Latest CVE Feed
-
7.3
HIGHCVE-2024-53305
An issue in the component /models/config.py of Whoogle search v0.9.0 allows attackers to execute arbitrary code via supplying a crafted search query.... Read more
- Published: Apr. 16, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Injection
-
4.3
MEDIUMCVE-2025-25621
Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows teachers to take attendance of fellow teachers. This affected endpoint is /courses/teacher/index?teacher_id=2&semester_id=1.... Read more
Affected Products : unifiedtransform- Published: Mar. 17, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Authorization
-
3.3
LOWCVE-2025-25618
Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation allowing the change of Section Name and Room Number by Teachers.... Read more
Affected Products : unifiedtransform- Published: Mar. 17, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Authorization
-
5.7
MEDIUMCVE-2024-46327
An issue in the Http_handle object of VONETS VAP11G-300 v3.3.23.6.9 allows attackers to access sensitive files via a directory traversal.... Read more
- Published: Sep. 26, 2024
- Modified: Jun. 24, 2025
-
7.5
HIGHCVE-2024-53907
An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. The strip_tags() method and striptags template filter are subject to a potential denial-of-service attack via certain inputs containing large sequences of nested... Read more
Affected Products : django- Published: Dec. 06, 2024
- Modified: Jun. 24, 2025
-
8.8
HIGHCVE-2025-6410
A vulnerability was found in PHPGurukul Art Gallery Management System 1.1. It has been classified as critical. Affected is an unknown function of the file /admin/edit-art-medium-detail.php. The manipulation of the argument editid leads to sql injection. I... Read more
Affected Products : art_gallery_management_system- Published: Jun. 21, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-6411
A vulnerability was found in PHPGurukul Art Gallery Management System 1.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/changepropic.php. The manipulation of the argument imageid leads to ... Read more
Affected Products : art_gallery_management_system- Published: Jun. 21, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2022-20685
A vulnerability in the Modbus preprocessor of the Snort detection engine could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an integer overflow while processing... Read more
- Published: Nov. 15, 2024
- Modified: Jun. 24, 2025
-
8.8
HIGHCVE-2025-6412
A vulnerability was found in PHPGurukul Art Gallery Management System 1.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/changeimage.php. The manipulation of the argument editid leads to sql injecti... Read more
Affected Products : art_gallery_management_system- Published: Jun. 21, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-6413
A vulnerability classified as critical has been found in PHPGurukul Art Gallery Management System 1.1. This affects an unknown part of the file /admin/changeimage1.php. The manipulation of the argument editid leads to sql injection. It is possible to init... Read more
Affected Products : art_gallery_management_system- Published: Jun. 21, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-6414
A vulnerability classified as critical was found in PHPGurukul Art Gallery Management System 1.1. This vulnerability affects unknown code of the file /admin/changeimage2.php. The manipulation of the argument editid leads to sql injection. The attack can b... Read more
Affected Products : art_gallery_management_system- Published: Jun. 21, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-6415
A vulnerability, which was classified as critical, has been found in PHPGurukul Art Gallery Management System 1.1. This issue affects some unknown processing of the file /admin/changeimage3.php. The manipulation of the argument editid leads to sql injecti... Read more
Affected Products : art_gallery_management_system- Published: Jun. 21, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-6416
A vulnerability, which was classified as critical, was found in PHPGurukul Art Gallery Management System 1.1. Affected is an unknown function of the file /admin/changeimage4.php. The manipulation of the argument editid leads to sql injection. It is possib... Read more
Affected Products : art_gallery_management_system- Published: Jun. 21, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-6417
A vulnerability has been found in PHPGurukul Art Gallery Management System 1.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/add-artist.php. The manipulation of the argument awarddetails leads to... Read more
Affected Products : art_gallery_management_system- Published: Jun. 21, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2025-4867
A vulnerability was found in Tenda A15 15.13.07.13. It has been declared as problematic. Affected by this vulnerability is the function formArpNerworkSet of the file /goform/ArpNerworkSet. The manipulation leads to denial of service. The attack can be lau... Read more
- Published: May. 18, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Denial of Service
-
8.0
HIGHCVE-2024-9847
FlatPress CMS version latest is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow an attacker to enable or disable plugins on behalf of a victim user. The attacker can craft a malicious link or script that, when clicked by an authenticate... Read more
Affected Products : flatpress- Published: Mar. 20, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Cross-Site Request Forgery
-
7.5
HIGHCVE-2024-9699
A vulnerability in the file upload functionality of the FlatPress CMS admin panel (version latest) allows an attacker to upload a file with a JavaScript payload disguised as a filename. This can lead to a Cross-Site Scripting (XSS) attack if the uploaded ... Read more
Affected Products : flatpress- Published: Mar. 20, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-1858
A vulnerability classified as critical was found in Codezips Online Shopping Website 1.0. This vulnerability affects unknown code of the file /success.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. T... Read more
Affected Products : online_shopping_website- Published: Mar. 03, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-1856
A vulnerability was found in Codezips Gym Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /dashboard/admin/gen_invoice.php. The manipulation of the argument id leads to sql injection. ... Read more
Affected Products : gym_management_system- Published: Mar. 03, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Injection
-
9.1
CRITICALCVE-2024-51164
Multiple parameters have SQL injection vulnerability in JEPaaS 7.2.8 via /je/login/btnLog/insertBtnLog, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB.... Read more
Affected Products : jepaas- Published: Nov. 15, 2024
- Modified: Jun. 24, 2025