Latest CVE Feed
-
6.7
MEDIUMCVE-2022-37930
A security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays and HPE Nimble Storage Secondary Flash Arrays which could potentially allow local disclosure of sensitive information. ... Read more
Affected Products : sf100_firmware sf300_firmware hf60c_firmware hf40c_firmware hf20_firmware hf40_firmware hf60_firmware hf20h_firmware hf20c_firmware sf100 +8 more products- EPSS Score: %0.05
- Published: Dec. 12, 2022
- Modified: May. 02, 2025
-
6.7
MEDIUMCVE-2022-37929
Improper Privilege Management vulnerability in Hewlett Packard Enterprise Nimble Storage Hybrid Flash Arrays and Nimble Storage Secondary Flash Arrays. ... Read more
Affected Products : sf100_firmware sf300_firmware hf60c_firmware hf40c_firmware hf20_firmware hf40_firmware hf60_firmware hf20h_firmware hf20c_firmware sf100 +8 more products- EPSS Score: %0.07
- Published: Dec. 12, 2022
- Modified: May. 02, 2025
-
8.0
HIGHCVE-2022-37928
Insufficient Verification of Data Authenticity vulnerability in Hewlett Packard Enterprise HPE Nimble Storage Hybrid Flash Arrays and Nimble Storage Secondary Flash Arrays. ... Read more
Affected Products : sf100_firmware sf300_firmware hf60c_firmware hf40c_firmware hf20_firmware hf40_firmware hf60_firmware hf20h_firmware hf20c_firmware sf100 +8 more products- EPSS Score: %0.19
- Published: Dec. 12, 2022
- Modified: May. 02, 2025
-
6.4
MEDIUMCVE-2021-46846
Cross Site Scripting vulnerability in Hewlett Packard Enterprise Integrated Lights-Out 5. ... Read more
Affected Products : integrated_lights-out_5_firmware 3par_service_processor apollo_4200_gen10_server proliant_bl460c_gen10_server_blade proliant_dl580_gen10_server proliant_dl560_gen10_server proliant_dl380_gen10_server proliant_dl360_gen10_server proliant_dl180_gen10_server proliant_dl160_gen10_server +35 more products- EPSS Score: %0.14
- Published: Dec. 12, 2022
- Modified: May. 02, 2025
-
9.8
CRITICALCVE-2020-36084
SQL Injection vulnerability in SourceCodester Responsive E-Learning System 1.0 allows remote attackers to inject sql query in /elearning/delete_teacher_students.php?id= parameter via id field.... Read more
Affected Products : responsive_e-learning_system- Published: Feb. 05, 2025
- Modified: May. 02, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-22928
OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the cp_id parameter at /modules/messages/Inbox.php.... Read more
Affected Products : opensis- Published: Apr. 03, 2025
- Modified: May. 02, 2025
- Vuln Type: Injection
-
9.1
CRITICALCVE-2024-55496
A vulnerability has been found in the 1000projects Bookstore Management System PHP MySQL Project 1.0. This issue affects some unknown functionality of add_company.php. Actions on the delete parameter result in SQL injection.... Read more
Affected Products : bookstore_management_system- Published: Dec. 17, 2024
- Modified: May. 02, 2025
-
9.8
CRITICALCVE-2024-48580
SQL Injection vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the email parameter of the login request.... Read more
Affected Products : best_courier_management_system- Published: Oct. 25, 2024
- Modified: May. 02, 2025
-
7.3
HIGHCVE-2024-48259
Cloudlog 2.6.15 allows Oqrs.php request_form SQL injection via station_id or callsign.... Read more
Affected Products : cloudlog- Published: Oct. 14, 2024
- Modified: May. 02, 2025
-
5.3
MEDIUMCVE-2024-24407
SQL Injection vulnerability in Best Courier management system v.1.0 allows a remote attacker to obtain sensitive information via print_pdets.php component.... Read more
- Published: Mar. 28, 2024
- Modified: May. 02, 2025
-
8.1
HIGHCVE-2024-22983
SQL injection vulnerability in Projectworlds Visitor Management System in PHP v.1.0 allows a remote attacker to escalate privileges via the name parameter in the myform.php endpoint.... Read more
- Published: Feb. 28, 2024
- Modified: May. 02, 2025
-
5.1
MEDIUMCVE-2025-25992
SQL Injection vulnerability in FeMiner wms 1.0 allows a remote attacker to obtain sensitive information via the inquire_inout_item.php component.... Read more
Affected Products : feminer_wms- Published: Feb. 14, 2025
- Modified: May. 02, 2025
- Vuln Type: Injection
-
5.1
MEDIUMCVE-2025-25993
SQL Injection vulnerability in FeMiner wms wms 1.0 allows a remote attacker to obtain sensitive information via the parameter "itemid."... Read more
Affected Products : feminer_wms- Published: Feb. 14, 2025
- Modified: May. 02, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-25994
SQL Injection vulnerability in FeMiner wms wms 1.0 allows a remote attacker to obtain sensitive information via the parameters date1, date2, id.... Read more
Affected Products : feminer_wms- Published: Feb. 14, 2025
- Modified: May. 02, 2025
- Vuln Type: Injection
-
9.1
CRITICALCVE-2025-32754
In jenkins/ssh-agent Docker images 6.11.1 and earlier, SSH host keys are generated on image creation for images based on Debian, causing all containers based on images of the same version use the same SSH host keys, allowing attackers able to insert thems... Read more
Affected Products : ssh-agent- Published: Apr. 10, 2025
- Modified: May. 02, 2025
- Vuln Type: Misconfiguration
-
6.1
MEDIUMCVE-2024-27684
A Cross-site scripting (XSS) vulnerability in dlapn.cgi, dldongle.cgi, dlcfg.cgi, fwup.cgi and seama.cgi in D-Link GORTAC750_A1_FW_v101b03 allows remote attackers to inject arbitrary web script or HTML via the url parameter.... Read more
- Published: Mar. 04, 2024
- Modified: May. 02, 2025
-
9.8
CRITICALCVE-2024-57684
An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the DMZ service of the device via a crafted POST request.... Read more
- Published: Jan. 16, 2025
- Modified: May. 02, 2025
- Vuln Type: Authentication
-
4.3
MEDIUMCVE-2024-57683
An access control issue in the component websURLFilterAddDel of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the filter settings of the device via a crafted POST request.... Read more
- Published: Jan. 16, 2025
- Modified: May. 02, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2024-57682
An information disclosure vulnerability in the component d_status.asp of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to access sensitive information via a crafted POST request.... Read more
- Published: Jan. 16, 2025
- Modified: May. 02, 2025
- Vuln Type: Information Disclosure
-
5.3
MEDIUMCVE-2024-57681
An access control issue in the component form2alg.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the agl service of the device via a crafted POST request.... Read more
- Published: Jan. 16, 2025
- Modified: May. 02, 2025
- Vuln Type: Authentication