Latest CVE Feed
-
4.3
MEDIUMCVE-2025-58459
Jenkins global-build-stats Plugin 322.v22f4db_18e2dd and earlier does not perform permission checks in its REST API endpoints, allowing attackers with Overall/Read permission to enumerate graph IDs.... Read more
- Published: Sep. 03, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Authorization
-
6.9
MEDIUMCVE-2025-54541
QuickCMS is vulnerable to Cross-Site Request Forgery in page deletion functionality. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request deleting an article. The vendor was notified early ... Read more
Affected Products : quick.cms- Published: Aug. 28, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.9
MEDIUMCVE-2025-54542
QuickCMS sends password and login via GET Request. This allows a local attacker with access to the victim's browser history to obtain the necessary credentials to log in as the user. The vendor was notified early about this vulnerability, but didn't resp... Read more
Affected Products : quick.cms- Published: Aug. 28, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Authentication
-
5.3
MEDIUMCVE-2025-54543
QuickCMS is vulnerable to Stored XSS via sDescriptionMeta parameter in page editor SEO functionality. Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. By def... Read more
Affected Products : quick.cms- Published: Aug. 28, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Cross-Site Scripting
-
8.5
HIGHCVE-2009-3369
CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias function, which allows remote authenticated users to read and write sensitive files by modifying ClientNa... Read more
- Published: Sep. 24, 2009
- Modified: Sep. 08, 2025
-
4.3
MEDIUMCVE-2011-3361
Cross-site scripting (XSS) vulnerability in CGI/Browse.pm in BackupPC 3.2.0 and possibly other versions before 3.2.1 allows remote attackers to inject arbitrary web script or HTML via the num parameter in a browse action to index.cgi.... Read more
- Published: Feb. 18, 2012
- Modified: Sep. 08, 2025
-
4.3
MEDIUMCVE-2011-4923
Cross-site scripting (XSS) vulnerability in View.pm in BackupPC 3.0.0, 3.1.0, 3.2.0, 3.2.1, and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the num parameter in a view action to index.cgi, related to the log file vi... Read more
- Published: Feb. 18, 2012
- Modified: Sep. 08, 2025
-
4.3
MEDIUMCVE-2011-5081
Cross-site scripting (XSS) vulnerability in RestoreFile.pm in BackupPC 3.1.0, 3.2.1, and possibly other earlier versions allows remote attackers to inject arbitrary web script or HTML via the share parameter in a RestoreFile action to index.cgi.... Read more
- Published: Feb. 18, 2012
- Modified: Sep. 08, 2025
-
9.8
CRITICALCVE-2025-9699
A vulnerability was detected in SourceCodester Online Polling System Code 1.0. This vulnerability affects unknown code of the file /admin/checklogin.php. The manipulation of the argument myusername results in sql injection. The attack may be performed fro... Read more
Affected Products : online_polling_system- Published: Aug. 30, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-9700
A flaw has been found in SourceCodester Online Book Store 1.0. This issue affects some unknown processing of the file /publisher_list.php. This manipulation of the argument pubid causes sql injection. It is possible to initiate the attack remotely. The ex... Read more
Affected Products : online_book_store- Published: Aug. 30, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-9701
A vulnerability was determined in SourceCodester Simple Cafe Billing System 1.0. The impacted element is an unknown function of the file /receipt.php. Executing manipulation of the argument ID can lead to sql injection. The attack can be launched remotely... Read more
Affected Products : simple_cafe_billing_system- Published: Aug. 30, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-9702
A vulnerability was identified in SourceCodester Simple Cafe Billing System 1.0. This affects an unknown function of the file /sales_report.php. The manipulation of the argument month leads to sql injection. The attack may be initiated remotely. The explo... Read more
Affected Products : simple_cafe_billing_system- Published: Aug. 30, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-9704
A security flaw has been discovered in SourceCodester Water Billing System 1.0. This impacts an unknown function of the file /viewbill.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has ... Read more
Affected Products : water_billing_system- Published: Aug. 30, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-9705
A weakness has been identified in SourceCodester Water Billing System 1.0. Affected is an unknown function of the file /paybill.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has ... Read more
Affected Products : water_billing_system- Published: Aug. 30, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-9706
A security vulnerability has been detected in SourceCodester Water Billing System 1.0. Affected by this vulnerability is an unknown functionality of the file /edit.php. Such manipulation of the argument ID leads to sql injection. The attack can be execute... Read more
Affected Products : water_billing_system- Published: Aug. 30, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-9664
A security flaw has been discovered in code-projects Simple Grading System 1.0. Affected is an unknown function of the file /add_student_grade.php of the component Admin Panel. The manipulation of the argument Add results in sql injection. It is possible ... Read more
Affected Products : simple_grading_system- Published: Aug. 29, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-9663
A vulnerability was identified in code-projects Simple Grading System 1.0. This impacts an unknown function of the file /edit_account.php of the component Admin Panel. The manipulation of the argument ID leads to sql injection. It is possible to initiate ... Read more
Affected Products : simple_grading_system- Published: Aug. 29, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-9662
A vulnerability was determined in code-projects Simple Grading System 1.0. This affects an unknown function of the file /login.php of the component Admin Panel. Executing manipulation can lead to sql injection. The attack may be performed from a remote lo... Read more
Affected Products : simple_grading_system- Published: Aug. 29, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-9660
A vulnerability was found in SourceCodester Bakeshop Online Ordering System 1.0. The impacted element is an unknown function of the file /passwordrecover.php. Performing manipulation of the argument phonenumber results in sql injection. The attack is poss... Read more
Affected Products : bakeshop_online_ordering_system- Published: Aug. 29, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-9667
A vulnerability was detected in code-projects Simple Grading System 1.0. This affects an unknown part of the file /delete_account.php of the component Admin Panel. Performing manipulation of the argument ID results in sql injection. The attack may be init... Read more
Affected Products : simple_grading_system- Published: Aug. 29, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Injection