Latest CVE Feed
-
7.5
HIGHCVE-2025-13578
A vulnerability has been found in code-projects Library System 1.0. This affects an unknown function of the file /index.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The... Read more
Affected Products :- Published: Nov. 24, 2025
- Modified: Nov. 24, 2025
- Vuln Type: Injection
-
5.1
MEDIUMCVE-2025-13577
A flaw has been found in PHPGurukul Hostel Management System 2.1. The impacted element is an unknown function of the file /register-complaint.php. Executing manipulation of the argument cdetails can lead to cross site scripting. It is possible to launch t... Read more
Affected Products :- Published: Nov. 24, 2025
- Modified: Nov. 24, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-13576
A vulnerability was detected in code-projects Blog Site 1.0. The affected element is an unknown function of the file /admin.php. Performing manipulation results in improper authorization. It is possible to initiate the attack remotely. The exploit is now ... Read more
Affected Products :- Published: Nov. 24, 2025
- Modified: Nov. 24, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-13575
A security vulnerability has been detected in code-projects Blog Site 1.0. Impacted is the function category_exists of the file /resources/functions/blog.php of the component Category Handler. Such manipulation of the argument name/field leads to sql inje... Read more
Affected Products :- Published: Nov. 24, 2025
- Modified: Nov. 24, 2025
- Vuln Type: Injection
-
5.8
MEDIUMCVE-2025-13574
A weakness has been identified in code-projects Online Bidding System 1.0. This issue affects the function categoryadd of the file /administrator/addcategory.php. This manipulation of the argument catimage causes unrestricted upload. The attack is possibl... Read more
Affected Products : online_bidding_system- Published: Nov. 24, 2025
- Modified: Nov. 24, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2025-13573
A security flaw has been discovered in projectworlds can pass malicious payloads up to 1.0. This vulnerability affects unknown code of the file /add_book.php. The manipulation of the argument image results in unrestricted upload. The attack can be execute... Read more
Affected Products :- Published: Nov. 24, 2025
- Modified: Nov. 24, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-13572
A vulnerability was identified in projectworlds Advanced Library Management System 1.0. This affects an unknown part of the file /delete_admin.php. The manipulation of the argument admin_id leads to sql injection. Remote exploitation of the attack is poss... Read more
Affected Products : advanced_library_management_system- Published: Nov. 23, 2025
- Modified: Nov. 23, 2025
- Vuln Type: Injection
-
6.4
MEDIUMCVE-2025-12800
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.4.5 via the su_shortcode_csv_table function. This makes it possible for authenticated attackers, with ... Read more
Affected Products : shortcodes_ultimate- Published: Nov. 23, 2025
- Modified: Nov. 23, 2025
- Vuln Type: Server-Side Request Forgery
-
6.5
MEDIUMCVE-2025-13571
A vulnerability was determined in code-projects Simple Food Ordering System 1.0. Affected by this issue is some unknown functionality of the file /listorder.php. Executing manipulation of the argument ID can lead to sql injection. The attack may be launch... Read more
Affected Products : simple_food_ordering_system- Published: Nov. 23, 2025
- Modified: Nov. 23, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-13570
A vulnerability was found in itsourcecode COVID Tracking System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/?page=state. Performing manipulation of the argument ID results in sql injection. The attack may be initiate... Read more
Affected Products :- Published: Nov. 23, 2025
- Modified: Nov. 23, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-13569
A vulnerability has been found in itsourcecode COVID Tracking System 1.0. Affected is an unknown function of the file /admin/?page=city. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been... Read more
Affected Products :- Published: Nov. 23, 2025
- Modified: Nov. 23, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-13568
A flaw has been found in itsourcecode COVID Tracking System 1.0. This impacts an unknown function of the file /admin/?page=people. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been publis... Read more
Affected Products :- Published: Nov. 23, 2025
- Modified: Nov. 23, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-13567
A vulnerability was detected in itsourcecode COVID Tracking System 1.0. This affects an unknown function of the file /admin/?page=establishment. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. Th... Read more
Affected Products :- Published: Nov. 23, 2025
- Modified: Nov. 23, 2025
- Vuln Type: Injection
-
4.8
MEDIUMCVE-2025-13566
A security vulnerability has been detected in jarun nnn up to 5.1. The impacted element is the function show_content_in_floating_window/run_cmd_as_plugin of the file nnn/src/nnn.c. The manipulation leads to double free. An attack has to be approached loca... Read more
Affected Products :- Published: Nov. 23, 2025
- Modified: Nov. 23, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-13565
A weakness has been identified in SourceCodester Inventory Management System 1.0. The affected element is an unknown function of the file /model/user/resetPassword.php. Executing manipulation can lead to weak password recovery. The attack may be performed... Read more
Affected Products : free_and_open_source_inventory_management_system- Published: Nov. 23, 2025
- Modified: Nov. 23, 2025
- Vuln Type: Authentication
-
5.5
MEDIUMCVE-2025-13564
A security flaw has been discovered in SourceCodester Pre-School Management System 1.0. Impacted is the function removefile of the file app/controllers/FilehelperController.php. Performing manipulation of the argument filepath results in denial of service... Read more
Affected Products :- Published: Nov. 23, 2025
- Modified: Nov. 23, 2025
- Vuln Type: Denial of Service
-
1.0
LOWCVE-2025-54515
The Secure Flag passed to Versal™ Adaptive SoC’s Arm® Trusted Firmware for Cortex®-A processors (TF-A) for Arm’s Power State Coordination Interface (PSCI) commands were incorrectly set to secure instead of using the processor’s actual security state. This... Read more
Affected Products :- Published: Nov. 23, 2025
- Modified: Nov. 23, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-13562
A vulnerability was identified in D-Link DIR-852 1.00. This issue affects some unknown processing of the file /gena.cgi. Such manipulation of the argument service leads to command injection. The attack can be executed remotely. The exploit is publicly ava... Read more
Affected Products : dir-852_firmware- Published: Nov. 23, 2025
- Modified: Nov. 23, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-13561
A vulnerability was determined in SourceCodester Company Website CMS 1.0. This vulnerability affects unknown code of the file /admin/index.php. This manipulation of the argument Username causes sql injection. Remote exploitation of the attack is possible.... Read more
Affected Products : company_website_cms- Published: Nov. 23, 2025
- Modified: Nov. 23, 2025
- Vuln Type: Injection
-
8.6
HIGHCVE-2025-48507
The security state of the calling processor into Arm® Trusted Firmware (TF-A) is not used and could potentially allow non-secure processors access to secure memories, access to crypto operations, and the ability to turn on and off subsystems within the SO... Read more
Affected Products :- Published: Nov. 23, 2025
- Modified: Nov. 23, 2025
- Vuln Type: Authentication