Latest CVE Feed
-
9.1
CRITICALCVE-2022-43196
dedecmdv6 v6.1.9 is vulnerable to Arbitrary file deletion via file_manage_control.php.... Read more
Affected Products : dedecmsv6- EPSS Score: %0.10
- Published: Nov. 23, 2022
- Modified: Apr. 28, 2025
-
4.8
MEDIUMCVE-2022-42095
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page content.... Read more
- EPSS Score: %43.36
- Published: Nov. 23, 2022
- Modified: Apr. 28, 2025
-
8.8
HIGHCVE-2022-3849
The WP User Merger WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as admin... Read more
Affected Products : wp_user_merger- EPSS Score: %0.29
- Published: Nov. 28, 2022
- Modified: Apr. 28, 2025
-
7.2
HIGHCVE-2024-46331
ModStartCMS v8.8.0 was discovered to contain an open redirect vulnerability in the redirect parameter at /admin/login. This vulnerability allows attackers to redirect users to an arbitrary website via a crafted URL.... Read more
Affected Products : mostartcms- Published: Sep. 27, 2024
- Modified: Apr. 28, 2025
-
9.8
CRITICALCVE-2024-46293
Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Incorrect Access Control. There is a lack of authorization checks for admin operations. Specifically, an attacker can perform admin-level actions without possessing a valid session token.... Read more
- Published: Sep. 30, 2024
- Modified: Apr. 28, 2025
-
6.5
MEDIUMCVE-2024-45870
Bandisoft BandiView 7.05 is vulnerable to Incorrect Access Control in sub_0x3d80fc via a crafted POC file.... Read more
Affected Products : bandiview- Published: Oct. 03, 2024
- Modified: Apr. 28, 2025
-
6.3
MEDIUMCVE-2024-45871
Bandisoft BandiView 7.05 is Incorrect Access Control via sub_0x232bd8 resulting in denial of service (DOS).... Read more
Affected Products : bandiview- Published: Oct. 03, 2024
- Modified: Apr. 28, 2025
-
6.3
MEDIUMCVE-2024-45872
Bandisoft BandiView 7.05 is vulnerable to Buffer Overflow via sub_0x410d1d. The vulnerability occurs due to insufficient validation of PSD files.... Read more
Affected Products : bandiview- Published: Oct. 03, 2024
- Modified: Apr. 28, 2025
-
5.4
MEDIUMCVE-2024-46077
itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the val-username, val-email, val-suggestions, val-digits and state_name parameters in travellers.php.... Read more
Affected Products : online_tours_and_travels_management_system online_tours_and_travels_management_system- Published: Oct. 04, 2024
- Modified: Apr. 28, 2025
-
4.8
MEDIUMCVE-2024-46654
A stored cross-site scripting (XSS) vulnerability in the Add Scheduled Task module of Maccms10 v2024.1000.4040 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products : maccms- Published: Sep. 20, 2024
- Modified: Apr. 28, 2025
-
9.8
CRITICALCVE-2024-48579
SQL Injection vulnerability in Best House rental management system project in php v.1.0 allows a remote attacker to execute arbitrary code via the username parameter of the login request.... Read more
Affected Products : best_house_rental_management_system- Published: Oct. 25, 2024
- Modified: Apr. 28, 2025
-
9.8
CRITICALCVE-2025-3827
A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/forgot-password.php. The manipulation of the argument email leads to sql injection. The att... Read more
Affected Products : men_salon_management_system- Published: Apr. 20, 2025
- Modified: Apr. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3828
A vulnerability was found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/view-appointment.php?viewid=11. The manipulation of the argument remark leads to sql injectio... Read more
Affected Products : men_salon_management_system- Published: Apr. 20, 2025
- Modified: Apr. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3829
A vulnerability was found in PHPGurukul Men Salon Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/sales-reports-detail.php. The manipulation of the argument fromdate/todate leads to sql injecti... Read more
Affected Products : men_salon_management_system- Published: Apr. 20, 2025
- Modified: Apr. 28, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-28072
PHPGurukul Pre-School Enrollment System is vulnerable to Directory Traversal in manage-teachers.php.... Read more
Affected Products : pre-school_enrollment_system- Published: Apr. 16, 2025
- Modified: Apr. 28, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2024-48357
LyLme Spage 1.2.0 through 1.6.0 is vulnerable to SQL Injection via /admin/apply.php.... Read more
Affected Products : lylme_spage- Published: Oct. 28, 2024
- Modified: Apr. 28, 2025
-
9.8
CRITICALCVE-2024-33868
An issue was discovered in linqi before 1.4.0.1 on Windows. There is LDAP injection.... Read more
- Published: May. 14, 2024
- Modified: Apr. 28, 2025
-
4.8
MEDIUMCVE-2024-33867
An issue was discovered in linqi before 1.4.0.1 on Windows. There is a hardcoded password salt.... Read more
- Published: May. 14, 2024
- Modified: Apr. 28, 2025
-
5.5
MEDIUMCVE-2024-33866
An issue was discovered in linqi before 1.4.0.1 on Windows. There is /api/DocumentTemplate/{GUID] XSS.... Read more
- Published: May. 14, 2024
- Modified: Apr. 28, 2025
-
5.9
MEDIUMCVE-2024-33864
An issue was discovered in linqi before 1.4.0.1 on Windows. There is SSRF via Document template generation; i.e., via remote images in process creation, file inclusion, and PDF document generation via malicious JavaScript.... Read more
- Published: May. 14, 2024
- Modified: Apr. 28, 2025