Latest CVE Feed
-
9.8
CRITICALCVE-2025-3829
A vulnerability was found in PHPGurukul Men Salon Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/sales-reports-detail.php. The manipulation of the argument fromdate/todate leads to sql injecti... Read more
Affected Products : men_salon_management_system- Published: Apr. 20, 2025
- Modified: Apr. 28, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-28072
PHPGurukul Pre-School Enrollment System is vulnerable to Directory Traversal in manage-teachers.php.... Read more
Affected Products : pre-school_enrollment_system- Published: Apr. 16, 2025
- Modified: Apr. 28, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2024-48357
LyLme Spage 1.2.0 through 1.6.0 is vulnerable to SQL Injection via /admin/apply.php.... Read more
Affected Products : lylme_spage- Published: Oct. 28, 2024
- Modified: Apr. 28, 2025
-
9.8
CRITICALCVE-2024-33868
An issue was discovered in linqi before 1.4.0.1 on Windows. There is LDAP injection.... Read more
- Published: May. 14, 2024
- Modified: Apr. 28, 2025
-
4.8
MEDIUMCVE-2024-33867
An issue was discovered in linqi before 1.4.0.1 on Windows. There is a hardcoded password salt.... Read more
- Published: May. 14, 2024
- Modified: Apr. 28, 2025
-
5.5
MEDIUMCVE-2024-33866
An issue was discovered in linqi before 1.4.0.1 on Windows. There is /api/DocumentTemplate/{GUID] XSS.... Read more
- Published: May. 14, 2024
- Modified: Apr. 28, 2025
-
5.9
MEDIUMCVE-2024-33864
An issue was discovered in linqi before 1.4.0.1 on Windows. There is SSRF via Document template generation; i.e., via remote images in process creation, file inclusion, and PDF document generation via malicious JavaScript.... Read more
- Published: May. 14, 2024
- Modified: Apr. 28, 2025
-
9.8
CRITICALCVE-2024-48180
ClassCMS <=4.8 is vulnerable to file inclusion in the nowView method in/class/cms/cms.php, which can include a file uploaded to the/class/template directory to execute PHP code.... Read more
Affected Products : classcms- Published: Oct. 16, 2024
- Modified: Apr. 28, 2025
-
7.5
HIGHCVE-2024-33865
An issue was discovered in linqi before 1.4.0.1 on Windows. There is an NTLM hash leak via the /api/Cdn/GetFile and /api/DocumentTemplate/{GUID] endpoints.... Read more
- Published: May. 14, 2024
- Modified: Apr. 28, 2025
-
9.8
CRITICALCVE-2024-33863
An issue was discovered in linqi before 1.4.0.1 on Windows. There is /api/Cdn/GetFile local file inclusion.... Read more
- Published: May. 14, 2024
- Modified: Apr. 28, 2025
-
9.8
CRITICALCVE-2022-30355
OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /profile/updateProfile via the userId and email parameters. Authentication is required.... Read more
Affected Products : ovaledge- Published: Oct. 25, 2024
- Modified: Apr. 28, 2025
-
9.8
CRITICALCVE-2024-46101
GDidees CMS <= v3.9.1 has a file upload vulnerability.... Read more
Affected Products : gdidees_cms- Published: Sep. 20, 2024
- Modified: Apr. 28, 2025
-
9.8
CRITICALCVE-2024-47218
An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows bypassing authentication.... Read more
Affected Products : nebulagraph_database- Published: Sep. 22, 2024
- Modified: Apr. 28, 2025
-
9.8
CRITICALCVE-2024-47219
An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows shell command injection.... Read more
- Published: Sep. 22, 2024
- Modified: Apr. 28, 2025
-
8.0
HIGHCVE-2024-46084
Scriptcase 9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_unzip function.... Read more
Affected Products : scriptcase- Published: Oct. 01, 2024
- Modified: Apr. 28, 2025
-
5.4
MEDIUMCVE-2024-46082
Scriptcase v.9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in nm_cor.php via the form and field parameters.... Read more
Affected Products : scriptcase- Published: Oct. 01, 2024
- Modified: Apr. 28, 2025
-
8.0
HIGHCVE-2024-46080
Scriptcase v9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_zip function.... Read more
Affected Products : scriptcase- Published: Oct. 01, 2024
- Modified: Apr. 28, 2025
-
5.4
MEDIUMCVE-2024-46083
Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads using the messages feature, which allows the injection of malicious code into any user's account on the platform. It is importa... Read more
Affected Products : scriptcase- Published: Oct. 01, 2024
- Modified: Apr. 28, 2025
-
6.1
MEDIUMCVE-2024-46079
Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in proj_new.php via the Descricao parameter.... Read more
Affected Products : scriptcase- Published: Oct. 01, 2024
- Modified: Apr. 28, 2025
-
5.4
MEDIUMCVE-2024-46081
Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads in the To-Do List. The assigned user will trigger a stored XSS, which is particularly dangerous because tasks are assigned to v... Read more
Affected Products : scriptcase- Published: Oct. 01, 2024
- Modified: Apr. 28, 2025