Latest CVE Feed
-
4.8
MEDIUMCVE-2021-25918
In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly and rendered in the TOTP Authentication method page. A highly privileged attacker could inject arbitrary code into input... Read more
Affected Products : openemr- EPSS Score: %2.80
- Published: Mar. 22, 2021
- Modified: Apr. 30, 2025
-
4.8
MEDIUMCVE-2021-25917
In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly and rendered in the U2F USB Device authentication method page. A highly privileged attacker could inject arbitrary code ... Read more
Affected Products : openemr- EPSS Score: %2.80
- Published: Mar. 22, 2021
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2021-25916
Prototype pollution vulnerability in 'patchmerge' versions 1.0.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.... Read more
Affected Products : patchmerge- EPSS Score: %2.95
- Published: Mar. 16, 2021
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2021-25915
Prototype pollution vulnerability in 'changeset' versions 0.0.1 through 0.2.5 allows an attacker to cause a denial of service and may lead to remote code execution.... Read more
Affected Products : changeset- EPSS Score: %2.95
- Published: Mar. 09, 2021
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2021-25914
Prototype pollution vulnerability in 'object-collider' versions 1.0.0 through 1.0.3 allows attacker to cause a denial of service and may lead to remote code execution.... Read more
Affected Products : object-collider- EPSS Score: %3.23
- Published: Mar. 01, 2021
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2025-4027
A vulnerability, which was classified as critical, was found in PHPGurukul Old Age Home Management System 1.0. Affected is an unknown function of the file /admin/rules.php. The manipulation of the argument pagetitle leads to sql injection. It is possible ... Read more
Affected Products : old_age_home_management_system- Published: Apr. 28, 2025
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2025-45949
A critical vulnerability was found in PHPGurukul User Registration & Login and User Management System V3.3 in the /loginsystem/change-password.php file of the user panel - Change Password component. Improper handling of session data allows a Session Hijac... Read more
Affected Products : user_registration_\&_login_and_user_management_system- Published: Apr. 28, 2025
- Modified: Apr. 30, 2025
-
9.1
CRITICALCVE-2025-45953
A vulnerability was found in PHPGurukul Hostel Management System 2.1 in the /hostel/change-password.php file of the user panel - Change Password component. Improper handling of session data allows a Session Hijacking attack, exploitable remotely... Read more
Affected Products : hostel_management_system- Published: Apr. 28, 2025
- Modified: Apr. 30, 2025
-
5.5
MEDIUMCVE-2025-4037
A vulnerability was found in code-projects ATM Banking 1.0. It has been classified as critical. Affected is the function moneyDeposit/moneyWithdraw. The manipulation leads to business logic errors. Local access is required to approach this attack. The exp... Read more
Affected Products : atm_banking- Published: Apr. 28, 2025
- Modified: Apr. 30, 2025
-
4.8
MEDIUMCVE-2025-3823
A vulnerability classified as problematic has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected is an unknown function of the file add-stock.php. The manipulation of the argument txttotalcost/txtproductID/txtprice/txt... Read more
- Published: Apr. 20, 2025
- Modified: Apr. 30, 2025
-
8.8
HIGHCVE-2024-13146
The Booknetic WordPress plugin before 4.1.5 does not have CSRF check when creating Staff accounts, which could allow attackers to make logged in admin add arbitrary Staff members via a CSRF attack... Read more
Affected Products : booknetic- Published: Mar. 26, 2025
- Modified: Apr. 30, 2025
-
4.8
MEDIUMCVE-2025-3824
A vulnerability classified as problematic was found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected by this vulnerability is an unknown functionality of the file add-product.php. The manipulation of the argument txtprice/txtpr... Read more
- Published: Apr. 20, 2025
- Modified: Apr. 30, 2025
-
4.8
MEDIUMCVE-2025-3825
A vulnerability, which was classified as problematic, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected by this issue is some unknown functionality of the file add-category.php. The manipulation of the argument tx... Read more
- Published: Apr. 20, 2025
- Modified: Apr. 30, 2025
-
4.8
MEDIUMCVE-2025-3826
A vulnerability, which was classified as problematic, was found in SourceCodester Web-based Pharmacy Product Management System 1.0. This affects an unknown part of the file add-supplier.php. The manipulation of the argument txtsupplier_name/txtaddress lea... Read more
- Published: Apr. 20, 2025
- Modified: Apr. 30, 2025
-
7.1
HIGHCVE-2024-52459
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chameleoni.Com Chameleoni Jobs chameleon-jobs allows Reflected XSS.This issue affects Chameleoni Jobs: from n/a through 2.5.4.... Read more
Affected Products :- Published: Dec. 02, 2024
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2022-45395
Jenkins CCCC Plugin 0.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.... Read more
Affected Products : cccc- EPSS Score: %0.29
- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025
-
4.3
MEDIUMCVE-2022-45394
A missing permission check in Jenkins Delete log Plugin 1.0 and earlier allows attackers with Item/Read permission to delete build logs.... Read more
Affected Products : delete_log- EPSS Score: %0.06
- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025
-
3.5
LOWCVE-2022-45393
A cross-site request forgery (CSRF) vulnerability in Jenkins Delete log Plugin 1.0 and earlier allows attackers to delete build logs.... Read more
Affected Products : delete_log- EPSS Score: %0.06
- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025
-
6.5
MEDIUMCVE-2022-45392
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by attackers with Extended Read permission, or access to the Jenkins contr... Read more
Affected Products : ns-nd_integration_performance_publisher- EPSS Score: %0.08
- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025
-
4.6
MEDIUMCVE-2022-30769
Session fixation exists in ZoneMinder through 1.36.12 as an attacker can poison a session cookie to the next logged-in user.... Read more
Affected Products : zoneminder- EPSS Score: %0.11
- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025