Latest CVE Feed
-
9.8
CRITICALCVE-2025-10025
A vulnerability has been found in PHPGurukul Online Course Registration 3.1. Affected is an unknown function of the file /admin/semester.php. The manipulation of the argument semester leads to sql injection. It is possible to initiate the attack remotely.... Read more
Affected Products : online_course_registration- Published: Sep. 05, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-10026
A vulnerability was found in itsourcecode POS Point of Sale System 1.0. Affected by this vulnerability is an unknown functionality of the file /inventory/main/vendors/datatables/unit_testing/templates/-complex_header.php. The manipulation of the argument ... Read more
Affected Products : point_of_sale_system- Published: Sep. 05, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-10112
A weakness has been identified in itsourcecode Student Information Management System 1.0. The impacted element is an unknown function of the file /admin/modules/department/index.php. This manipulation of the argument ID causes sql injection. The attack is... Read more
Affected Products : student_information_management_system- Published: Sep. 09, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-10114
A vulnerability was found in PHPGurukul Small CRM 4.0. Affected by this issue is some unknown functionality of the file /profile.php. The manipulation of the argument Name results in sql injection. The attack can be launched remotely. The exploit has been... Read more
Affected Products : small_crm- Published: Sep. 09, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-10113
A security vulnerability has been detected in itsourcecode Student Information Management System 1.0. This affects an unknown function of the file /admin/modules/room/index.php. Such manipulation of the argument ID leads to sql injection. The attack may b... Read more
Affected Products : student_information_management_system- Published: Sep. 09, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2025-10117
A weakness has been identified in SourceCodester Simple To-Do List System 1.0. Impacted is an unknown function of the file /fetch_tasks.php of the component Add New Task. Executing manipulation with the input <script>alert('XSS')</script> can lead to cros... Read more
Affected Products : simple_to-do_list_system- Published: Sep. 09, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-10118
A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. The affected element is an unknown function of the file /login.php. The manipulation of the argument Username leads to sql injection. The ... Read more
Affected Products : e-logbook_with_health_monitoring_system_for_covid-19- Published: Sep. 09, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Injection
-
9.0
HIGHCVE-2025-10120
A vulnerability was detected in Tenda AC20 up to 16.03.08.12. The impacted element is the function strcpy of the file /goform/GetParentControlInfo. The manipulation of the argument mac results in buffer overflow. The attack may be performed from remote. T... Read more
- Published: Sep. 09, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-10109
A vulnerability was determined in Campcodes Online Loan Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=delete_payment. Executing manipulation of the argument ID can lead to sql injection. The attack may be l... Read more
Affected Products : online_loan_management_system- Published: Sep. 08, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-13792
The WooCommerce Food - Restaurant Menu & Food ordering plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.2. This is due to the software allowing users to execute an action that does not properly ... Read more
- Published: Feb. 20, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-10111
A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is an unknown function of the file /admin/modules/instructor/index.php. The manipulation of the argument ID results in sql injection. The a... Read more
Affected Products : student_information_management_system- Published: Sep. 08, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-10110
A vulnerability was identified in ChanCMS up to 3.3.1. Impacted is an unknown function of the file /search/. The manipulation with the input '%20or%201=1%20%23/words.html leads to sql injection. Remote exploitation of the attack is possible. The exploit i... Read more
Affected Products : chancms- Published: Sep. 08, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Injection
-
5.5
MEDIUMCVE-2025-8681
Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component. Requires a high privileged user with a developer role.... Read more
Affected Products : infinity- Published: Sep. 10, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-59045
Stalwart is a mail and collaboration server. Starting in version 0.12.0 and prior to version 0.13.3, a memory exhaustion vulnerability exists in Stalwart's CalDAV implementation that allows authenticated attackers to cause denial-of-service by triggering ... Read more
Affected Products :- Published: Sep. 10, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Denial of Service
-
8.7
HIGHCVE-2025-59041
Claude Code is an agentic coding tool. At startup, Claude Code executed a command templated in with `git config user.email`. Prior to version 1.0.105, a maliciously configured user email in git could be used to trigger arbitrary code execution before a us... Read more
Affected Products :- Published: Sep. 10, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Misconfiguration
-
4.6
MEDIUMCVE-2025-59035
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to version 3.3.8, there is a Cross-Site-Scripting vulnerability when rendering LaTeX math code in contribution or abstract descriptions.... Read more
Affected Products : indico- Published: Sep. 10, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-59034
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to version 3.3.8, a legacy API to retrieve user details could be misused to retrieve profile details of other users without having admin... Read more
Affected Products : indico- Published: Sep. 10, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Authorization
-
8.7
HIGHCVE-2025-58764
Claude Code is an agentic coding tool. Due to an error in command parsing, versions prior to 1.0.105 were vulnerable to a bypass of the Claude Code confirmation prompt to trigger execution of an untrusted command. Reliably exploiting this requires the abi... Read more
Affected Products :- Published: Sep. 10, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Misconfiguration
-
6.9
MEDIUMCVE-2025-57791
A security vulnerability has been identified that allows remote attackers to inject or manipulate command-line arguments passed to internal components due to insufficient input validation. Successful exploitation results in a valid user session for a low ... Read more
- Published: Aug. 20, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-57790
A security vulnerability has been identified that allows remote attackers to perform unauthorized file system access through a path traversal issue. The vulnerability may lead to remote code execution.... Read more
- Published: Aug. 20, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Path Traversal