Latest CVE Feed
-
9.8
CRITICALCVE-2025-2660
A vulnerability has been found in Project Worlds Online Time Table Generator 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/index.php. The manipulation of the argument e leads to sql injection. The attack can be... Read more
Affected Products : online_time_table_generator- Published: Mar. 23, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2659
A vulnerability, which was classified as critical, was found in Project Worlds Online Time Table Generator 1.0. This affects an unknown part of the file /student/index.php. The manipulation of the argument e leads to sql injection. It is possible to initi... Read more
Affected Products : online_time_table_generator- Published: Mar. 23, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2658
A vulnerability, which was classified as critical, has been found in PHPGurukul Online Security Guards Hiring System 1.0. Affected by this issue is some unknown functionality of the file /search-request.php. The manipulation of the argument searchdata lea... Read more
- Published: Mar. 23, 2025
- Modified: May. 13, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2657
A vulnerability classified as critical was found in projectworlds Apartment Visitors Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /front.php. The manipulation of the argument rid leads to sql injection. The... Read more
Affected Products : apartment_visitors_management_system- Published: Mar. 23, 2025
- Modified: May. 13, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2656
A vulnerability classified as critical has been found in PHPGurukul Zoo Management System 2.1. Affected is an unknown function of the file /admin/login.php. The manipulation of the argument Username leads to sql injection. It is possible to launch the att... Read more
Affected Products : zoo_management_system- Published: Mar. 23, 2025
- Modified: May. 13, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2655
A vulnerability was found in SourceCodester AC Repair and Services System 1.0. It has been declared as critical. This vulnerability affects the function save_users of the file /classes/Users.php. The manipulation of the argument ID leads to sql injection.... Read more
Affected Products : ac_repair_and_services_system- Published: Mar. 23, 2025
- Modified: May. 13, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-29806
No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.... Read more
Affected Products : edge_chromium- Published: Mar. 23, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Authentication
-
7.8
HIGHCVE-2025-29795
Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.... Read more
- Published: Mar. 23, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-2654
A vulnerability was found in SourceCodester AC Repair and Services System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/services/manage_service.php. The manipulation of the argument ID leads to sql injection. It ... Read more
Affected Products : ac_repair_and_services_system- Published: Mar. 23, 2025
- Modified: Mar. 26, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2025-2653
A vulnerability was found in FoxCMS 1.25 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the publ... Read more
Affected Products : foxcms- Published: Mar. 23, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Authorization
-
5.0
MEDIUMCVE-2025-30474
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Commons VFS. The FtpFileObject class can throw an exception when a file is not found, revealing the original URI in its message, which may include a password. The fix is t... Read more
Affected Products : commons_vfs- Published: Mar. 23, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Information Disclosure
-
9.1
CRITICALCVE-2025-2691
Versions of the package nossrf before 1.0.4 are vulnerable to Server-Side Request Forgery (SSRF) where an attacker can provide a hostname that resolves to a local or reserved IP address space and bypass the SSRF protection mechanism.... Read more
Affected Products : nossrf- Published: Mar. 23, 2025
- Modified: Mar. 26, 2025
- Vuln Type: Server-Side Request Forgery
-
7.5
HIGHCVE-2025-2652
A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to exposure of information through directo... Read more
Affected Products : employee_and_visitor_gate_pass_logging_system- Published: Mar. 23, 2025
- Modified: Mar. 26, 2025
- Vuln Type: Information Disclosure
-
6.9
MEDIUMCVE-2025-2651
A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /oews/admin/. The manipulation leads to exposure of information through directory listing. It is possibl... Read more
Affected Products : online_eyewear_shop- Published: Mar. 23, 2025
- Modified: May. 14, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2025-27553
Relative Path Traversal vulnerability in Apache Commons VFS before 2.10.0. The FileObject API in Commons VFS has a 'resolveFile' method that takes a 'scope' parameter. Specifying 'NameScope.DESCENDENT' promises that "an exception is thrown if the resolve... Read more
Affected Products : commons_vfs- Published: Mar. 23, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Path Traversal
-
6.1
MEDIUMCVE-2025-2650
A vulnerability, which was classified as problematic, has been found in PHPGurukul Medical Card Generation System 1.0. This issue affects some unknown processing of the file /download-medical-cards.php. The manipulation of the argument searchdata leads to... Read more
Affected Products : medical_card_generation_system- Published: Mar. 23, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-2649
A vulnerability classified as critical was found in PHPGurukul Doctor Appointment Management System 1.0. This vulnerability affects unknown code of the file /check-appointment.php. The manipulation of the argument searchdata leads to sql injection. The at... Read more
- Published: Mar. 23, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2648
A vulnerability classified as critical has been found in PHPGurukul Art Gallery Management System 1.0. This affects an unknown part of the file /admin/view-enquiry-detail.php. The manipulation of the argument viewid leads to sql injection. It is possible ... Read more
Affected Products : art_gallery_management_system- Published: Mar. 23, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2647
A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /search.php. The manipulation of the argument Search leads to sql injection. The att... Read more
Affected Products : art_gallery_management_system- Published: Mar. 23, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2646
A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/admin-profile.php. The manipulation of the argument contactnumber le... Read more
Affected Products : art_gallery_management_system- Published: Mar. 23, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Injection