Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.5

    MEDIUM
    CVE-2025-25462

    A SQL Injection vulnerability was found in /admin/add-propertytype.php in PHPGurukul Land Record System Project in PHP v1.0 allows remote attackers to execute arbitrary code via the propertytype POST request parameter.... Read more

    Affected Products : land_record_system
    • Published: Feb. 26, 2025
    • Modified: Mar. 28, 2025
    • Vuln Type: Injection
  • 8.1

    HIGH
    CVE-2024-53427

    decNumberCopy in decNumber.c in jq through 1.7.1 does not properly consider that NaN is interpreted as numeric, which has a resultant stack-based buffer overflow and out-of-bounds write, as demonstrated by use of --slurp with subtraction, such as a filter... Read more

    Affected Products : jq
    • Published: Feb. 26, 2025
    • Modified: Jul. 01, 2025
    • Vuln Type: Memory Corruption
  • 4.8

    MEDIUM
    CVE-2024-46226

    A stored cross site scripting (XSS) vulnerability in HelpDeskZ < v2.0.2 allows remote attackers to execute arbitrary JavaScript in the administration panel by including a malicious payload into the file name and upload file function when creating a new ti... Read more

    Affected Products : helpdeskz
    • Published: Feb. 26, 2025
    • Modified: Apr. 07, 2025
    • Vuln Type: Cross-Site Scripting
  • 6.8

    MEDIUM
    CVE-2025-25827

    A Server-Side Request Forgery (SSRF) in the component sort.php of Emlog Pro v2.5.4 allows attackers to scan local and internal ports via supplying a crafted URL.... Read more

    Affected Products : emlog
    • Published: Feb. 26, 2025
    • Modified: Apr. 07, 2025
    • Vuln Type: Server-Side Request Forgery
  • 7.1

    HIGH
    CVE-2025-25825

    A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Titile in the article category section.... Read more

    Affected Products : emlog
    • Published: Feb. 26, 2025
    • Modified: Apr. 07, 2025
    • Vuln Type: Cross-Site Scripting
  • 7.3

    HIGH
    CVE-2025-25823

    A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the article header at /admin/article.php.... Read more

    Affected Products : emlog
    • Published: Feb. 26, 2025
    • Modified: Apr. 07, 2025
    • Vuln Type: Cross-Site Scripting
  • 5.1

    MEDIUM
    CVE-2025-25818

    A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the postStrVar function at article_save.php.... Read more

    Affected Products : emlog
    • Published: Feb. 26, 2025
    • Modified: Apr. 07, 2025
    • Vuln Type: Cross-Site Scripting
  • 5.1

    MEDIUM
    CVE-2025-25813

    SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_files.php.... Read more

    Affected Products : seacms
    • Published: Feb. 26, 2025
    • Modified: Mar. 28, 2025
  • 5.1

    MEDIUM
    CVE-2025-25802

    SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ip.php.... Read more

    Affected Products : seacms
    • Published: Feb. 26, 2025
    • Modified: Mar. 28, 2025
  • 5.3

    MEDIUM
    CVE-2025-25800

    SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe_file.php.... Read more

    Affected Products : seacms
    • Published: Feb. 26, 2025
    • Modified: Mar. 28, 2025
    • Vuln Type: Information Disclosure
  • 6.0

    MEDIUM
    CVE-2025-25799

    SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe.php.... Read more

    Affected Products : seacms
    • Published: Feb. 26, 2025
    • Modified: Mar. 28, 2025
    • Vuln Type: Information Disclosure
  • 5.1

    MEDIUM
    CVE-2025-25797

    SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_smtp.php.... Read more

    Affected Products : seacms
    • Published: Feb. 26, 2025
    • Modified: Mar. 28, 2025
  • 5.1

    MEDIUM
    CVE-2025-25796

    SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_template.php.... Read more

    Affected Products : seacms
    • Published: Feb. 26, 2025
    • Modified: Mar. 28, 2025
  • 5.1

    MEDIUM
    CVE-2025-25794

    SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ping.php.... Read more

    Affected Products : seacms
    • Published: Feb. 26, 2025
    • Modified: Mar. 28, 2025
  • 5.1

    MEDIUM
    CVE-2025-25793

    SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_notify.php.... Read more

    Affected Products : seacms
    • Published: Feb. 26, 2025
    • Modified: Mar. 28, 2025
    • Vuln Type: Authentication
  • 4.4

    MEDIUM
    CVE-2025-25792

    SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the isopen parameter at admin_weixin.php.... Read more

    Affected Products : seacms
    • Published: Feb. 26, 2025
    • Modified: Mar. 28, 2025
    • Vuln Type: Authentication
  • 4.4

    MEDIUM
    CVE-2025-25791

    An arbitrary file upload vulnerability in the plugin installation feature of YZNCMS v2.0.1 allows attackers to execute arbitrary code via uploading a crafted Zip file.... Read more

    Affected Products : yzncms
    • Published: Feb. 26, 2025
    • Modified: Apr. 07, 2025
    • Vuln Type: Misconfiguration
  • 9.8

    CRITICAL
    CVE-2025-25790

    An arbitrary file upload vulnerability in the component \controller\LocalTemplate.php of FoxCMS v1.2.5 allows attackers to execute arbitrary code via uploading a crafted Zip file.... Read more

    Affected Products : foxcms
    • Published: Feb. 26, 2025
    • Modified: Apr. 09, 2025
    • Vuln Type: Authentication
  • 9.8

    CRITICAL
    CVE-2025-25789

    FoxCMS v1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the index() method at \controller\Sitemap.php.... Read more

    Affected Products : foxcms
    • Published: Feb. 26, 2025
    • Modified: Apr. 09, 2025
    • Vuln Type: Misconfiguration
  • 9.1

    CRITICAL
    CVE-2025-25785

    JizhiCMS v2.5.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component \c\PluginsController.php. This vulnerability allows attackers to perform an intranet scan via a crafted request.... Read more

    Affected Products : jizhicms
    • Published: Feb. 26, 2025
    • Modified: Apr. 10, 2025
    • Vuln Type: Server-Side Request Forgery
Showing 20 of 291777 Results