Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.3

    MEDIUM
    CVE-2025-2653

    A vulnerability was found in FoxCMS 1.25 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the publ... Read more

    Affected Products : foxcms
    • Published: Mar. 23, 2025
    • Modified: Jul. 16, 2025
    • Vuln Type: Authorization
  • 5.0

    MEDIUM
    CVE-2025-30474

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Commons VFS. The FtpFileObject class can throw an exception when a file is not found, revealing the original URI in its message, which may include a password. The fix is t... Read more

    Affected Products : commons_vfs
    • Published: Mar. 23, 2025
    • Modified: Jul. 14, 2025
    • Vuln Type: Information Disclosure
  • 9.1

    CRITICAL
    CVE-2025-2691

    Versions of the package nossrf before 1.0.4 are vulnerable to Server-Side Request Forgery (SSRF) where an attacker can provide a hostname that resolves to a local or reserved IP address space and bypass the SSRF protection mechanism.... Read more

    Affected Products : nossrf
    • Published: Mar. 23, 2025
    • Modified: Mar. 26, 2025
    • Vuln Type: Server-Side Request Forgery
  • 7.5

    HIGH
    CVE-2025-2652

    A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to exposure of information through directo... Read more

    • Published: Mar. 23, 2025
    • Modified: Mar. 26, 2025
    • Vuln Type: Information Disclosure
  • 6.9

    MEDIUM
    CVE-2025-2651

    A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /oews/admin/. The manipulation leads to exposure of information through directory listing. It is possibl... Read more

    Affected Products : online_eyewear_shop
    • Published: Mar. 23, 2025
    • Modified: May. 14, 2025
    • Vuln Type: Information Disclosure
  • 7.5

    HIGH
    CVE-2025-27553

    Relative Path Traversal vulnerability in Apache Commons VFS before 2.10.0. The FileObject API in Commons VFS has a 'resolveFile' method that takes a 'scope' parameter. Specifying 'NameScope.DESCENDENT' promises that "an exception is thrown if the resolve... Read more

    Affected Products : commons_vfs
    • Published: Mar. 23, 2025
    • Modified: Apr. 02, 2025
    • Vuln Type: Path Traversal
  • 6.1

    MEDIUM
    CVE-2025-2650

    A vulnerability, which was classified as problematic, has been found in PHPGurukul Medical Card Generation System 1.0. This issue affects some unknown processing of the file /download-medical-cards.php. The manipulation of the argument searchdata leads to... Read more

    Affected Products : medical_card_generation_system
    • Published: Mar. 23, 2025
    • Modified: Mar. 27, 2025
    • Vuln Type: Cross-Site Scripting
  • 9.8

    CRITICAL
    CVE-2025-2649

    A vulnerability classified as critical was found in PHPGurukul Doctor Appointment Management System 1.0. This vulnerability affects unknown code of the file /check-appointment.php. The manipulation of the argument searchdata leads to sql injection. The at... Read more

    • Published: Mar. 23, 2025
    • Modified: Mar. 27, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-2648

    A vulnerability classified as critical has been found in PHPGurukul Art Gallery Management System 1.0. This affects an unknown part of the file /admin/view-enquiry-detail.php. The manipulation of the argument viewid leads to sql injection. It is possible ... Read more

    Affected Products : art_gallery_management_system
    • Published: Mar. 23, 2025
    • Modified: Mar. 27, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-2647

    A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /search.php. The manipulation of the argument Search leads to sql injection. The att... Read more

    Affected Products : art_gallery_management_system
    • Published: Mar. 23, 2025
    • Modified: Mar. 27, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-2646

    A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/admin-profile.php. The manipulation of the argument contactnumber le... Read more

    Affected Products : art_gallery_management_system
    • Published: Mar. 23, 2025
    • Modified: Apr. 02, 2025
    • Vuln Type: Injection
  • 6.1

    MEDIUM
    CVE-2025-2645

    A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file /product.php. The manipulation of the argument artname leads to cross site scripting. It is possi... Read more

    Affected Products : art_gallery_management_system
    • Published: Mar. 23, 2025
    • Modified: Apr. 02, 2025
    • Vuln Type: Cross-Site Scripting
  • 9.8

    CRITICAL
    CVE-2025-2644

    A vulnerability was found in PHPGurukul Art Gallery Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/add-art-product.php. The manipulation of the argument arttype leads to sql injection. The a... Read more

    Affected Products : art_gallery_management_system
    • Published: Mar. 23, 2025
    • Modified: Apr. 02, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-2643

    A vulnerability has been found in PHPGurukul Art Gallery Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/edit-art-type-detail.php?editid=1. The manipulation of the argument arttype leads to sql ... Read more

    Affected Products : art_gallery_management_system
    • Published: Mar. 23, 2025
    • Modified: Apr. 02, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-2642

    A vulnerability, which was classified as critical, was found in PHPGurukul Art Gallery Management System 1.0. This affects an unknown part of the file /admin/edit-art-product-detail.php?editid=2. The manipulation of the argument editide/sprice/description... Read more

    Affected Products : art_gallery_management_system
    • Published: Mar. 23, 2025
    • Modified: Apr. 02, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-1446

    The Pods WordPress plugin before 3.2.8.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks... Read more

    Affected Products : pods
    • Published: Mar. 23, 2025
    • Modified: Apr. 02, 2025
    • Vuln Type: Injection
  • 4.8

    MEDIUM
    CVE-2025-0718

    The Nested Pages WordPress plugin before 3.2.13 does not sanitise and escape some of its settings, which could allow high privilege users such as contributors to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disal... Read more

    Affected Products : nested_pages
    • Published: Mar. 23, 2025
    • Modified: Apr. 02, 2025
    • Vuln Type: Cross-Site Scripting
  • 9.8

    CRITICAL
    CVE-2025-2641

    A vulnerability, which was classified as critical, has been found in PHPGurukul Art Gallery Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/edit-artist-detail.php?editid=1. The manipulation of the argument Na... Read more

    Affected Products : art_gallery_management_system
    • Published: Mar. 23, 2025
    • Modified: Apr. 02, 2025
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-2640

    A vulnerability was found in PHPGurukul Doctor Appointment Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /doctor/appointment-bwdates-reports-details.php. The manipulation of the argument fromdate/... Read more

    • Published: Mar. 23, 2025
    • Modified: Apr. 02, 2025
    • Vuln Type: Injection
  • 5.3

    MEDIUM
    CVE-2025-2639

    A vulnerability has been found in JIZHICMS up to 1.7.0 and classified as problematic. This vulnerability affects unknown code of the file /user/release.html of the component Article Handler. The manipulation leads to improper authorization. The attack can... Read more

    Affected Products : jizhicms
    • Published: Mar. 23, 2025
    • Modified: Mar. 28, 2025
    • Vuln Type: Authorization
Showing 20 of 291728 Results