Latest CVE Feed
-
4.8
MEDIUMCVE-2025-3825
A vulnerability, which was classified as problematic, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected by this issue is some unknown functionality of the file add-category.php. The manipulation of the argument tx... Read more
- Published: Apr. 20, 2025
- Modified: Apr. 30, 2025
-
4.8
MEDIUMCVE-2025-3826
A vulnerability, which was classified as problematic, was found in SourceCodester Web-based Pharmacy Product Management System 1.0. This affects an unknown part of the file add-supplier.php. The manipulation of the argument txtsupplier_name/txtaddress lea... Read more
- Published: Apr. 20, 2025
- Modified: Apr. 30, 2025
-
7.1
HIGHCVE-2024-52459
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chameleoni.Com Chameleoni Jobs chameleon-jobs allows Reflected XSS.This issue affects Chameleoni Jobs: from n/a through 2.5.4.... Read more
Affected Products :- Published: Dec. 02, 2024
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2022-45395
Jenkins CCCC Plugin 0.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.... Read more
Affected Products : cccc- EPSS Score: %0.29
- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025
-
4.3
MEDIUMCVE-2022-45394
A missing permission check in Jenkins Delete log Plugin 1.0 and earlier allows attackers with Item/Read permission to delete build logs.... Read more
Affected Products : delete_log- EPSS Score: %0.06
- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025
-
3.5
LOWCVE-2022-45393
A cross-site request forgery (CSRF) vulnerability in Jenkins Delete log Plugin 1.0 and earlier allows attackers to delete build logs.... Read more
Affected Products : delete_log- EPSS Score: %0.06
- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025
-
6.5
MEDIUMCVE-2022-45392
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by attackers with Extended Read permission, or access to the Jenkins contr... Read more
Affected Products : ns-nd_integration_performance_publisher- EPSS Score: %0.08
- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025
-
4.6
MEDIUMCVE-2022-30769
Session fixation exists in ZoneMinder through 1.36.12 as an attacker can poison a session cookie to the next logged-in user.... Read more
Affected Products : zoneminder- EPSS Score: %0.11
- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025
-
5.4
MEDIUMCVE-2022-30768
A Stored Cross Site Scripting (XSS) issue in ZoneMinder 1.36.12 allows an attacker to execute HTML or JavaScript code via the Username field when an Admin (or non-Admin users that can see other users logged into the platform) clicks on Logout. NOTE: this ... Read more
Affected Products : zoneminder- EPSS Score: %0.24
- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2025-3830
A vulnerability was found in kuangstudy KuangSimpleBBS 1.0. It has been declared as critical. Affected by this vulnerability is the function fileUpload of the file src/main/java/com/kuang/controller/QuestionController.java. The manipulation of the argumen... Read more
Affected Products : kuangsimplebbs- Published: Apr. 20, 2025
- Modified: Apr. 30, 2025
-
8.2
HIGHCVE-2024-26566
An issue in Cute Http File Server v.3.1 allows a remote attacker to escalate privileges via the password verification component.... Read more
Affected Products : cute_http_file_server- Published: Mar. 07, 2024
- Modified: Apr. 30, 2025
-
7.5
HIGHCVE-2024-24375
SQL injection vulnerability in Jfinalcms v.5.0.0 allows a remote attacker to obtain sensitive information via /admin/admin name parameter.... Read more
Affected Products : jfinalcms- Published: Mar. 07, 2024
- Modified: Apr. 30, 2025
-
7.5
HIGHCVE-2024-25164
iA Path Traversal vulnerability exists in iDURAR v2.0.0, that allows unauthenticated attackers to expose sensitive files via the download functionality.... Read more
- Published: Mar. 05, 2024
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2024-27516
Server-Side Template Injection (SSTI) vulnerability in livehelperchat before 4.34v, allows remote attackers to execute arbitrary code and obtain sensitive information via the search parameter in lhc_web/modules/lhfaq/faqweight.php.... Read more
- Published: Feb. 29, 2024
- Modified: Apr. 30, 2025
-
6.1
MEDIUMCVE-2024-26473
A reflected cross-site scripting (XSS) vulnerability in SocialMediaWebsite v1.0.1 allows attackers to inject malicious JavaScript into the web browser of a victim via the poll parameter in poll.php.... Read more
Affected Products : klik_socialmediawebsite- Published: Feb. 29, 2024
- Modified: Apr. 30, 2025
-
6.1
MEDIUMCVE-2024-26472
KLiK SocialMediaWebsite version 1.0.1 from msaad1999 has a reflected cross-site scripting (XSS) vulnerability which may allow remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'selecto... Read more
Affected Products : klik_socialmediawebsite- Published: Feb. 29, 2024
- Modified: Apr. 30, 2025
-
5.4
MEDIUMCVE-2024-26471
A reflected cross-site scripting (XSS) vulnerability in zhimengzhe iBarn v1.5 allows attackers to inject malicious JavaScript into the web browser of a victim via the search parameter in offer.php.... Read more
- Published: Feb. 29, 2024
- Modified: Apr. 30, 2025
-
8.1
HIGHCVE-2024-26470
A host header injection vulnerability in the forgot password function of FullStackHero's WebAPI Boilerplate v1.0.0 and v1.0.1 allows attackers to leak the password reset token via a crafted request.... Read more
Affected Products : .net_9_starter_kit- Published: Feb. 29, 2024
- Modified: Apr. 30, 2025
-
9.1
CRITICALCVE-2024-25846
In the module "Product Catalog (CSV, Excel) Import" (simpleimportproduct) <= 6.7.0 from MyPrestaModules for PrestaShop, a guest can upload files with extensions .php.... Read more
Affected Products : simpleimportproduct- Published: Feb. 27, 2024
- Modified: Apr. 30, 2025
-
6.8
MEDIUMCVE-2024-42768
A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Hotel Management System v1.0 via /admin/delete_room.php.... Read more
- Published: Aug. 22, 2024
- Modified: Apr. 30, 2025