Latest CVE Feed
-
5.4
MEDIUMCVE-2022-42114
A Cross-site scripting (XSS) vulnerability in the Role module's edit role assignees page in Liferay Portal 7.4.0 through 7.4.3.36, and Liferay DXP 7.4 before update 37 allows remote attackers to inject arbitrary web script or HTML.... Read more
- EPSS Score: %0.19
- Published: Oct. 18, 2022
- Modified: May. 10, 2025
-
6.1
MEDIUMCVE-2022-42113
A Cross-site scripting (XSS) vulnerability in Document Library module in Liferay Portal 7.4.3.30 through 7.4.3.36, and Liferay DXP 7.4 update 30 through update 36 allows remote attackers to inject arbitrary web script or HTML via the `redirect` parameter.... Read more
- EPSS Score: %0.18
- Published: Oct. 18, 2022
- Modified: May. 10, 2025
-
7.5
HIGHCVE-2022-41547
Mobile Security Framework (MobSF) v0.9.2 and below was discovered to contain a local file inclusion (LFI) vulnerability in the StaticAnalyzer/views.py script. This vulnerability allows attackers to read arbitrary files via a crafted HTTP request.... Read more
Affected Products : mobile_security_framework- EPSS Score: %3.28
- Published: Oct. 18, 2022
- Modified: May. 10, 2025
-
8.8
HIGHCVE-2022-3368
A vulnerability within the Software Updater functionality of Avira Security for Windows allowed an attacker with write access to the filesystem, to escalate his privileges in certain scenarios. The issue was fixed with Avira Security version 1.1.72.30556.... Read more
Affected Products : avira_security- EPSS Score: %2.60
- Published: Oct. 17, 2022
- Modified: May. 10, 2025
-
7.0
HIGHCVE-2025-46326
snowflake-connector-net is the Snowflake Connector for .NET. Versions starting from 2.1.2 to before 4.4.1, are vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition. When using the Easy Logging feature on Linux and macOS, the Connector read... Read more
Affected Products : snowflake_connector- Published: Apr. 28, 2025
- Modified: May. 10, 2025
- Vuln Type: Race Condition
-
9.8
CRITICALCVE-2024-32499
Newforma Project Center Server through 2023.3.0.32259 allows remote code execution because .NET Remoting is exposed.... Read more
Affected Products : project_center_server- Published: Apr. 28, 2025
- Modified: May. 10, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-4028
A vulnerability has been found in PHPGurukul COVID19 Testing Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /profile.php. The manipulation of the argument mobilenumber leads to sql ... Read more
Affected Products : covid19_testing_management_system- Published: Apr. 28, 2025
- Modified: May. 10, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2025-4029
A vulnerability was found in code-projects Personal Diary Management System 1.0 and classified as critical. Affected by this issue is the function addrecord of the component New Record Handler. The manipulation of the argument filename leads to stack-base... Read more
Affected Products : personal_diary_management_system- Published: Apr. 28, 2025
- Modified: May. 10, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4030
A vulnerability was found in PHPGurukul COVID19 Testing Management System 1.0. It has been classified as critical. This affects an unknown part of the file /search-report-result.php. The manipulation of the argument serachdata leads to sql injection. It i... Read more
Affected Products : covid19_testing_management_system- Published: Apr. 28, 2025
- Modified: May. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4031
A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/aboutus.php. The manipulation of the argument pagetitle leads to sql injection. The atta... Read more
Affected Products : pre-school_enrollment_system- Published: Apr. 28, 2025
- Modified: May. 10, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2025-34489
GFI MailEssentials prior to version 21.8 is vulnerable to a local privilege escalation issue. A local attacker can escalate to NT Authority/SYSTEM by sending a crafted serialized payload to a .NET Remoting Service.... Read more
Affected Products : mailessentials- Published: Apr. 28, 2025
- Modified: May. 10, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-34490
GFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An authenticated and remote attacker can send crafted HTTP requests to read arbitrary system files.... Read more
Affected Products : mailessentials- Published: Apr. 28, 2025
- Modified: May. 10, 2025
- Vuln Type: XML External Entity
-
8.1
HIGHCVE-2025-4032
A vulnerability was found in inclusionAI AWorld up to 8c257626e648d98d793dd9a1a950c2af4dd84c4e. It has been rated as critical. This issue affects the function subprocess.run/subprocess.Popen of the file AWorld/aworld/virtual_environments/terminals/shell_t... Read more
Affected Products : aworld- Published: Apr. 28, 2025
- Modified: May. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4033
A vulnerability classified as critical has been found in PHPGurukul Nipah Virus Testing Management System 1.0. Affected is an unknown function of the file /patient-search-report.php. The manipulation of the argument searchdata leads to sql injection. It i... Read more
Affected Products : nipah_virus_testing_management_system- Published: Apr. 28, 2025
- Modified: May. 10, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-34491
GFI MailEssentials prior to version 21.8 is vulnerable to a .NET deserialization issue. A remote and authenticated attacker can execute arbitrary code by sending crafted serialized .NET when joining to a Multi-Server setup.... Read more
Affected Products : mailessentials- Published: Apr. 28, 2025
- Modified: May. 10, 2025
- Vuln Type: Misconfiguration
-
7.8
HIGHCVE-2025-3224
A vulnerability in the update process of Docker Desktop for Windows versions prior to 4.41.0 could allow a local, low-privileged attacker to escalate privileges to SYSTEM. During an update, Docker Desktop attempts to delete files and subdirectories under ... Read more
Affected Products : desktop- Published: Apr. 28, 2025
- Modified: May. 10, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-4034
A vulnerability classified as critical was found in projectworlds Online Examination System 1.0. Affected by this vulnerability is an unknown functionality of the file /inser_doc_process.php. The manipulation of the argument Doc_ID leads to sql injection.... Read more
- Published: Apr. 28, 2025
- Modified: May. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4036
A vulnerability was found in 201206030 Novel 3.5.0 and classified as critical. This issue affects the function updateBookChapter of the file src/main/java/io/github/xxyopen/novel/controller/author/AuthorController.java of the component Chapter Handler. Th... Read more
Affected Products : novel- Published: Apr. 28, 2025
- Modified: May. 10, 2025
- Vuln Type: Authorization
-
6.1
MEDIUMCVE-2024-10635
Enterprise Protection contains an improper input validation vulnerability in attachment defense that allows an unauthenticated remote attacker to bypass attachment scanning security policy by sending a malicious S/MIME attachment with an opaque signature.... Read more
Affected Products : enterprise_protection- Published: Apr. 28, 2025
- Modified: May. 10, 2025
- Vuln Type: Misconfiguration
-
6.3
MEDIUMCVE-2024-11922
Missing input validation in certain features of the Web Client of Fortra's GoAnywhere prior to version 7.8.0 allows an attacker with permission to trigger emails to insert arbitrary HTML or JavaScript into an email.... Read more
Affected Products : goanywhere_managed_file_transfer- Published: Apr. 28, 2025
- Modified: May. 10, 2025
- Vuln Type: Cross-Site Scripting