Latest CVE Feed
-
9.8
CRITICALCVE-2024-48579
SQL Injection vulnerability in Best House rental management system project in php v.1.0 allows a remote attacker to execute arbitrary code via the username parameter of the login request.... Read more
Affected Products : best_house_rental_management_system- Published: Oct. 25, 2024
- Modified: Apr. 28, 2025
-
9.8
CRITICALCVE-2025-3827
A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/forgot-password.php. The manipulation of the argument email leads to sql injection. The att... Read more
Affected Products : men_salon_management_system- Published: Apr. 20, 2025
- Modified: Apr. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3828
A vulnerability was found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/view-appointment.php?viewid=11. The manipulation of the argument remark leads to sql injectio... Read more
Affected Products : men_salon_management_system- Published: Apr. 20, 2025
- Modified: Apr. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3829
A vulnerability was found in PHPGurukul Men Salon Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/sales-reports-detail.php. The manipulation of the argument fromdate/todate leads to sql injecti... Read more
Affected Products : men_salon_management_system- Published: Apr. 20, 2025
- Modified: Apr. 28, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-28072
PHPGurukul Pre-School Enrollment System is vulnerable to Directory Traversal in manage-teachers.php.... Read more
Affected Products : pre-school_enrollment_system- Published: Apr. 16, 2025
- Modified: Apr. 28, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2024-48357
LyLme Spage 1.2.0 through 1.6.0 is vulnerable to SQL Injection via /admin/apply.php.... Read more
Affected Products : lylme_spage- Published: Oct. 28, 2024
- Modified: Apr. 28, 2025
-
9.8
CRITICALCVE-2024-33868
An issue was discovered in linqi before 1.4.0.1 on Windows. There is LDAP injection.... Read more
- Published: May. 14, 2024
- Modified: Apr. 28, 2025
-
4.8
MEDIUMCVE-2024-33867
An issue was discovered in linqi before 1.4.0.1 on Windows. There is a hardcoded password salt.... Read more
- Published: May. 14, 2024
- Modified: Apr. 28, 2025
-
5.5
MEDIUMCVE-2024-33866
An issue was discovered in linqi before 1.4.0.1 on Windows. There is /api/DocumentTemplate/{GUID] XSS.... Read more
- Published: May. 14, 2024
- Modified: Apr. 28, 2025
-
5.9
MEDIUMCVE-2024-33864
An issue was discovered in linqi before 1.4.0.1 on Windows. There is SSRF via Document template generation; i.e., via remote images in process creation, file inclusion, and PDF document generation via malicious JavaScript.... Read more
- Published: May. 14, 2024
- Modified: Apr. 28, 2025
-
9.8
CRITICALCVE-2024-48180
ClassCMS <=4.8 is vulnerable to file inclusion in the nowView method in/class/cms/cms.php, which can include a file uploaded to the/class/template directory to execute PHP code.... Read more
Affected Products : classcms- Published: Oct. 16, 2024
- Modified: Apr. 28, 2025
-
7.5
HIGHCVE-2024-33865
An issue was discovered in linqi before 1.4.0.1 on Windows. There is an NTLM hash leak via the /api/Cdn/GetFile and /api/DocumentTemplate/{GUID] endpoints.... Read more
- Published: May. 14, 2024
- Modified: Apr. 28, 2025
-
9.8
CRITICALCVE-2024-33863
An issue was discovered in linqi before 1.4.0.1 on Windows. There is /api/Cdn/GetFile local file inclusion.... Read more
- Published: May. 14, 2024
- Modified: Apr. 28, 2025
-
9.8
CRITICALCVE-2022-30355
OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /profile/updateProfile via the userId and email parameters. Authentication is required.... Read more
Affected Products : ovaledge- Published: Oct. 25, 2024
- Modified: Apr. 28, 2025
-
9.8
CRITICALCVE-2024-46101
GDidees CMS <= v3.9.1 has a file upload vulnerability.... Read more
Affected Products : gdidees_cms- Published: Sep. 20, 2024
- Modified: Apr. 28, 2025
-
9.8
CRITICALCVE-2024-47218
An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows bypassing authentication.... Read more
Affected Products : nebulagraph_database- Published: Sep. 22, 2024
- Modified: Apr. 28, 2025
-
9.8
CRITICALCVE-2024-47219
An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows shell command injection.... Read more
- Published: Sep. 22, 2024
- Modified: Apr. 28, 2025
-
8.0
HIGHCVE-2024-46084
Scriptcase 9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_unzip function.... Read more
Affected Products : scriptcase- Published: Oct. 01, 2024
- Modified: Apr. 28, 2025
-
5.4
MEDIUMCVE-2024-46082
Scriptcase v.9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in nm_cor.php via the form and field parameters.... Read more
Affected Products : scriptcase- Published: Oct. 01, 2024
- Modified: Apr. 28, 2025
-
8.0
HIGHCVE-2024-46080
Scriptcase v9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_zip function.... Read more
Affected Products : scriptcase- Published: Oct. 01, 2024
- Modified: Apr. 28, 2025