Latest CVE Feed
-
9.8
CRITICALCVE-2025-4263
A vulnerability was found in PHPGurukul Online DJ Booking Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/booking-search.php. The manipulation of the argument searchdata leads to sql inje... Read more
Affected Products : online_dj_booking_management_system- Published: May. 05, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
4.3
MEDIUMCVE-2024-24708
Cross-Site Request Forgery (CSRF) vulnerability in W3speedster W3SPEEDSTER.This issue affects W3SPEEDSTER: from n/a through 7.19. ... Read more
Affected Products : w3speedster- Published: Feb. 29, 2024
- Modified: May. 07, 2025
-
4.8
MEDIUMCVE-2025-3504
The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (f... Read more
Affected Products : wp_maps- Published: May. 01, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-3503
The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (f... Read more
Affected Products : wp_maps- Published: May. 01, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
9.1
CRITICALCVE-2024-2557
A vulnerability was found in kishor-23 Food Waste Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/admin.php. The manipulation leads to improper authorization. The attack can be initiated ... Read more
Affected Products : food_waste_management_system- Published: Mar. 17, 2024
- Modified: May. 07, 2025
-
4.8
MEDIUMCVE-2025-3502
The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (f... Read more
Affected Products : wp_maps- Published: May. 01, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2024-3078
A vulnerability was found in Qdrant up to 1.6.1/1.7.4/1.8.2 and classified as critical. This issue affects some unknown processing of the file lib/collection/src/collection/snapshots.rs of the component Full Snapshot REST API. The manipulation leads to pa... Read more
Affected Products : qdrant- Published: Mar. 29, 2024
- Modified: May. 07, 2025
-
7.3
HIGHCVE-2025-28029
TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a buffer overflow vulnerability in cstecgi.cgi... Read more
Affected Products : a830r_firmware a3100r_firmware a950rg_firmware a3000ru_firmware a3100r a3000ru a830r a950rg- Published: Apr. 22, 2025
- Modified: May. 07, 2025
- Vuln Type: Memory Corruption
-
7.3
HIGHCVE-2025-28026
TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a buffer overflow vulnerability in downloadFile.cgi.... Read more
Affected Products : a830r_firmware a3100r_firmware a950rg_firmware a3000ru_firmware a3100r a3000ru a830r a950rg- Published: Apr. 22, 2025
- Modified: May. 07, 2025
- Vuln Type: Memory Corruption
-
7.3
HIGHCVE-2025-28027
TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 was found to contain a buffer overflow vulnerability in downloadFile.cgi.... Read more
Affected Products : a830r_firmware a3100r_firmware a950rg_firmware a3000ru_firmware a3100r a3000ru a830r a950rg- Published: Apr. 22, 2025
- Modified: May. 07, 2025
- Vuln Type: Memory Corruption
-
5.4
MEDIUMCVE-2024-54998
MonicaHQ v4.1.2 was discovered to contain an authenticated Client-Side Injection vulnerability via the Reason parameter at /people/h:[id]/debts/create.... Read more
Affected Products : monica- Published: Jan. 10, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
10.0
CRITICALCVE-2024-25029
IBM Personal Communications 14.0.6 through 15.0.1 includes a Windows service that is vulnerable to remote code execution (RCE) and local privilege escalation (LPE). The vulnerability allows any unprivileged user with network access to a target computer to... Read more
Affected Products : personal_communications- Published: Apr. 06, 2024
- Modified: May. 07, 2025
-
9.9
CRITICALCVE-2025-0471
Unrestricted file upload vulnerability in the PMB platform, affecting versions 4.0.10 and above. This vulnerability could allow an attacker to upload a file to gain remote access to the machine, being able to access, modify and execute commands freely.... Read more
Affected Products : pmb- Published: Jan. 16, 2025
- Modified: May. 07, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-0472
Information exposure in the PMB platform affecting versions 4.2.13 and earlier. This vulnerability allows an attacker to upload a file to the environment and enumerate the internal files of a machine by looking at the request response.... Read more
Affected Products : pmb- Published: Jan. 16, 2025
- Modified: May. 07, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-3248
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.... Read more
Affected Products : langflow- Actively Exploited
- Published: Apr. 07, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-0473
Vulnerability in the PMB platform that allows an attacker to persist temporary files on the server, affecting versions 4.0.10 and above. This vulnerability exists in the file upload functionality on the ‘/pmb/authorities/import/iimport_authorities’ endpoi... Read more
Affected Products : pmb- Published: Jan. 16, 2025
- Modified: May. 07, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-3146
A vulnerability, which was classified as critical, was found in PHPGurukul Bus Pass Management System 1.0. This affects an unknown part of the file /view-pass-detail.php. The manipulation of the argument viewid leads to sql injection. It is possible to in... Read more
- Published: Apr. 03, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3147
A vulnerability has been found in PHPGurukul Boat Booking System 1.0 and classified as critical. This vulnerability affects unknown code of the file /add-subadmin.php. The manipulation of the argument sadminusername leads to sql injection. The attack can ... Read more
Affected Products : boat_booking_system- Published: Apr. 03, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2025-3148
A vulnerability was found in codeprojects Product Management System 1.0 and classified as problematic. This issue affects some unknown processing of the component Login. The manipulation of the argument Str1 leads to buffer overflow. Attacking locally is ... Read more
Affected Products : product_management_system- Published: Apr. 03, 2025
- Modified: May. 07, 2025
- Vuln Type: Memory Corruption
-
5.4
MEDIUMCVE-2024-54997
MonicaHQ v4.1.1 was discovered to contain an authenticated Client-Side Injection vulnerability via the entry text field at /journal/entries/ID/edit.... Read more
Affected Products : monica- Published: Jan. 10, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting