Latest CVE Feed
-
3.3
LOWCVE-2024-56495
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.... Read more
- Published: Feb. 27, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Information Disclosure
-
3.3
LOWCVE-2024-56496
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.... Read more
- Published: Feb. 27, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Information Disclosure
-
7.8
HIGHCVE-2022-40847
In Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576), there exists a command injection vulnerability in the function formSetFixTools. This vulnerability allows attackers to run arbitrary commands on the server via the hostname parameter.... Read more
- Published: Nov. 15, 2022
- Modified: Jul. 07, 2025
-
6.5
MEDIUMCVE-2022-40845
The Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576) is affected by a password exposure vulnerability. When combined with the improper authorization/improper session management vulnerability, an attacker with access to the router may be able to expose s... Read more
- Published: Nov. 15, 2022
- Modified: Jul. 07, 2025
-
4.9
MEDIUMCVE-2022-40843
The Tenda AC1200 V-W15Ev2 V15.11.0.10(1576) router is vulnerable to improper authorization / improper session management that allows the router login page to be bypassed. This leads to authenticated attackers having the ability to read the routers syslog.... Read more
- Published: Nov. 15, 2022
- Modified: Jul. 07, 2025
-
7.8
HIGHCVE-2022-42053
Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a command injection vulnerability via the PortMappingServer parameter in the setPortMapping function.... Read more
- Published: Nov. 15, 2022
- Modified: Jul. 07, 2025
-
4.8
MEDIUMCVE-2022-40846
In Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576), a Stored Cross Site Scripting (XSS) vulnerability exists allowing an attacker to execute JavaScript code via the applications stored hostname.... Read more
- Published: Nov. 15, 2022
- Modified: Jul. 07, 2025
-
9.8
CRITICALCVE-2025-25763
crmeb CRMEB-KY v5.4.0 and before has a SQL Injection vulnerability at getRead() in /system/SystemDatabackupServices.php... Read more
Affected Products : crmeb- Published: Mar. 06, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2022-40844
In Tenda (Shenzhen Tenda Technology Co., Ltd) AC1200 Router model W15Ev2 V15.11.0.10(1576), a Stored Cross Site Scripting (XSS) issue exists allowing an attacker to execute JavaScript code via the applications website filtering tab, specifically the URL b... Read more
- Published: Nov. 15, 2022
- Modified: Jul. 07, 2025
-
6.5
MEDIUMCVE-2024-12607
The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'mj_smgt_show_event_task' AJAX action in all versions up to, and including, 92.0.0 due to insufficient escaping on the user suppli... Read more
Affected Products : school_management_system- Published: Mar. 07, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2024-12609
The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'view-attendance' page in all versions up to, and including, 92.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient p... Read more
Affected Products : school_management_system- Published: Mar. 07, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-40733
Reflected Cross-Site Scripting (XSS) vulnerability in Daily Expense Manager v1.0. This vulnerability allows an attacker to execute JavaScript code by sending a POST request through the username parameter in /login.php.... Read more
Affected Products : daily_expense_manager- Published: Jun. 30, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2024-56518
Hazelcast Management Center through 6.0 allows remote code execution via a JndiLoginModule user.provider.url in a hazelcast-client XML document (aka a client configuration file), which can be uploaded at the /cluster-connections URI.... Read more
Affected Products : management_center- Published: Apr. 17, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Misconfiguration
-
6.1
MEDIUMCVE-2025-40734
Reflected Cross-Site Scripting (XSS) vulnerability in Daily Expense Manager v1.0. This vulnerability allows an attacker to execute JavaScript code by sending a POST request through the password and confirm_password parameters in /register.php.... Read more
Affected Products : daily_expense_manager- Published: Jun. 30, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2024-12610
The School Management System for Wordpress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'mj_smgt_remove_feetype' and 'mj_smgt_remove_category_new' AJAX actions in all versions up to, and includin... Read more
Affected Products : school_management_system- Published: Mar. 07, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2024-12611
The School Management System for Wordpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'title' parameter in all versions up to, and including, 93.0.0 due to insufficient input sanitization and output escaping. This makes i... Read more
Affected Products : school_management_system- Published: Mar. 07, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-25929
A reflected cross-site scripting (XSS) vulnerability in the component /legacyui/quickReportServlet of Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted payload injected into the re... Read more
Affected Products : openmrs- Published: Mar. 11, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Cross-Site Scripting
-
7.7
HIGHCVE-2025-25680
LSC Smart Connect LSC Indoor PTZ Camera 7.6.32 is contains a RCE vulnerability in the tuya_ipc_direct_connect function of the anyka_ipc process. The vulnerability allows arbitrary code execution through the Wi-Fi configuration process when a specially cra... Read more
- Published: Mar. 11, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Authentication
-
7.8
HIGHCVE-2022-41121
Windows Graphics Component Elevation of Privilege Vulnerability... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 +16 more products- Published: Dec. 13, 2022
- Modified: Jul. 07, 2025
-
6.5
MEDIUMCVE-2022-22015
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_server windows_10_1607 +15 more products- Published: May. 10, 2022
- Modified: Jul. 07, 2025