Latest CVE Feed
-
6.1
MEDIUMCVE-2022-40606
MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability than CVE-2022-40605.... Read more
Affected Products : caldera- EPSS Score: %0.11
- Published: Oct. 17, 2022
- Modified: May. 14, 2025
-
6.1
MEDIUMCVE-2022-40605
MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a different vulnerability than CVE-2022-40606.... Read more
Affected Products : caldera- EPSS Score: %0.11
- Published: Oct. 17, 2022
- Modified: May. 14, 2025
-
9.8
CRITICALCVE-2022-40055
An issue in GX Group GPON ONT Titanium 2122A T2122-V1.26EXL allows attackers to escalate privileges via a brute force attack at the login page.... Read more
- EPSS Score: %0.12
- Published: Oct. 17, 2022
- Modified: May. 14, 2025
-
4.3
MEDIUMCVE-2022-3331
An issue has been discovered in GitLab EE affecting all versions starting from 14.5 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab's Zentao integration has an insecure direct object refe... Read more
Affected Products : gitlab- EPSS Score: %0.12
- Published: Oct. 17, 2022
- Modified: May. 14, 2025
-
7.2
HIGHCVE-2022-3243
The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not properly sanitise and escape imported data before using them back SQL statements, leading to SQL injection exploitable by high privilege users such as admin... Read more
Affected Products : import_all_pages\,_post_types\,_products\,_orders\,_and_users_as_xml_\&_csv- EPSS Score: %0.29
- Published: Oct. 17, 2022
- Modified: May. 14, 2025
-
5.9
MEDIUMCVE-2022-3206
The Passster WordPress plugin before 3.5.5.5.2 stores the password inside a cookie named "passster" using base64 encoding method which is easy to decode. This puts the password at risk in case the cookies get leaked.... Read more
Affected Products : passster- EPSS Score: %0.10
- Published: Oct. 17, 2022
- Modified: May. 14, 2025
-
6.5
MEDIUMCVE-2022-3165
An integer underflow issue was found in the QEMU VNC server while processing ClientCutText messages in the extended format. A malicious client could use this flaw to make QEMU unresponsive by sending a specially crafted payload message, resulting in a den... Read more
- EPSS Score: %0.10
- Published: Oct. 17, 2022
- Modified: May. 14, 2025
-
7.5
HIGHCVE-2024-3353
A vulnerability was found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0 and classified as critical. This issue affects some unknown processing of the file admin/mod_reports/index.php. The manipulation of the argument categ/end leads ... Read more
Affected Products : aplaya_beach_resort_online_reservation_system- Published: Apr. 05, 2024
- Modified: May. 14, 2025
-
9.8
CRITICALCVE-2024-2569
A vulnerability was found in SourceCodester Employee Task Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin-manage-user.php. The manipulation leads to execution after redirect. The at... Read more
- Published: Mar. 18, 2024
- Modified: May. 14, 2025
-
7.8
HIGHCVE-2025-29824
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 +10 more products- Actively Exploited
- Published: Apr. 08, 2025
- Modified: May. 14, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-3244
A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /add-admin.php of the component Create User Page. The ma... Read more
- Published: Apr. 04, 2025
- Modified: May. 14, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-3151
A vulnerability was found in SourceCodester Gym Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /signup.php. The manipulation of the argument user_name leads to sql injection. The atta... Read more
- Published: Apr. 03, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-3143
A vulnerability classified as critical has been found in SourceCodester Apartment Visitor Management System 1.0. Affected is an unknown function of the file /visitor-entry.php. The manipulation of the argument visname/address leads to sql injection. It is... Read more
- Published: Apr. 03, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-3142
A vulnerability was found in SourceCodester Apartment Visitor Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /add-apartment.php. The manipulation of the argument buildingno leads to sql injecti... Read more
- Published: Apr. 03, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2846
A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. This vulnerability affects the function registration of the file /oews/classes/Users.php?f=registration of the component Registration. The manipulation of the argu... Read more
Affected Products : online_eyewear_shop- Published: Mar. 27, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-3697
A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. This issue affects some unknown processing of the file /edit-product.php. The manipulation of the argument ID leads to sq... Read more
- Published: Apr. 16, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-3696
A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. This vulnerability affects unknown code of the file /search/search_stock. php. The manipulation of the argument Name leads to sql injectio... Read more
- Published: Apr. 16, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3694
A vulnerability classified as critical has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. This affects an unknown part of the component Login Handler. The manipulation of the argument login_email leads to sql injection. It ... Read more
- Published: Apr. 16, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3315
A vulnerability was found in SourceCodester Apartment Visitor Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /view-report.php. The manipulation of the argument fromdate/todate leads to sq... Read more
- Published: Apr. 06, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3314
A vulnerability has been found in SourceCodester Apartment Visitor Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /forgotpw.php. The manipulation of the argument secode leads to sql... Read more
- Published: Apr. 06, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection