Latest CVE Feed
-
5.9
MEDIUMCVE-2025-39444
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maxfoundry MaxButtons allows Stored XSS.This issue affects MaxButtons: from n/a through 9.8.3.... Read more
Affected Products : maxbuttons- Published: Apr. 17, 2025
- Modified: May. 14, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2023-43958
An arbitrary file upload vulnerability in the component /jquery-file-upload/server/php/index.php of Hospital Management System v4.0 allows an unauthenticated attacker to upload any file to the server and execute arbitrary code.... Read more
Affected Products : hospital_management_system- Published: Apr. 22, 2025
- Modified: May. 14, 2025
- Vuln Type: Authentication
-
4.9
MEDIUMCVE-2025-47729
The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which is different functionality than described in the TeleMessage "End-to-End encryption from the mobile phone through to... Read more
Affected Products : text_message_archiver- Actively Exploited
- Published: May. 08, 2025
- Modified: May. 14, 2025
- Vuln Type: Cryptography
-
4.8
MEDIUMCVE-2025-29568
A vulnerability has been discovered in the code-projects Online Class and Exam Scheduling System 1.0. The issue affects some unknown features in the file /Scheduling/pages/class_sched.php. Manipulating the class parameter can lead to cross-site scripting ... Read more
Affected Products : online_class_and_exam_scheduling_system- Published: Apr. 24, 2025
- Modified: May. 14, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-44134
A vulnerability was found in Code-Projects Online Class and Exam Scheduling System 1.0 in the file /Scheduling/pages/class_save.php. Manipulation of parameter class will lead to SQL injection attacks.... Read more
Affected Products : online_class_and_exam_scheduling_system- Published: Apr. 24, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-44135
A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0 in /Scheduling/pages/profile_update.php. Manipulating the parameter username will cause SQL injection attacks.... Read more
Affected Products : online_class_and_exam_scheduling_system- Published: Apr. 24, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
5.5
MEDIUMCVE-2024-0340
A vulnerability was found in vhost_new_msg in drivers/vhost/vhost.c in the Linux kernel, which does not properly initialize memory in messages passed between virtual guests and the host operating system in the vhost/vhost.c:vhost_new_msg() function. This ... Read more
- EPSS Score: %0.01
- Published: Jan. 09, 2024
- Modified: May. 14, 2025
-
6.5
MEDIUMCVE-2025-32912
A flaw was found in libsoup, where SoupAuthDigest is vulnerable to a NULL pointer dereference. The HTTP server may cause the libsoup client to crash.... Read more
- Published: Apr. 14, 2025
- Modified: May. 14, 2025
- Vuln Type: Denial of Service
-
5.3
MEDIUMCVE-2024-52616
A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction ID... Read more
- Published: Nov. 21, 2024
- Modified: May. 14, 2025
-
9.8
CRITICALCVE-2025-0793
A vulnerability has been found in ESAFENET CDG V5 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /todoDetail.jsp. The manipulation of the argument flowId leads to sql injection. The attack can be launche... Read more
Affected Products : cdg- Published: Jan. 29, 2025
- Modified: May. 13, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-0794
A vulnerability was found in ESAFENET CDG V5 and classified as problematic. Affected by this issue is some unknown functionality of the file /todoDetail.jsp. The manipulation of the argument curpage leads to cross site scripting. The attack may be launche... Read more
Affected Products : cdg- Published: Jan. 29, 2025
- Modified: May. 13, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-0795
A vulnerability was found in ESAFENET CDG V5. It has been classified as problematic. This affects an unknown part of the file /todolistjump.jsp. The manipulation of the argument flowId leads to cross site scripting. It is possible to initiate the attack r... Read more
Affected Products : cdg- Published: Jan. 29, 2025
- Modified: May. 13, 2025
- Vuln Type: Cross-Site Scripting
-
5.9
MEDIUMCVE-2024-45627
In Apache Linkis <1.7.0, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in the DataSource Manager Module will allow the attacker to read arbitrary files from the Linkis server. Therefore, th... Read more
Affected Products : linkis- Published: Jan. 14, 2025
- Modified: May. 13, 2025
- Vuln Type: Information Disclosure
-
5.4
MEDIUMCVE-2024-9020
The List category posts WordPress plugin before 0.90.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to pe... Read more
Affected Products : list_category_posts- Published: Jan. 18, 2025
- Modified: May. 13, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2024-12321
The WC Affiliate WordPress plugin through 2.3.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.... Read more
Affected Products : wc_affiliate- Published: Jan. 27, 2025
- Modified: May. 13, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-32908
A flaw was found in libsoup. The HTTP/2 server in libsoup may not fully validate the values of pseudo-headers :scheme, :authority, and :path, which may allow a user to cause a denial of service (DoS).... Read more
- Published: Apr. 14, 2025
- Modified: May. 13, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2022-22128
Tableau discovered a path traversal vulnerability affecting Tableau Server Administration Agent’s internal file transfer service that could allow remote code execution.Tableau only supports product versions for 24 months after release. Older versions have... Read more
- EPSS Score: %3.61
- Published: Oct. 17, 2022
- Modified: May. 13, 2025
-
9.8
CRITICALCVE-2022-0699
A double-free condition exists in contrib/shpsort.c of shapelib 1.5.0 and older releases. This issue may allow an attacker to cause a denial of service or have other unspecified impact via control over malloc.... Read more
Affected Products : shapelib- EPSS Score: %0.11
- Published: Oct. 17, 2022
- Modified: May. 13, 2025
-
8.8
HIGHCVE-2019-14841
A flaw was found in the RHDM, where an authenticated attacker can change their assigned role in the response header. This flaw allows an attacker to gain admin privileges in the Business Central Console.... Read more
- EPSS Score: %0.17
- Published: Oct. 17, 2022
- Modified: May. 13, 2025
-
7.5
HIGHCVE-2019-14840
A flaw was found in the RHDM, where sensitive HTML form fields like Password has auto-complete enabled which may lead to leak of credentials.... Read more
Affected Products : decision_manager- EPSS Score: %0.16
- Published: Oct. 17, 2022
- Modified: May. 13, 2025