Latest CVE Feed
-
9.8
CRITICALCVE-2024-28322
SQL Injection vulnerability in /event-management-master/backend/register.php in PuneethReddyHC Event Management 1.0 allows attackers to run arbitrary SQL commands via the event_id parameter in a crafted POST request.... Read more
Affected Products : event_management- Published: Apr. 26, 2024
- Modified: May. 14, 2025
-
5.4
MEDIUMCVE-2024-3433
A vulnerability classified as problematic has been found in PuneethReddyHC Event Management 1.0. Affected is an unknown function of the file /backend/register.php. The manipulation of the argument event_id/full_name/email/mobile/college/branch leads to cr... Read more
Affected Products : event_management- Published: Apr. 07, 2024
- Modified: May. 14, 2025
-
8.8
HIGHCVE-2024-3432
A vulnerability was found in PuneethReddyHC Event Management 1.0. It has been rated as critical. This issue affects some unknown processing of the file /backend/register.php. The manipulation of the argument event_id/full_name/email/mobile/college/branch ... Read more
Affected Products : event_management- Published: Apr. 07, 2024
- Modified: May. 14, 2025
-
5.5
MEDIUMCVE-2025-30320
InDesign Desktop versions ID19.5.2, ID20.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption in ... Read more
- Published: May. 13, 2025
- Modified: May. 14, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2025-30319
InDesign Desktop versions ID19.5.2, ID20.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing a disruption i... Read more
- Published: May. 13, 2025
- Modified: May. 14, 2025
- Vuln Type: Denial of Service
-
7.8
HIGHCVE-2025-30318
InDesign Desktop versions ID19.5.2, ID20.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a vi... Read more
- Published: May. 13, 2025
- Modified: May. 14, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-30310
Dreamweaver Desktop versions 21.4 and earlier are affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requi... Read more
- Published: May. 13, 2025
- Modified: May. 14, 2025
- Vuln Type: Memory Corruption
-
6.1
MEDIUMCVE-2024-11849
The Pods WordPress plugin before 3.2.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for ex... Read more
Affected Products : pods- Published: Jan. 06, 2025
- Modified: May. 14, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-24645
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rob Scott Eazy Under Construction allows Reflected XSS. This issue affects Eazy Under Construction: from n/a through 1.0.... Read more
Affected Products :- Published: Apr. 17, 2025
- Modified: May. 14, 2025
- Vuln Type: Cross-Site Scripting
-
3.4
LOWCVE-2022-41603
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.... Read more
- EPSS Score: %0.01
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
7.8
HIGHCVE-2022-41305
A maliciously crafted PKT file when consumed through SubassemblyComposer.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in ... Read more
Affected Products : subassembly_composer- EPSS Score: %0.04
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
7.3
HIGHCVE-2022-2865
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, 15.2 to 15.2.4 and 15.3 prior to 15.3.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XS... Read more
Affected Products : gitlab- EPSS Score: %0.13
- Published: Oct. 17, 2022
- Modified: May. 14, 2025
-
6.1
MEDIUMCVE-2024-12302
The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its Campaign settings, which could allow authors and above to perform Stored Cross-Site Scripting attacks... Read more
Affected Products : icegram_engage- Published: Jan. 06, 2025
- Modified: May. 14, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2024-12311
The Email Subscribers by Icegram Express WordPress plugin before 5.7.44 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks... Read more
Affected Products : email_subscribers_\&_newsletters- Published: Jan. 06, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
2.7
LOWCVE-2024-10102
The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some of its Gallery settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks... Read more
- Published: Jan. 07, 2025
- Modified: May. 14, 2025
- Vuln Type: Cross-Site Scripting
-
7.0
HIGHCVE-2025-30378
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.... Read more
- Published: May. 13, 2025
- Modified: May. 14, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-8855
The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitize and escape a parameter before using it in a SQL statement, allowing editors and above to perform SQL injection attacks... Read more
Affected Products : wordpress_auction- Published: Jan. 07, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
4.8
MEDIUMCVE-2024-8857
The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Stored Cross-Site Scripting attacks.... Read more
Affected Products : wordpress_auction- Published: Jan. 07, 2025
- Modified: May. 14, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-3819
A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/search-appointment.php. The manipulation of the argument searchdata lead... Read more
Affected Products : men_salon_management_system- Published: Apr. 19, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
5.9
MEDIUMCVE-2025-39444
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maxfoundry MaxButtons allows Stored XSS.This issue affects MaxButtons: from n/a through 9.8.3.... Read more
Affected Products : maxbuttons- Published: Apr. 17, 2025
- Modified: May. 14, 2025
- Vuln Type: Cross-Site Scripting