Latest CVE Feed
-
5.4
MEDIUMCVE-2025-30143
Rule 3000216 (before version 2) in Akamai App & API Protector (with Akamai ASE) before 2024-12-10 does not properly consider JavaScript variable assignment to built-in functions and properties.... Read more
Affected Products :- Published: Mar. 17, 2025
- Modified: Mar. 17, 2025
-
7.5
HIGHCVE-2025-2384
A vulnerability, which was classified as critical, was found in code-projects Real Estate Property Management System 1.0. This affects an unknown part of the file /InsertCustomer.php of the component Parameter Handler. The manipulation of the argument txt... Read more
Affected Products : real_estate_property_management_system- Published: Mar. 17, 2025
- Modified: Mar. 25, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2383
A vulnerability, which was classified as critical, has been found in PHPGurukul Doctor Appointment Management System 1.0. Affected by this issue is some unknown functionality of the file /doctor/search.php. The manipulation of the argument searchdata lead... Read more
- Published: Mar. 17, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2382
A vulnerability classified as critical was found in PHPGurukul Online Banquet Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/booking-search.php. The manipulation of the argument searchdata leads to sql in... Read more
Affected Products : online_banquet_booking_system- Published: Mar. 17, 2025
- Modified: May. 26, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2381
A vulnerability classified as critical has been found in PHPGurukul Curfew e-Pass Management System 1.0. Affected is an unknown function of the file /admin/search-pass.php. The manipulation of the argument searchdata leads to sql injection. It is possible... Read more
Affected Products : curfew_e-pass_management_system- Published: Mar. 17, 2025
- Modified: May. 06, 2025
- Vuln Type: Injection
-
2.1
LOWCVE-2025-27512
Zincati is an auto-update agent for Fedora CoreOS hosts. Zincati ships a polkit rule which allows the `zincati` system user to use the actions `org.projectatomic.rpmostree1.deploy` to deploy updates to the system and `org.projectatomic.rpmostree1.finalize... Read more
Affected Products :- Published: Mar. 17, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Authorization
-
5.0
MEDIUMCVE-2025-26127
A stored cross-site scripting (XSS) vulnerability in the Send for Approval function of FileCloud v23.241.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products :- Published: Mar. 17, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Cross-Site Scripting
-
9.1
CRITICALCVE-2025-25650
An issue in the storage of NFC card data in Dorset DG 201 Digital Lock H5_433WBSK_v2.2_220605 allows attackers to produce cloned NFC cards to bypass authentication.... Read more
Affected Products :- Published: Mar. 17, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Authentication
-
4.3
MEDIUMCVE-2025-25621
Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows teachers to take attendance of fellow teachers. This affected endpoint is /courses/teacher/index?teacher_id=2&semester_id=1.... Read more
Affected Products : unifiedtransform- Published: Mar. 17, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Authorization
-
3.3
LOWCVE-2025-25618
Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation allowing the change of Section Name and Room Number by Teachers.... Read more
Affected Products : unifiedtransform- Published: Mar. 17, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Authorization
-
7.1
HIGHCVE-2025-25612
FS Inc S3150-8T2F prior to version S3150-8T2F_2.2.0D_135103 is vulnerable to Cross Site Scripting (XSS) in the Time Range Configuration functionality of the administration interface. An attacker can inject malicious JavaScript into the "Time Range Name" f... Read more
Affected Products :- Published: Mar. 17, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Cross-Site Scripting
-
6.3
MEDIUMCVE-2025-1774
Incorrect string encoding vulnerability in NASK - PIB BotSense allows injection of an additional field separator character or value in the content of some fields of the generated event. A field with additional field separator characters or values can be i... Read more
Affected Products :- Published: Mar. 17, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Injection
-
3.3
LOWCVE-2025-1398
Mattermost Desktop App versions <=5.10.0 explicitly declared unnecessary macOS entitlements which allows an attacker with remote access to bypass Transparency, Consent, and Control (TCC) via code injection.... Read more
- Published: Mar. 17, 2025
- Modified: Mar. 31, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-2380
A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin-profile.php. The manipulation of the argument mobilenumber leads to sql injectio... Read more
Affected Products : apartment_visitors_management_system- Published: Mar. 17, 2025
- Modified: May. 06, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2379
A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /create-pass.php. The manipulation of the argument visname leads to sql injection. The ... Read more
Affected Products : apartment_visitors_management_system- Published: Mar. 17, 2025
- Modified: May. 06, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-29788
The Syliud PayPal Plugin is the Sylius Core Team’s plugin for the PayPal Commerce Platform. A vulnerability in versions prior to 1.6.1, 1.7.1, and 2.0.1 allows users to manipulate the final payment amount processed by PayPal. If a user modifies the item q... Read more
Affected Products : sylius- Published: Mar. 17, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Authorization
-
7.3
HIGHCVE-2025-29787
`zip` is a zip library for rust which supports reading and writing of simple ZIP files. In the archive extraction routine of affected versions of the `zip` crate starting with version 1.3.0 and prior to version 2.3.0, symbolic links earlier in the archive... Read more
Affected Products : zip- Published: Mar. 17, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2025-29786
Expr is an expression language and expression evaluation for Go. Prior to version 1.17.0, if the Expr expression parser is given an unbounded input string, it will attempt to compile the entire string and generate an Abstract Syntax Tree (AST) node for ea... Read more
Affected Products :- Published: Mar. 17, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Denial of Service
-
5.4
MEDIUMCVE-2025-27102
Agate is central authentication server software for OBiBa epidemiology applications. Prior to version 3.3.0, when registering for an Agate account, arbitrary HTML code can be injected into a user's first and last name. This HTML is then rendered in the em... Read more
Affected Products :- Published: Mar. 17, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Cross-Site Scripting
-
8.7
HIGHCVE-2025-0833
A stored Cross-site Scripting (XSS) vulnerability affecting Route Management in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's brow... Read more
Affected Products : 3dexperience- Published: Mar. 17, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Cross-Site Scripting