Latest CVE Feed
-
5.5
MEDIUMCVE-2025-25462
A SQL Injection vulnerability was found in /admin/add-propertytype.php in PHPGurukul Land Record System Project in PHP v1.0 allows remote attackers to execute arbitrary code via the propertytype POST request parameter.... Read more
Affected Products : land_record_system- Published: Feb. 26, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Injection
-
8.1
HIGHCVE-2024-53427
decNumberCopy in decNumber.c in jq through 1.7.1 does not properly consider that NaN is interpreted as numeric, which has a resultant stack-based buffer overflow and out-of-bounds write, as demonstrated by use of --slurp with subtraction, such as a filter... Read more
Affected Products : jq- Published: Feb. 26, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Memory Corruption
-
4.8
MEDIUMCVE-2024-46226
A stored cross site scripting (XSS) vulnerability in HelpDeskZ < v2.0.2 allows remote attackers to execute arbitrary JavaScript in the administration panel by including a malicious payload into the file name and upload file function when creating a new ti... Read more
Affected Products : helpdeskz- Published: Feb. 26, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Cross-Site Scripting
-
6.8
MEDIUMCVE-2025-25827
A Server-Side Request Forgery (SSRF) in the component sort.php of Emlog Pro v2.5.4 allows attackers to scan local and internal ports via supplying a crafted URL.... Read more
Affected Products : emlog- Published: Feb. 26, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Server-Side Request Forgery
-
7.1
HIGHCVE-2025-25825
A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Titile in the article category section.... Read more
Affected Products : emlog- Published: Feb. 26, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Cross-Site Scripting
-
7.3
HIGHCVE-2025-25823
A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the article header at /admin/article.php.... Read more
Affected Products : emlog- Published: Feb. 26, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Cross-Site Scripting
-
5.1
MEDIUMCVE-2025-25818
A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the postStrVar function at article_save.php.... Read more
Affected Products : emlog- Published: Feb. 26, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Cross-Site Scripting
-
5.1
MEDIUMCVE-2025-25813
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_files.php.... Read more
Affected Products : seacms- Published: Feb. 26, 2025
- Modified: Mar. 28, 2025
-
5.1
MEDIUMCVE-2025-25802
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ip.php.... Read more
Affected Products : seacms- Published: Feb. 26, 2025
- Modified: Mar. 28, 2025
-
5.3
MEDIUMCVE-2025-25800
SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe_file.php.... Read more
Affected Products : seacms- Published: Feb. 26, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Information Disclosure
-
6.0
MEDIUMCVE-2025-25799
SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe.php.... Read more
Affected Products : seacms- Published: Feb. 26, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Information Disclosure
-
5.1
MEDIUMCVE-2025-25797
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_smtp.php.... Read more
Affected Products : seacms- Published: Feb. 26, 2025
- Modified: Mar. 28, 2025
-
5.1
MEDIUMCVE-2025-25796
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_template.php.... Read more
Affected Products : seacms- Published: Feb. 26, 2025
- Modified: Mar. 28, 2025
-
5.1
MEDIUMCVE-2025-25794
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ping.php.... Read more
Affected Products : seacms- Published: Feb. 26, 2025
- Modified: Mar. 28, 2025
-
5.1
MEDIUMCVE-2025-25793
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_notify.php.... Read more
Affected Products : seacms- Published: Feb. 26, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Authentication
-
4.4
MEDIUMCVE-2025-25792
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the isopen parameter at admin_weixin.php.... Read more
Affected Products : seacms- Published: Feb. 26, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Authentication
-
4.4
MEDIUMCVE-2025-25791
An arbitrary file upload vulnerability in the plugin installation feature of YZNCMS v2.0.1 allows attackers to execute arbitrary code via uploading a crafted Zip file.... Read more
Affected Products : yzncms- Published: Feb. 26, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-25790
An arbitrary file upload vulnerability in the component \controller\LocalTemplate.php of FoxCMS v1.2.5 allows attackers to execute arbitrary code via uploading a crafted Zip file.... Read more
Affected Products : foxcms- Published: Feb. 26, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-25789
FoxCMS v1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the index() method at \controller\Sitemap.php.... Read more
Affected Products : foxcms- Published: Feb. 26, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Misconfiguration
-
9.1
CRITICALCVE-2025-25785
JizhiCMS v2.5.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component \c\PluginsController.php. This vulnerability allows attackers to perform an intranet scan via a crafted request.... Read more
Affected Products : jizhicms- Published: Feb. 26, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Server-Side Request Forgery