Latest CVE Feed
-
9.8
CRITICALCVE-2025-8439
A vulnerability, which was classified as critical, has been found in code-projects Wazifa System 1.0. This issue affects some unknown processing of the file /controllers/updatesettings.php. The manipulation of the argument Password leads to sql injection.... Read more
Affected Products : wazifa_system- Published: Aug. 01, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-8441
A vulnerability, which was classified as critical, was found in code-projects Online Medicine Guide 1.0. Affected is an unknown function of the file /pharsignup.php. The manipulation of the argument phuname leads to sql injection. It is possible to launch... Read more
Affected Products : online_medicine_guide- Published: Aug. 01, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-8442
A vulnerability has been found in code-projects Online Medicine Guide 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /cussignup.php. The manipulation of the argument uname leads to sql injection. The... Read more
Affected Products : online_medicine_guide- Published: Aug. 01, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-8443
A vulnerability was found in code-projects Online Medicine Guide 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument uname leads to sql injection. The attack may be ... Read more
Affected Products : online_medicine_guide- Published: Aug. 01, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2024-52279
Improper Input Validation vulnerability in Apache Zeppelin. The fix for JDBC URL validation in CVE-2024-31864 did not account for URL encoded input. This issue affects Apache Zeppelin: from 0.11.1 before 0.12.0. Users are recommended to upgrade to versi... Read more
Affected Products : zeppelin- Published: Aug. 03, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-8494
A vulnerability, which was classified as critical, has been found in code-projects Intern Membership Management System 1.0. This issue affects some unknown processing of the file /admin/delete_student.php. The manipulation of the argument ID leads to sql ... Read more
- Published: Aug. 03, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2024-43438
A flaw was found in Feedback. Bulk messaging in the activity's non-respondents report did not verify message recipients belonging to the set of users returned by the report.... Read more
Affected Products : moodle- Published: Nov. 07, 2024
- Modified: Aug. 05, 2025
-
7.2
HIGHCVE-2024-43436
A SQL injection risk flaw was found in the XMLDB editor tool available to site administrators.... Read more
Affected Products : moodle- Published: Nov. 07, 2024
- Modified: Aug. 05, 2025
-
6.0
MEDIUMCVE-2024-3447
A heap-based buffer overflow was found in the SDHCI device emulation of QEMU. The bug is triggered when both `s->data_count` and the size of `s->fifo_buffer` are set to 0x200, leading to an out-of-bound access. A malicious guest could use this flaw to cr... Read more
- Published: Nov. 14, 2024
- Modified: Aug. 05, 2025
-
7.5
HIGHCVE-2024-43426
A flaw was found in pdfTeX. Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available, such as those with TeX Live installed.... Read more
Affected Products : moodle- Published: Nov. 07, 2024
- Modified: Aug. 05, 2025
-
9.8
CRITICALCVE-2025-8466
A vulnerability was found in code-projects Online Farm System 1.0. It has been classified as critical. Affected is an unknown function of the file /forgot_passfarmer.php. The manipulation of the argument email leads to sql injection. It is possible to lau... Read more
Affected Products : online_farm_system- Published: Aug. 02, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-8467
A vulnerability was found in code-projects Wazifa System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /controllers/regcontrol.php. The manipulation of the argument Username leads to sql inje... Read more
Affected Products : wazifa_system- Published: Aug. 02, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-8468
A vulnerability was found in code-projects Wazifa System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /controllers/reset.php. The manipulation of the argument email leads to sql injection. The attack... Read more
Affected Products : wazifa_system- Published: Aug. 02, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Injection
-
7.7
HIGHCVE-2025-53893
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename, and edit files. In version 2.38.0, a Denial of Service (DoS) vulnerability exists in the file processing logic when reading... Read more
Affected Products : filebrowser- Published: Jul. 15, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Denial of Service
-
7.8
HIGHCVE-2024-7730
A heap buffer overflow was found in the virtio-snd device in QEMU. When reading input audio in the virtio-snd input callback, virtio_snd_pcm_in_cb, the function did not check whether the iov can fit the data buffer. This issue can trigger an out-of-bounds... Read more
Affected Products : qemu- Published: Nov. 14, 2024
- Modified: Aug. 05, 2025
-
9.8
CRITICALCVE-2025-53826
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename, and edit files. In version 2.39.0, File Browser’s authentication system issues long-lived JWT tokens that remain valid even... Read more
Affected Products : filebrowser- Published: Jul. 15, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-8469
A vulnerability classified as critical has been found in SourceCodester Online Hotel Reservation System 1.0. This affects an unknown part of the file /admin/deletegallery.php. The manipulation of the argument ID leads to sql injection. It is possible to i... Read more
- Published: Aug. 02, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-8470
A vulnerability classified as critical was found in SourceCodester Online Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /admin/deleteroom.php. The manipulation of the argument ID leads to sql injection. The attack can b... Read more
- Published: Aug. 02, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Injection
-
8.0
HIGHCVE-2025-52904
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. In version 2.32.0 of the web application, all users have a scope assigned, and they only have access to the ... Read more
Affected Products : filebrowser- Published: Jun. 26, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-8471
A vulnerability, which was classified as critical, has been found in projectworlds Online Admission System 1.0. This issue affects some unknown processing of the file /adminlogin.php. The manipulation of the argument a_id leads to sql injection. The attac... Read more
Affected Products : online_admission_system- Published: Aug. 02, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Injection