2209
A vulnerability, which was classified as problematic, was found in aitangbao springboot-manager 3.0. Affected is an unknown function of the file /sysDict/add. The manipulation of the argument name leads to cross site scripting. It is possible to launch th... Read more
Affected Products : springboot-manager- Published: Mar. 11, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-2208
A vulnerability, which was classified as problematic, has been found in aitangbao springboot-manager 3.0. This issue affects some unknown processing of the file /sysFiles/upload of the component Filename Handler. The manipulation of the argument name lead... Read more
Affected Products : springboot-manager- Published: Mar. 11, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-2207
A vulnerability classified as problematic was found in aitangbao springboot-manager 3.0. This vulnerability affects unknown code of the file /sys/dept. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remote... Read more
Affected Products : springboot-manager- Published: Mar. 11, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting
-
6.6
MEDIUMCVE-2024-20294
A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability... Read more
Affected Products : nx-os firepower_extensible_operating_system unified_computing_system nexus_7000 nexus_7000_10-slot nexus_7000_18-slot nexus_7000_9-slot nexus_5548p nexus_5548up nexus_5596up +237 more products- Published: Feb. 29, 2024
- Modified: May. 21, 2025
-
6.5
MEDIUMCVE-2025-26771
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Blocks – Gutenberg based Page Builder allows Stored XSS. This issue affects SKT Blocks – Gutenberg based Page Builder: from n/a through ... Read more
Affected Products : skt_blocks- Published: Feb. 17, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-4933
A vulnerability, which was classified as critical, was found in ponaravindb Hospital-Management-System 1.0. This affects an unknown part of the file /doctor-panel.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate ... Read more
Affected Products : hospital_management_system- Published: May. 19, 2025
- Modified: May. 21, 2025
-
9.8
CRITICALCVE-2025-4930
A vulnerability classified as critical has been found in Campcodes Online Shopping Portal 1.0. Affected is an unknown function of the file /my-cart.php. The manipulation of the argument billingaddress leads to sql injection. It is possible to launch the a... Read more
- Published: May. 19, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-2099
A vulnerability in the `preprocess_string()` function of the `transformers.testing_utils` module in huggingface/transformers version v4.48.3 allows for a Regular Expression Denial of Service (ReDoS) attack. The regular expression used to process code bloc... Read more
Affected Products : transformers- Published: May. 19, 2025
- Modified: May. 21, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2025-4928
A vulnerability was found in projectworlds Online Lawyer Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /save_lawyer_edit_profile.php. The manipulation leads to sql injection. The attack can be... Read more
- Published: May. 19, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4924
A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. Affected is an unknown function of the file /user_void_transaction.php. The manipulation of the argument order_id leads to sql injection.... Read more
- Published: May. 19, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
9.1
CRITICALCVE-2025-4912
A vulnerability has been found in SourceCodester Student Result Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/core/update_student.php of the component Image File Handler. Th... Read more
- Published: May. 19, 2025
- Modified: May. 21, 2025
- Vuln Type: Path Traversal