Latest CVE Feed
-
8.8
HIGHCVE-2024-42554
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at admin_room_added.php.... Read more
- Published: Aug. 20, 2024
- Modified: Jun. 05, 2025
-
8.8
HIGHCVE-2024-42555
A Cross-Site Request Forgery (CSRF) in the component admin_room_removed.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.... Read more
Affected Products : hotel_management_system- Published: Aug. 20, 2024
- Modified: Jun. 05, 2025
-
9.8
CRITICALCVE-2024-42556
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at admin_room_removed.php.... Read more
Affected Products : hotel_management_system- Published: Aug. 20, 2024
- Modified: Jun. 05, 2025
-
8.8
HIGHCVE-2024-42557
A Cross-Site Request Forgery (CSRF) in the component admin_modify_room.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.... Read more
Affected Products : hotel_management_system- Published: Aug. 20, 2024
- Modified: Jun. 05, 2025
-
9.8
CRITICALCVE-2024-42558
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter at admin_modify_room.php.... Read more
Affected Products : hotel_management_system- Published: Aug. 20, 2024
- Modified: Jun. 05, 2025
-
6.1
MEDIUMCVE-2024-42560
A cross-site scripting (XSS) vulnerability in the component update_page_details.php of Blood Bank And Donation Management System commit dc9e039 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page Details ... Read more
Affected Products : blood_bank_and_donation_management_system- Published: Aug. 20, 2024
- Modified: Jun. 05, 2025
-
8.8
HIGHCVE-2024-42561
Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at sales_report.php.... Read more
- Published: Aug. 20, 2024
- Modified: Jun. 05, 2025
-
9.8
CRITICALCVE-2024-42562
Pharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at preview.php.... Read more
Affected Products : pharmacy_management_system- Published: Aug. 20, 2024
- Modified: Jun. 05, 2025
-
9.8
CRITICALCVE-2024-42563
An arbitrary file upload vulnerability in ERP commit 44bd04 allows attackers to execute arbitrary code via uploading a crafted HTML file.... Read more
- Published: Aug. 20, 2024
- Modified: Jun. 05, 2025
-
9.8
CRITICALCVE-2024-42569
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at paidclass.php.... Read more
Affected Products : school_management_system- Published: Aug. 20, 2024
- Modified: Jun. 05, 2025
-
9.8
CRITICALCVE-2024-42571
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at insertattendance.php.... Read more
- Published: Aug. 20, 2024
- Modified: Jun. 05, 2025
-
7.8
HIGHCVE-2024-22705
An issue was discovered in ksmbd in the Linux kernel before 6.6.10. smb2_get_data_area_len in fs/smb/server/smb2misc.c can cause an smb_strndup_from_utf16 out-of-bounds access because the relationship between Name data and CreateContexts data is mishandle... Read more
Affected Products : linux_kernel- EPSS Score: %0.02
- Published: Jan. 23, 2024
- Modified: Jun. 05, 2025
-
6.3
MEDIUMCVE-2024-22099
NULL Pointer Dereference vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (net, bluetooth modules) allows Overflow Buffers. This vulnerability is associated with program files /net/bluetooth/rfcomm/core.C. This issue affects Linux kernel: v2... Read more
Affected Products : linux_kernel- EPSS Score: %0.04
- Published: Jan. 25, 2024
- Modified: Jun. 05, 2025
-
4.9
MEDIUMCVE-2023-34324
Closing of an event channel in the Linux kernel can result in a deadlock. This happens when the close is being performed in parallel to an unrelated Xen console action and the handling of a Xen console interrupt in an unprivileged guest. The closing of a... Read more
- EPSS Score: %0.07
- Published: Jan. 05, 2024
- Modified: Jun. 05, 2025
-
9.8
CRITICALCVE-2025-5074
A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. Affected is an unknown function of the component PROMPT Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The... Read more
- Published: May. 22, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-5073
A vulnerability, which was classified as critical, has been found in FreeFloat FTP Server 1.0. This issue affects some unknown processing of the component MKDIR Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remote... Read more
- Published: May. 22, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Memory Corruption
-
6.1
MEDIUMCVE-2024-21727
XSS vulnerability in DP Calendar component for Joomla.... Read more
Affected Products : dpcalendar- EPSS Score: %0.09
- Published: Feb. 15, 2024
- Modified: Jun. 05, 2025
-
7.7
HIGHCVE-2025-48947
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In Auth0 Next.js SDK versions 4.0.1 through 4.6.0, `__session` cookies set by auth0.middleware may be cached by CDNs due to missing Cache-Control headers. Thr... Read more
Affected Products : nextjs-auth0- Published: Jun. 04, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2025-3054
The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_files() function in all versions up to, and including, 4.1.3. This makes it possible for authenticated attackers, with ... Read more
Affected Products :- Published: Jun. 05, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Authentication
-
5.1
MEDIUMCVE-2025-48493
The Yii 2 Redis extension provides the redis key-value store support for the Yii framework 2.0. On failing connection, the extension writes commands sequence to logs. Prior to version 2.0.20, AUTH parameters are written in plain text exposing username and... Read more
Affected Products :- Published: Jun. 05, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Cryptography