Latest CVE Feed
-
7.2
HIGHCVE-2024-2568
A vulnerability has been found in heyewei JFinalCMS 5.0.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/div_data/delete?divId=9 of the component Custom Data Page. The manipulation leads to sql in... Read more
Affected Products : jfinalcms- Published: Mar. 17, 2024
- Modified: May. 19, 2025
-
6.1
MEDIUMCVE-2024-26466
A DOM based cross-site scripting (XSS) vulnerability in the component /dom/ranges/Range-test-iframe.html of web-platform-tests/wpt before commit 938e843 allows attackers to execute arbitrary Javascript via sending a crafted URL.... Read more
Affected Products : web-platform-tests- Published: Feb. 26, 2024
- Modified: May. 19, 2025
-
6.1
MEDIUMCVE-2024-41693
Mashov - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)... Read more
Affected Products : mashov- Published: Jul. 30, 2024
- Modified: May. 19, 2025
-
5.3
MEDIUMCVE-2023-27043
The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypass a protection m... Read more
Affected Products : fedora active_iq_unified_manager ontap_select_deploy_administration_utility python- EPSS Score: %0.12
- Published: Apr. 19, 2023
- Modified: May. 19, 2025
-
8.1
HIGHCVE-2025-3952
The Projectopia – WordPress Project Management plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'pto_remove_logo' function in all versions up to, and incl... Read more
Affected Products : projectopia- Published: May. 01, 2025
- Modified: May. 19, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2024-13845
The Gravity Forms WebHooks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.6.0 via the 'process_feed' method of the GF_Webhooks class This makes it possible for authenticated attackers, with Admini... Read more
Affected Products : gravity_forms_webhooks- Published: May. 01, 2025
- Modified: May. 19, 2025
- Vuln Type: Server-Side Request Forgery
-
9.8
CRITICALCVE-2025-4149
A vulnerability was found in Netgear EX6200 1.0.3.94. It has been classified as critical. This affects the function sub_54014. The manipulation of the argument host leads to buffer overflow. It is possible to initiate the attack remotely. The vendor was c... Read more
- Published: May. 01, 2025
- Modified: May. 19, 2025
- Vuln Type: Memory Corruption
-
6.3
MEDIUMCVE-2025-24887
OpenCTI is an open-source cyber threat intelligence platform. In versions starting from 6.4.8 to before 6.4.10, the allow/deny lists can be bypassed, allowing a user to change attributes that are intended to be unmodifiable by the user. It is possible to ... Read more
Affected Products : opencti- Published: Apr. 30, 2025
- Modified: May. 19, 2025
- Vuln Type: Authorization
-
6.4
MEDIUMCVE-2025-4099
The List Children plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'list_children' shortcode in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping on user supplied attributes... Read more
Affected Products : list_children- Published: May. 01, 2025
- Modified: May. 19, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2024-21610
An Improper Handling of Exceptional Conditions vulnerability in the Class of Service daemon (cosd) of Juniper Networks Junos OS allows an authenticated, network-based attacker with low privileges to cause a limited Denial of Service (DoS). In a scaled Co... Read more
- Published: Apr. 12, 2024
- Modified: May. 19, 2025
-
8.8
HIGHCVE-2024-12950
A vulnerability was found in code-projects/projectworlds Travel Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /subcat.php. The manipulation of the argument catid leads to sql injection. The at... Read more
- Published: Dec. 26, 2024
- Modified: May. 18, 2025
-
9.8
CRITICALCVE-2025-3173
A vulnerability, which was classified as critical, was found in Project Worlds Online Lawyer Management System 1.0. Affected is an unknown function of the file /save_booking.php. The manipulation of the argument lawyer_id/description leads to sql injectio... Read more
- Published: Apr. 03, 2025
- Modified: May. 18, 2025
- Vuln Type: Injection
-
0.0
NACVE-2025-37880
In the Linux kernel, the following vulnerability has been resolved: um: work around sched_yield not yielding in time-travel mode sched_yield by a userspace may not actually cause scheduling in time-travel mode as no time has passed. In the case seen it ... Read more
Affected Products : linux_kernel- Published: May. 09, 2025
- Modified: May. 18, 2025
- Vuln Type: Race Condition
-
0.0
NACVE-2025-37821
In the Linux kernel, the following vulnerability has been resolved: sched/eevdf: Fix se->slice being set to U64_MAX and resulting crash There is a code path in dequeue_entities() that can set the slice of a sched_entity to U64_MAX, which sometimes resul... Read more
Affected Products : linux_kernel- Published: May. 08, 2025
- Modified: May. 18, 2025
- Vuln Type: Memory Corruption
-
4.5
MEDIUMCVE-2025-47203
dbclient in Dropbear SSH before 2025.88 allows command injection via an untrusted hostname argument, because a shell is used.... Read more
Affected Products : dropbear_ssh- Published: May. 07, 2025
- Modified: May. 17, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4331
A vulnerability classified as critical was found in SourceCodester Online Student Clearance System 1.0. This vulnerability affects unknown code of the file /Admin/login.php. The manipulation of the argument id/username/password leads to sql injection. The... Read more
Affected Products : online_student_clearance_system- Published: May. 06, 2025
- Modified: May. 17, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2023-1061
A vulnerability, which was classified as critical, has been found in SourceCodester Doctors Appointment System 1.0. This issue affects some unknown processing of the file /admin/edit-doc.php. The manipulation of the argument email/oldmail leads to sql inj... Read more
- EPSS Score: %0.05
- Published: Feb. 27, 2023
- Modified: May. 17, 2025
-
8.8
HIGHCVE-2023-1059
A vulnerability classified as critical was found in SourceCodester Doctors Appointment System 1.0. This vulnerability affects unknown code of the file /admin/doctors.php of the component Parameter Handler. The manipulation of the argument search/id leads ... Read more
- EPSS Score: %0.05
- Published: Feb. 27, 2023
- Modified: May. 17, 2025
-
9.9
CRITICALCVE-2025-2605
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Honeywell MB-Secure allows Privilege Abuse. This issue affects MB-Secure: from V11.04 before V12.53 and MB-Secure PRO from V01.06 before V03.09.Hon... Read more
- Published: May. 02, 2025
- Modified: May. 17, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2025-22458
DLL hijacking in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an authenticated attacker to escalate to System.... Read more
Affected Products : endpoint_manager- Published: Apr. 08, 2025
- Modified: May. 17, 2025
- Vuln Type: Authorization