Latest CVE Feed
-
9.8
CRITICALCVE-2025-5008
A vulnerability was found in projectworlds Online Time Table Generator 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/add_teacher.php. The manipulation of the argument e leads to sql injection. ... Read more
- Published: May. 20, 2025
- Modified: Aug. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-0498
A vulnerability was found in Project Worlds Lawyer Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file searchLawyer.php. The manipulation of the argument experience leads to sql i... Read more
- EPSS Score: %0.05
- Published: Jan. 13, 2024
- Modified: Aug. 28, 2025
-
5.4
MEDIUMCVE-2024-0266
A vulnerability classified as problematic has been found in Project Worlds Online Lawyer Management System 1.0. Affected is an unknown function of the component User Registration. The manipulation of the argument First Name leads to cross site scripting. ... Read more
- EPSS Score: %0.10
- Published: Jan. 07, 2024
- Modified: Aug. 28, 2025
-
9.8
CRITICALCVE-2025-4931
A vulnerability classified as critical was found in projectworlds Online Lawyer Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /user_registation.php. The manipulation of the argument email leads to sql inject... Read more
- Published: May. 19, 2025
- Modified: Aug. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4706
A vulnerability was found in projectworlds Online Examination System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /Procedure3b_yearwiseVisit.php. The manipulation of the argument Visit_year leads to sql inject... Read more
- Published: May. 15, 2025
- Modified: Aug. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4739
A vulnerability was found in projectworlds Hospital Database Management System 1.0. It has been classified as critical. This affects an unknown part of the file /medicines_info.php. The manipulation of the argument Med_ID leads to sql injection. It is pos... Read more
- Published: May. 16, 2025
- Modified: Aug. 28, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2024-53269
Envoy is a cloud-native high-performance edge/middle/service proxy. When additional address are not ip addresses, then the Happy Eyeballs sorting algorithm will crash in data plane. This issue has been addressed in releases 1.32.2, 1.31.4, and 1.30.8. Use... Read more
Affected Products : envoy- Published: Dec. 18, 2024
- Modified: Aug. 28, 2025
-
5.4
MEDIUMCVE-2024-53262
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. The static error.html template for errors contains placeholders that are replaced without escaping the content first. error.html is the page that is rendered... Read more
Affected Products : sveltekit- Published: Nov. 25, 2024
- Modified: Aug. 28, 2025
-
5.4
MEDIUMCVE-2024-53261
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. "Unsanitized input from *the request URL* flows into `end`, where it is used to render an HTML page returned to the user. This may result in a Cross-Site Scr... Read more
Affected Products : sveltekit- Published: Nov. 25, 2024
- Modified: Aug. 28, 2025
-
7.5
HIGHCVE-2024-52510
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client did not stop with an error but allowed by-passing the signature validation, if a manipulated server sends an empty initial signature. ... Read more
- Published: Nov. 15, 2024
- Modified: Aug. 28, 2025
-
7.7
HIGHCVE-2025-51970
A SQL Injection vulnerability exists in the action.php endpoint of PuneethReddyHC Online Shopping System Advanced 1.0 due to improper sanitization of user-supplied input in the keyword POST parameter.... Read more
Affected Products : online_shopping_system_advanced- Published: Jul. 29, 2025
- Modified: Aug. 28, 2025
- Vuln Type: Injection
-
3.8
LOWCVE-2024-6219
Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not honoured.... Read more
Affected Products : lxd- Published: Dec. 06, 2024
- Modified: Aug. 28, 2025
-
6.1
MEDIUMCVE-2025-9432
A vulnerability has been found in mtons mblog up to 3.5.0. The affected element is an unknown function of the file /admin/post/list of the component Admin Panel. Such manipulation of the argument Title leads to cross site scripting. The attack can be laun... Read more
Affected Products : mblog- Published: Aug. 26, 2025
- Modified: Aug. 28, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-9431
A flaw has been found in mtons mblog up to 3.5.0. Impacted is an unknown function of the file /search. This manipulation of the argument kw causes cross site scripting. The attack can be initiated remotely. The exploit has been published and may be used.... Read more
Affected Products : mblog- Published: Aug. 26, 2025
- Modified: Aug. 28, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2022-4536
The IP Vault – WP Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.1. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restr... Read more
- Published: Aug. 31, 2024
- Modified: Aug. 28, 2025
-
4.8
MEDIUMCVE-2025-9430
A vulnerability was detected in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /admin/options/update. The manipulation of the argument input results in cross site scripting. It is possible to launch the attack remotely. Th... Read more
Affected Products : mblog- Published: Aug. 26, 2025
- Modified: Aug. 28, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-9429
A security vulnerability has been detected in mtons mblog up to 3.5.0. This vulnerability affects unknown code of the file /post/submit of the component Post Handler. The manipulation of the argument content/title/ leads to cross site scripting. It is pos... Read more
Affected Products : mblog- Published: Aug. 26, 2025
- Modified: Aug. 28, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-8908
A vulnerability was determined in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.5.4. Affected by this issue is some unknown functionality of the file crm/WeiXinApp/yunzhijia/event.php. The manipulation of the argument openid leads to sql... Read more
Affected Products : lingdang_crm- Published: Aug. 13, 2025
- Modified: Aug. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-55619
Reolink v4.54.0.4.20250526 was discovered to contain a hardcoded encryption key and initialization vector. An attacker can leverage this vulnerability to decrypt access tokens and web session tokens stored inside the app via reverse engineering.... Read more
Affected Products : reolink- Published: Aug. 22, 2025
- Modified: Aug. 28, 2025
- Vuln Type: Cryptography
-
6.1
MEDIUMCVE-2025-55620
A cross-site scripting (XSS) vulnerability in the valuateJavascript() function of Reolink v4.54.0.4.20250526 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products : reolink- Published: Aug. 22, 2025
- Modified: Aug. 28, 2025
- Vuln Type: Cross-Site Scripting