Latest CVE Feed
-
6.5
MEDIUMCVE-2025-2390
A vulnerability classified as critical has been found in code-projects Blood Bank Management System 1.0. This affects an unknown part of the file /user_dashboard/add_donor.php. The manipulation leads to sql injection. It is possible to initiate the attack... Read more
- Published: Mar. 17, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Injection
-
7.2
HIGHCVE-2025-2389
A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/add_city.php. The manipulation leads to sql injection. The attack may be la... Read more
- Published: Mar. 17, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
5.9
MEDIUMCVE-2025-29427
Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in profile.php via the member_first and member_last parameters.... Read more
- Published: Mar. 17, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Cross-Site Scripting
-
5.5
MEDIUMCVE-2025-29425
Code-projects Online Class and Exam Scheduling System 1.0 is vulnerable to SQL Injection in exam_save.php via the parameters member and first.... Read more
- Published: Mar. 17, 2025
- Modified: Mar. 25, 2025
- Vuln Type: Injection
-
6.0
MEDIUMCVE-2025-26042
Uptime Kuma >== 1.23.0 has a ReDoS vulnerability, specifically when an administrator creates a notification through the web service. If a string is provided it triggers catastrophic backtracking in the regular expression, leading to a ReDoS attack.... Read more
- Published: Mar. 17, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Denial of Service
-
5.3
MEDIUMCVE-2024-8510
N-central is vulnerable to a path traversal that allows unintended access to the Apache Tomcat WEB-INF directory. Customer data is not exposed. This vulnerability is present in all deployments of N-central prior to N-central 2024.6.... Read more
Affected Products : n-central- Published: Mar. 17, 2025
- Modified: Sep. 05, 2025
- Vuln Type: Path Traversal
-
6.8
MEDIUMCVE-2024-44866
A buffer overflow in the GuitarPro1::read function of MuseScore Studio v4.3.2 allows attackers to to execute arbitrary code or cause a Denial of Service (DoS) via opening a crafted GuitarPro file.... Read more
Affected Products :- Published: Mar. 17, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-2388
A vulnerability was found in Keytop 路内停车收费系统 2.7.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /saas/commonApi/park/getParks of the component API. The manipulation leads to improper authenticat... Read more
Affected Products :- Published: Mar. 17, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-2387
A vulnerability was found in SourceCodester Online Food Ordering System 2.0. It has been classified as critical. Affected is an unknown function of the file /admin/ajax.php?action=add_to_cart. The manipulation of the argument pid leads to sql injection. I... Read more
- Published: Mar. 17, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
4.1
MEDIUMCVE-2025-29430
Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/room.php via the id and rome parameters.... Read more
- Published: Mar. 17, 2025
- Modified: Mar. 25, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-29429
Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/program.php via the id, code, and name parameters.... Read more
- Published: Mar. 17, 2025
- Modified: Mar. 25, 2025
- Vuln Type: Cross-Site Scripting
-
7.3
HIGHCVE-2025-26125
An exposed ioctl in the IMFForceDelete driver of IObit Malware Fighter v12.1.0 allows attackers to arbitrarily delete files and escalate privileges.... Read more
Affected Products :- Published: Mar. 17, 2025
- Modified: Mar. 24, 2025
- Vuln Type: Path Traversal
-
7.8
HIGHCVE-2025-22473
Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access could potential... Read more
Affected Products : smartfabric_os10- Published: Mar. 17, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2025-22472
Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access could potential... Read more
Affected Products : smartfabric_os10- Published: Mar. 17, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2024-49561
Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation o... Read more
Affected Products : smartfabric_os10- Published: Mar. 17, 2025
- Modified: May. 08, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2024-49559
Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Use of Default Password vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized acce... Read more
Affected Products : smartfabric_os10- Published: Mar. 17, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Authentication
-
8.4
HIGHCVE-2024-48831
Dell SmartFabric OS10 Software, version(s) 10.5.6.x, contain(s) a Use of Hard-coded Password vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.... Read more
Affected Products : smartfabric_os10- Published: Mar. 17, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Authentication
-
5.5
MEDIUMCVE-2024-48828
Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized... Read more
Affected Products : smartfabric_os10- Published: Mar. 17, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2024-48017
Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged attacker with remote access could potenti... Read more
Affected Products : smartfabric_os10- Published: Mar. 17, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Injection
-
6.7
MEDIUMCVE-2024-48015
Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged attacker with local access could potentia... Read more
Affected Products : smartfabric_os10- Published: Mar. 17, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Injection