Latest CVE Feed
-
6.5
MEDIUMCVE-2025-8697
A vulnerability was found in agentUniverse up to 0.0.18 and classified as critical. This issue affects the function StdioServerParameters of the component MCPSessionManager/MCPTool/MCPToolkit. The manipulation leads to os command injection. The attack may... Read more
Affected Products :- Published: Aug. 07, 2025
- Modified: Aug. 07, 2025
-
5.2
MEDIUMCVE-2025-7195
Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK before 0.15.2 provided a script, user_setup, which modifies the permissions of the /etc/passwd file to 664 ... Read more
Affected Products :- Published: Aug. 07, 2025
- Modified: Aug. 08, 2025
-
7.4
HIGHCVE-2025-55077
Tyler Technologies ERP Pro 9 SaaS allows an authenticated user to escape the application and execute limited operating system commands within the remote Microsoft Windows environment with the privileges of the authenticated user. Tyler Technologies deploy... Read more
Affected Products :- Published: Aug. 07, 2025
- Modified: Aug. 07, 2025
-
5.3
MEDIUMCVE-2025-51533
An Insecure Direct Object Reference (IDOR) in Sage DPW v2024_12_004 and below allows unauthorized attackers to access internal forms via sending a crafted GET request.... Read more
Affected Products :- Published: Aug. 07, 2025
- Modified: Aug. 07, 2025
-
9.8
CRITICALCVE-2025-50692
FoxCMS <=v1.2.5 is vulnerable to Code Execution in admin/template_file/editFile.html.... Read more
Affected Products : foxcms- Published: Aug. 07, 2025
- Modified: Aug. 14, 2025
-
7.8
HIGHCVE-2025-50675
GPMAW 14, a bioinformatics software, has a critical vulnerability related to insecure file permissions in its installation directory. The directory is accessible with full read, write, and execute permissions for all users, allowing unprivileged users to ... Read more
Affected Products :- Published: Aug. 07, 2025
- Modified: Aug. 08, 2025
-
8.8
HIGHCVE-2025-51629
A cross-site scripting (XSS) vulnerability in the PdfViewer component of Agenzia Impresa Eccobook 2.81.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Temp parameter.... Read more
Affected Products :- Published: Aug. 07, 2025
- Modified: Aug. 07, 2025
-
8.8
HIGHCVE-2023-41532
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the doctor_contact parameter in doctorsearch.php.... Read more
Affected Products : hospital_management_system- Published: Aug. 07, 2025
- Modified: Aug. 11, 2025
-
8.8
HIGHCVE-2023-41531
Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func3.php via the username1 and password2 parameters.... Read more
Affected Products : hospital_management_system- Published: Aug. 07, 2025
- Modified: Aug. 11, 2025
-
9.8
CRITICALCVE-2023-41530
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the app_contact parameter in appsearch.php.... Read more
Affected Products : hospital_management_system- Published: Aug. 07, 2025
- Modified: Aug. 11, 2025
-
6.1
MEDIUMCVE-2023-41529
Hospital Management System v4 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in func2.php via the fname and lname parameters.... Read more
Affected Products : hospital_management_system- Published: Aug. 07, 2025
- Modified: Aug. 11, 2025
-
9.8
CRITICALCVE-2023-41528
Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in contact.php via the txtname, txtphone, and txtmail parameters.... Read more
Affected Products : hospital_management_system- Published: Aug. 07, 2025
- Modified: Aug. 11, 2025
-
9.8
CRITICALCVE-2023-41527
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the password2 parameter in func.php.... Read more
Affected Products : hospital_management_system- Published: Aug. 07, 2025
- Modified: Aug. 11, 2025
-
9.8
CRITICALCVE-2023-41526
Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func1.php via the username3 and password3 parameters.... Read more
Affected Products : hospital_management_system- Published: Aug. 07, 2025
- Modified: Aug. 11, 2025
-
9.8
CRITICALCVE-2023-41525
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the patient_contact parameter in patientsearch.php.... Read more
Affected Products : hospital_management_system- Published: Aug. 07, 2025
- Modified: Aug. 11, 2025
-
8.8
HIGHCVE-2023-41524
Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the username parameter at index.php.... Read more
Affected Products : student_attendance_management_system- Published: Aug. 07, 2025
- Modified: Aug. 13, 2025
-
8.8
HIGHCVE-2023-41523
Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the emailAddress parameter at createClassTeacher.php.... Read more
Affected Products : student_attendance_management_system- Published: Aug. 07, 2025
- Modified: Aug. 13, 2025
-
8.8
HIGHCVE-2023-41522
Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createStudents.php via the Id, firstname, and admissionNumber parameters.... Read more
Affected Products : student_attendance_management_system- Published: Aug. 07, 2025
- Modified: Aug. 13, 2025
-
8.8
HIGHCVE-2023-41521
Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createSessionTerm.php via the id, termId, and sessionName parameters.... Read more
Affected Products : student_attendance_management_system- Published: Aug. 07, 2025
- Modified: Aug. 13, 2025
-
8.8
HIGHCVE-2023-41520
Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createClassArms.php via the classId and classArmName parameters.... Read more
Affected Products : student_attendance_management_system- Published: Aug. 07, 2025
- Modified: Aug. 13, 2025