Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.1

    CRITICAL
    CVE-2022-43196

    dedecmdv6 v6.1.9 is vulnerable to Arbitrary file deletion via file_manage_control.php.... Read more

    Affected Products : dedecmsv6
    • EPSS Score: %0.10
    • Published: Nov. 23, 2022
    • Modified: Apr. 28, 2025
  • 4.8

    MEDIUM
    CVE-2022-42095

    Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page content.... Read more

    Affected Products : backdrop backdrop_cms
    • EPSS Score: %43.36
    • Published: Nov. 23, 2022
    • Modified: Apr. 28, 2025
  • 8.8

    HIGH
    CVE-2022-3849

    The WP User Merger WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as admin... Read more

    Affected Products : wp_user_merger
    • EPSS Score: %0.29
    • Published: Nov. 28, 2022
    • Modified: Apr. 28, 2025
  • 7.2

    HIGH
    CVE-2024-46331

    ModStartCMS v8.8.0 was discovered to contain an open redirect vulnerability in the redirect parameter at /admin/login. This vulnerability allows attackers to redirect users to an arbitrary website via a crafted URL.... Read more

    Affected Products : mostartcms
    • Published: Sep. 27, 2024
    • Modified: Apr. 28, 2025
  • 9.8

    CRITICAL
    CVE-2024-46293

    Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Incorrect Access Control. There is a lack of authorization checks for admin operations. Specifically, an attacker can perform admin-level actions without possessing a valid session token.... Read more

    • Published: Sep. 30, 2024
    • Modified: Apr. 28, 2025
  • 6.5

    MEDIUM
    CVE-2024-45870

    Bandisoft BandiView 7.05 is vulnerable to Incorrect Access Control in sub_0x3d80fc via a crafted POC file.... Read more

    Affected Products : bandiview
    • Published: Oct. 03, 2024
    • Modified: Apr. 28, 2025
  • 6.3

    MEDIUM
    CVE-2024-45871

    Bandisoft BandiView 7.05 is Incorrect Access Control via sub_0x232bd8 resulting in denial of service (DOS).... Read more

    Affected Products : bandiview
    • Published: Oct. 03, 2024
    • Modified: Apr. 28, 2025
  • 6.3

    MEDIUM
    CVE-2024-45872

    Bandisoft BandiView 7.05 is vulnerable to Buffer Overflow via sub_0x410d1d. The vulnerability occurs due to insufficient validation of PSD files.... Read more

    Affected Products : bandiview
    • Published: Oct. 03, 2024
    • Modified: Apr. 28, 2025
  • 5.4

    MEDIUM
    CVE-2024-46077

    itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the val-username, val-email, val-suggestions, val-digits and state_name parameters in travellers.php.... Read more

    • Published: Oct. 04, 2024
    • Modified: Apr. 28, 2025
  • 4.8

    MEDIUM
    CVE-2024-46654

    A stored cross-site scripting (XSS) vulnerability in the Add Scheduled Task module of Maccms10 v2024.1000.4040 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more

    Affected Products : maccms
    • Published: Sep. 20, 2024
    • Modified: Apr. 28, 2025
  • 9.8

    CRITICAL
    CVE-2024-48579

    SQL Injection vulnerability in Best House rental management system project in php v.1.0 allows a remote attacker to execute arbitrary code via the username parameter of the login request.... Read more

    • Published: Oct. 25, 2024
    • Modified: Apr. 28, 2025
  • 9.8

    CRITICAL
    CVE-2025-3827

    A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/forgot-password.php. The manipulation of the argument email leads to sql injection. The att... Read more

    Affected Products : men_salon_management_system
    • Published: Apr. 20, 2025
    • Modified: Apr. 28, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-3828

    A vulnerability was found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/view-appointment.php?viewid=11. The manipulation of the argument remark leads to sql injectio... Read more

    Affected Products : men_salon_management_system
    • Published: Apr. 20, 2025
    • Modified: Apr. 28, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-3829

    A vulnerability was found in PHPGurukul Men Salon Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/sales-reports-detail.php. The manipulation of the argument fromdate/todate leads to sql injecti... Read more

    Affected Products : men_salon_management_system
    • Published: Apr. 20, 2025
    • Modified: Apr. 28, 2025
    • Vuln Type: Injection
  • 7.5

    HIGH
    CVE-2025-28072

    PHPGurukul Pre-School Enrollment System is vulnerable to Directory Traversal in manage-teachers.php.... Read more

    Affected Products : pre-school_enrollment_system
    • Published: Apr. 16, 2025
    • Modified: Apr. 28, 2025
    • Vuln Type: Path Traversal
  • 9.8

    CRITICAL
    CVE-2024-48357

    LyLme Spage 1.2.0 through 1.6.0 is vulnerable to SQL Injection via /admin/apply.php.... Read more

    Affected Products : lylme_spage
    • Published: Oct. 28, 2024
    • Modified: Apr. 28, 2025
  • 9.8

    CRITICAL
    CVE-2024-33868

    An issue was discovered in linqi before 1.4.0.1 on Windows. There is LDAP injection.... Read more

    Affected Products : windows linqi
    • Published: May. 14, 2024
    • Modified: Apr. 28, 2025
  • 4.8

    MEDIUM
    CVE-2024-33867

    An issue was discovered in linqi before 1.4.0.1 on Windows. There is a hardcoded password salt.... Read more

    Affected Products : windows linqi
    • Published: May. 14, 2024
    • Modified: Apr. 28, 2025
  • 5.5

    MEDIUM
    CVE-2024-33866

    An issue was discovered in linqi before 1.4.0.1 on Windows. There is /api/DocumentTemplate/{GUID] XSS.... Read more

    Affected Products : windows linqi
    • Published: May. 14, 2024
    • Modified: Apr. 28, 2025
  • 5.9

    MEDIUM
    CVE-2024-33864

    An issue was discovered in linqi before 1.4.0.1 on Windows. There is SSRF via Document template generation; i.e., via remote images in process creation, file inclusion, and PDF document generation via malicious JavaScript.... Read more

    Affected Products : windows linqi
    • Published: May. 14, 2024
    • Modified: Apr. 28, 2025
Showing 20 of 291736 Results