Latest CVE Feed
-
7.5
HIGHCVE-2023-37022
Open5GS MME versions <= 2.6.4 contain a reachable assertion in the `UE Context Release Request` packet handler. A packet containing an invalid `MME_UE_S1AP_ID` field causes Open5gs to crash; an attacker may repeatedly send such packets to cause denial of ... Read more
Affected Products : open5gs- Published: Jan. 22, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Denial of Service
-
8.6
HIGHCVE-2023-37023
Open5GS MME versions <= 2.6.4 contain a reachable assertion in the `Uplink NAS Transport` packet handler. A packet missing its `MME_UE_S1AP_ID` field causes Open5gs to crash; an attacker may repeatedly send such packets to cause denial of service.... Read more
Affected Products : open5gs- Published: Jan. 22, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Denial of Service
-
7.6
HIGHCVE-2025-29189
Flowise <= 2.2.3 is vulnerable to SQL Injection. via tableName parameter at Postgres_VectorStores.... Read more
Affected Products : flowise- Published: Apr. 09, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-29390
jerryhanjj ERP 1.0 is vulnerable to SQL Injection in the set_password function in application/controllers/home.php.... Read more
- Published: Apr. 09, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Injection
-
7.2
HIGHCVE-2025-29391
horvey Library-Manager v1.0 is vulnerable to SQL Injection in Admin/Controller/BookController.class.php.... Read more
Affected Products : library-manager- Published: Apr. 09, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Injection
-
5.9
MEDIUMCVE-2024-40068
Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at id_generator/admin/?page=templates/manage_template&id=1.... Read more
Affected Products : online_id_generator_system- Published: Apr. 16, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2024-40069
Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generator/classes/Users.php?f=save, and the point of vulnerability is in the POST parameter 'firstname' and 'lastname'.... Read more
Affected Products : online_id_generator_system- Published: Apr. 16, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Cross-Site Scripting
-
5.1
MEDIUMCVE-2024-40070
Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/Users.php?f=save. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.... Read more
Affected Products : online_id_generator_system- Published: Apr. 16, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-40071
Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/SystemSettings.php?f=update_settings. This vulnerability allows attackers to execute arbitrary code via a crafted PHP f... Read more
Affected Products : online_id_generator_system- Published: Apr. 16, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2024-40072
Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at id_generator/admin/?page=generate/index&id=1.... Read more
Affected Products : online_id_generator_system- Published: Apr. 16, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-40073
Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the template parameter at id_generator/admin/?page=generate&template=4.... Read more
Affected Products : online_id_generator_system- Published: Apr. 16, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Injection
-
4.8
MEDIUMCVE-2024-40074
Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generator/classes/SystemSettings.php?f=update_settings, and the point of vulnerability is in the POST parameter 'short_name'.... Read more
Affected Products : online_id_generator_system- Published: Apr. 16, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-28276
Sourcecodester School Task Manager 1.0 is vulnerable to Cross Site Scripting (XSS) via add-task.php?task_name=.... Read more
Affected Products : school_task_manager- Published: May. 14, 2024
- Modified: Apr. 22, 2025
-
9.4
CRITICALCVE-2024-34226
SQL injection vulnerability in /php-sqlite-vms/?page=manage_visitor&id=1 in SourceCodester Visitor Management System 1.0 allow attackers to execute arbitrary SQL commands via the id parameters.... Read more
Affected Products : visitor_management_system- Published: May. 14, 2024
- Modified: Apr. 22, 2025
-
4.6
MEDIUMCVE-2025-22903
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the pin parameter in the function setWiFiWpsConfig.... Read more
- Published: Apr. 15, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-22900
Totolink N600R v4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the macCloneMac parameter in the setWanConfig function.... Read more
- Published: Apr. 15, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Memory Corruption
-
6.9
MEDIUMCVE-2025-3665
A vulnerability has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as critical. Affected by this vulnerability is the function setSmartQosCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. The att... Read more
- Published: Apr. 16, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Authorization
-
6.9
MEDIUMCVE-2025-3664
A vulnerability, which was classified as critical, was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. Affected is the function setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. It is possible to lau... Read more
- Published: Apr. 16, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Authorization
-
6.1
MEDIUMCVE-2024-34230
A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the System Information parameter.... Read more
Affected Products : laboratory_management_system- Published: May. 14, 2024
- Modified: Apr. 22, 2025
-
6.9
MEDIUMCVE-2025-3674
A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been declared as critical. Affected by this vulnerability is the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. Th... Read more
- Published: Apr. 16, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Authorization