Latest CVE Feed
-
9.8
CRITICALCVE-2025-2644
A vulnerability was found in PHPGurukul Art Gallery Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/add-art-product.php. The manipulation of the argument arttype leads to sql injection. The a... Read more
Affected Products : art_gallery_management_system- Published: Mar. 23, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2643
A vulnerability has been found in PHPGurukul Art Gallery Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/edit-art-type-detail.php?editid=1. The manipulation of the argument arttype leads to sql ... Read more
Affected Products : art_gallery_management_system- Published: Mar. 23, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2642
A vulnerability, which was classified as critical, was found in PHPGurukul Art Gallery Management System 1.0. This affects an unknown part of the file /admin/edit-art-product-detail.php?editid=2. The manipulation of the argument editide/sprice/description... Read more
Affected Products : art_gallery_management_system- Published: Mar. 23, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-1446
The Pods WordPress plugin before 3.2.8.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks... Read more
Affected Products : pods- Published: Mar. 23, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Injection
-
4.8
MEDIUMCVE-2025-0718
The Nested Pages WordPress plugin before 3.2.13 does not sanitise and escape some of its settings, which could allow high privilege users such as contributors to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disal... Read more
Affected Products : nested_pages- Published: Mar. 23, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-2641
A vulnerability, which was classified as critical, has been found in PHPGurukul Art Gallery Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/edit-artist-detail.php?editid=1. The manipulation of the argument Na... Read more
Affected Products : art_gallery_management_system- Published: Mar. 23, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2640
A vulnerability was found in PHPGurukul Doctor Appointment Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /doctor/appointment-bwdates-reports-details.php. The manipulation of the argument fromdate/... Read more
- Published: Mar. 23, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2025-2639
A vulnerability has been found in JIZHICMS up to 1.7.0 and classified as problematic. This vulnerability affects unknown code of the file /user/release.html of the component Article Handler. The manipulation leads to improper authorization. The attack can... Read more
Affected Products : jizhicms- Published: Mar. 23, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2025-2638
A vulnerability, which was classified as problematic, was found in JIZHICMS up to 1.7.0. This affects an unknown part of the file /user/release.html of the component Article Handler. The manipulation of the argument ishot with the input 1 leads to imprope... Read more
Affected Products : jizhicms- Published: Mar. 23, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2025-2637
A vulnerability, which was classified as problematic, has been found in JIZHICMS up to 1.7.0. Affected by this issue is some unknown functionality of the file /user/userinfo.html of the component Account Profile Page. The manipulation of the argument jife... Read more
Affected Products : jizhicms- Published: Mar. 23, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-2628
A vulnerability, which was classified as critical, was found in PHPGurukul Art Gallery Management System 1.1. Affected is an unknown function of the file /art-enquiry.php. The manipulation of the argument eid leads to sql injection. It is possible to laun... Read more
Affected Products : art_gallery_management_system- Published: Mar. 22, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2627
A vulnerability, which was classified as critical, has been found in PHPGurukul Art Gallery Management System 1.0. This issue affects some unknown processing of the file /admin/contactus.php. The manipulation of the argument pagetitle leads to sql injecti... Read more
Affected Products : art_gallery_management_system- Published: Mar. 22, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2626
A vulnerability classified as critical was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. This vulnerability affects unknown code of the file edit_case.php. The manipulation of the argument ID leads to sql injection. The attack... Read more
Affected Products : advocate_office_management_system- Published: Mar. 22, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-2625
A vulnerability classified as critical has been found in westboy CicadasCMS 1.0. This affects an unknown part of the file /system/cms/content/page. The manipulation of the argument orderField/orderDirection leads to sql injection. It is possible to initia... Read more
Affected Products : cicadascms- Published: Mar. 22, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-2624
A vulnerability was found in westboy CicadasCMS 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /system/cms/content/save. The manipulation of the argument content/fujian/laiyuan leads to sql injection. ... Read more
Affected Products : cicadascms- Published: Mar. 22, 2025
- Modified: Mar. 26, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2025-2623
A vulnerability was found in westboy CicadasCMS 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /system/cms/content/save. The manipulation of the argument title/content/laiyuan leads to cros... Read more
Affected Products : cicadascms- Published: Mar. 22, 2025
- Modified: Mar. 26, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-2622
A vulnerability was found in aizuda snail-job 1.4.0. It has been classified as critical. Affected is the function getRuntime of the file /snail-job/workflow/check-node-expression of the component Workflow-Task Management Module. The manipulation of the ar... Read more
Affected Products : snail-job- Published: Mar. 22, 2025
- Modified: Mar. 26, 2025
- Vuln Type: Misconfiguration
-
10.0
HIGHCVE-2025-2621
A vulnerability was found in D-Link DAP-1620 1.03 and classified as critical. This issue affects the function check_dws_cookie of the file /storage. The manipulation of the argument uid leads to stack-based buffer overflow. The attack may be initiated rem... Read more
- Published: Mar. 22, 2025
- Modified: Mar. 26, 2025
- Vuln Type: Memory Corruption
-
10.0
HIGHCVE-2025-2620
A vulnerability has been found in D-Link DAP-1620 1.03 and classified as critical. This vulnerability affects the function mod_graph_auth_uri_handler of the file /storage of the component Authentication Handler. The manipulation leads to stack-based buffe... Read more
- Published: Mar. 22, 2025
- Modified: Mar. 26, 2025
- Vuln Type: Authentication
-
10.0
HIGHCVE-2025-2619
A vulnerability, which was classified as critical, was found in D-Link DAP-1620 1.03. This affects the function check_dws_cookie of the file /storage of the component Cookie Handler. The manipulation leads to stack-based buffer overflow. It is possible to... Read more
- Published: Mar. 22, 2025
- Modified: Mar. 26, 2025
- Vuln Type: Memory Corruption