Latest CVE Feed
-
4.8
MEDIUMCVE-2024-13381
The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is di... Read more
Affected Products : calculated_fields_form- Published: May. 01, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
7.8
HIGHCVE-2025-31172
Memory write permission bypass vulnerability in the kernel futex module Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
Affected Products : harmonyos- Published: Apr. 07, 2025
- Modified: May. 07, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4151
A vulnerability was found in PHPGurukul Curfew e-Pass Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/pass-bwdates-reports-details.php. The manipulation of the argument fromdate leads to ... Read more
Affected Products : curfew_e-pass_management_system- Published: May. 01, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4152
A vulnerability classified as critical has been found in PHPGurukul Online Birth Certificate System 1.0. Affected is an unknown function of the file /admin/bwdates-reports-details.php. The manipulation of the argument fromdate leads to sql injection. It i... Read more
Affected Products : online_birth_certificate_system- Published: May. 01, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
4.3
MEDIUMCVE-2025-21530
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Supported versions that are affected are 8.60 and 8.61. Easily exploitable vulnerability allows low privileged attacker with network access... Read more
Affected Products : peoplesoft_enterprise_peopletools- Published: Jan. 21, 2025
- Modified: May. 07, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2025-21545
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch). Supported versions that are affected are 8.60 and 8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via... Read more
Affected Products : peoplesoft_enterprise_peopletools- Published: Jan. 21, 2025
- Modified: May. 07, 2025
- Vuln Type: Denial of Service
-
6.0
MEDIUMCVE-2025-21551
Vulnerability in the Oracle Solaris product of Oracle Systems (component: File system). The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris ... Read more
- Published: Jan. 21, 2025
- Modified: May. 07, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2025-24399
Jenkins OpenId Connect Authentication Plugin 4.452.v2849b_d3945fa_ and earlier, except 4.438.440.v3f5f201de5dc, treats usernames as case-insensitive, allowing attackers on Jenkins instances configured with a case-sensitive OpenID Connect provider to log i... Read more
- Published: Jan. 22, 2025
- Modified: May. 07, 2025
- Vuln Type: Authentication
-
5.1
MEDIUMCVE-2025-0709
A vulnerability was found in Dcat-Admin 2.2.1-beta. It has been rated as problematic. This issue affects some unknown processing of the file /admin/auth/roles of the component Roles Page. The manipulation leads to cross site scripting. The attack may be i... Read more
Affected Products : dcat_admin- Published: Jan. 24, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-4153
A vulnerability classified as critical was found in PHPGurukul Park Ticketing Management System 2.0. Affected by this vulnerability is an unknown functionality of the file /profile.php. The manipulation of the argument adminname leads to sql injection. Th... Read more
Affected Products : park_ticketing_management_system- Published: May. 01, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-4154
A vulnerability, which was classified as critical, has been found in PHPGurukul Pre-School Enrollment System 1.0. Affected by this issue is some unknown functionality of the file /admin/enrollment-details.php. The manipulation of the argument Status leads... Read more
Affected Products : pre-school_enrollment_system- Published: May. 01, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-4155
A vulnerability, which was classified as critical, was found in PHPGurukul Boat Booking System 1.0. This affects an unknown part of the file /admin/edit-boat.php. The manipulation of the argument bid leads to sql injection. It is possible to initiate the ... Read more
Affected Products : boat_booking_system- Published: May. 01, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
4.7
MEDIUMCVE-2025-1749
HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to modify the HTML of the victim's browser by sending a malicious URL and modifying the parameter name in /account/voucher.... Read more
Affected Products : opencart- Published: Feb. 28, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
4.7
MEDIUMCVE-2025-1748
HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to modify the HTML of the victim's browser by sending a malicious URL and modifying the parameter name in /account/register.... Read more
Affected Products : opencart- Published: Feb. 28, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
4.7
MEDIUMCVE-2025-1747
HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to modify the HTML of the victim's browser by sending a malicious URL and modifying the parameter name in /account/login.... Read more
Affected Products : opencart- Published: Feb. 28, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-1746
Cross-Site Scripting vulnerability in OpenCart versions prior to 4.1.0. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the search in the /product/search endpoint. This v... Read more
Affected Products : opencart- Published: Feb. 28, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-4156
A vulnerability has been found in PHPGurukul Boat Booking System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/change-image.php. The manipulation of the argument ID leads to sql injection. The attack can be ini... Read more
Affected Products : boat_booking_system- Published: May. 01, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-4157
A vulnerability was found in PHPGurukul Boat Booking System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/booking-details.php. The manipulation of the argument Status leads to sql injection. The attack may b... Read more
Affected Products : boat_booking_system- Published: May. 01, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2024-13569
The Front End Users WordPress plugin through 3.2.32 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.... Read more
Affected Products : front_end_users- Published: Apr. 22, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-46225
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Post in page for Elementor allows DOM-Based XSS. This issue affects Post in page for Elementor: from n/a through 1.0.1.... Read more
Affected Products : post_in_page_for_elementor- Published: Apr. 22, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting