Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 4.8

    MEDIUM
    CVE-2021-25918

    In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly and rendered in the TOTP Authentication method page. A highly privileged attacker could inject arbitrary code into input... Read more

    Affected Products : openemr
    • EPSS Score: %2.80
    • Published: Mar. 22, 2021
    • Modified: Apr. 30, 2025
  • 4.8

    MEDIUM
    CVE-2021-25917

    In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly and rendered in the U2F USB Device authentication method page. A highly privileged attacker could inject arbitrary code ... Read more

    Affected Products : openemr
    • EPSS Score: %2.80
    • Published: Mar. 22, 2021
    • Modified: Apr. 30, 2025
  • 9.8

    CRITICAL
    CVE-2021-25916

    Prototype pollution vulnerability in 'patchmerge' versions 1.0.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.... Read more

    Affected Products : patchmerge
    • EPSS Score: %2.95
    • Published: Mar. 16, 2021
    • Modified: Apr. 30, 2025
  • 9.8

    CRITICAL
    CVE-2021-25915

    Prototype pollution vulnerability in 'changeset' versions 0.0.1 through 0.2.5 allows an attacker to cause a denial of service and may lead to remote code execution.... Read more

    Affected Products : changeset
    • EPSS Score: %2.95
    • Published: Mar. 09, 2021
    • Modified: Apr. 30, 2025
  • 9.8

    CRITICAL
    CVE-2021-25914

    Prototype pollution vulnerability in 'object-collider' versions 1.0.0 through 1.0.3 allows attacker to cause a denial of service and may lead to remote code execution.... Read more

    Affected Products : object-collider
    • EPSS Score: %3.23
    • Published: Mar. 01, 2021
    • Modified: Apr. 30, 2025
  • 9.8

    CRITICAL
    CVE-2025-4027

    A vulnerability, which was classified as critical, was found in PHPGurukul Old Age Home Management System 1.0. Affected is an unknown function of the file /admin/rules.php. The manipulation of the argument pagetitle leads to sql injection. It is possible ... Read more

    Affected Products : old_age_home_management_system
    • Published: Apr. 28, 2025
    • Modified: Apr. 30, 2025
  • 9.8

    CRITICAL
    CVE-2025-45949

    A critical vulnerability was found in PHPGurukul User Registration & Login and User Management System V3.3 in the /loginsystem/change-password.php file of the user panel - Change Password component. Improper handling of session data allows a Session Hijac... Read more

    • Published: Apr. 28, 2025
    • Modified: Apr. 30, 2025
  • 9.1

    CRITICAL
    CVE-2025-45953

    A vulnerability was found in PHPGurukul Hostel Management System 2.1 in the /hostel/change-password.php file of the user panel - Change Password component. Improper handling of session data allows a Session Hijacking attack, exploitable remotely... Read more

    Affected Products : hostel_management_system
    • Published: Apr. 28, 2025
    • Modified: Apr. 30, 2025
  • 5.5

    MEDIUM
    CVE-2025-4037

    A vulnerability was found in code-projects ATM Banking 1.0. It has been classified as critical. Affected is the function moneyDeposit/moneyWithdraw. The manipulation leads to business logic errors. Local access is required to approach this attack. The exp... Read more

    Affected Products : atm_banking
    • Published: Apr. 28, 2025
    • Modified: Apr. 30, 2025
  • 4.8

    MEDIUM
    CVE-2025-3823

    A vulnerability classified as problematic has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected is an unknown function of the file add-stock.php. The manipulation of the argument txttotalcost/txtproductID/txtprice/txt... Read more

    • Published: Apr. 20, 2025
    • Modified: Apr. 30, 2025
  • 8.8

    HIGH
    CVE-2024-13146

    The Booknetic WordPress plugin before 4.1.5 does not have CSRF check when creating Staff accounts, which could allow attackers to make logged in admin add arbitrary Staff members via a CSRF attack... Read more

    Affected Products : booknetic
    • Published: Mar. 26, 2025
    • Modified: Apr. 30, 2025
  • 4.8

    MEDIUM
    CVE-2025-3824

    A vulnerability classified as problematic was found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected by this vulnerability is an unknown functionality of the file add-product.php. The manipulation of the argument txtprice/txtpr... Read more

    • Published: Apr. 20, 2025
    • Modified: Apr. 30, 2025
  • 4.8

    MEDIUM
    CVE-2025-3825

    A vulnerability, which was classified as problematic, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected by this issue is some unknown functionality of the file add-category.php. The manipulation of the argument tx... Read more

    • Published: Apr. 20, 2025
    • Modified: Apr. 30, 2025
  • 4.8

    MEDIUM
    CVE-2025-3826

    A vulnerability, which was classified as problematic, was found in SourceCodester Web-based Pharmacy Product Management System 1.0. This affects an unknown part of the file add-supplier.php. The manipulation of the argument txtsupplier_name/txtaddress lea... Read more

    • Published: Apr. 20, 2025
    • Modified: Apr. 30, 2025
  • 7.1

    HIGH
    CVE-2024-52459

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chameleoni.Com Chameleoni Jobs chameleon-jobs allows Reflected XSS.This issue affects Chameleoni Jobs: from n/a through 2.5.4.... Read more

    Affected Products :
    • Published: Dec. 02, 2024
    • Modified: Apr. 30, 2025
  • 9.8

    CRITICAL
    CVE-2022-45395

    Jenkins CCCC Plugin 0.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.... Read more

    Affected Products : cccc
    • EPSS Score: %0.29
    • Published: Nov. 15, 2022
    • Modified: Apr. 30, 2025
  • 4.3

    MEDIUM
    CVE-2022-45394

    A missing permission check in Jenkins Delete log Plugin 1.0 and earlier allows attackers with Item/Read permission to delete build logs.... Read more

    Affected Products : delete_log
    • EPSS Score: %0.06
    • Published: Nov. 15, 2022
    • Modified: Apr. 30, 2025
  • 3.5

    LOW
    CVE-2022-45393

    A cross-site request forgery (CSRF) vulnerability in Jenkins Delete log Plugin 1.0 and earlier allows attackers to delete build logs.... Read more

    Affected Products : delete_log
    • EPSS Score: %0.06
    • Published: Nov. 15, 2022
    • Modified: Apr. 30, 2025
  • 6.5

    MEDIUM
    CVE-2022-45392

    Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by attackers with Extended Read permission, or access to the Jenkins contr... Read more

    • EPSS Score: %0.08
    • Published: Nov. 15, 2022
    • Modified: Apr. 30, 2025
  • 4.6

    MEDIUM
    CVE-2022-30769

    Session fixation exists in ZoneMinder through 1.36.12 as an attacker can poison a session cookie to the next logged-in user.... Read more

    Affected Products : zoneminder
    • EPSS Score: %0.11
    • Published: Nov. 15, 2022
    • Modified: Apr. 30, 2025
Showing 20 of 291058 Results