Latest CVE Feed
-
5.1
MEDIUMCVE-2025-2047
A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /search.php. The manipulation of the argument search leads to cross site scripting. It is possible t... Read more
Affected Products : art_gallery_management_system- Published: Mar. 06, 2025
- Modified: Apr. 03, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-27598
ImageSharp is a 2D graphics API. An Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. The problem has been pat... Read more
Affected Products : imagesharp- Published: Mar. 06, 2025
- Modified: Mar. 24, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-2046
A vulnerability was found in SourceCodester Best Employee Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/print1.php. The manipulation of the argument id leads to sql injection. The... Read more
Affected Products : best_employee_management_system- Published: Mar. 06, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Injection
-
7.2
HIGHCVE-2025-2044
A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/delete_bloodGroup.php. The manipulation of the argument blood_id l... Read more
- Published: Mar. 06, 2025
- Modified: May. 13, 2025
- Vuln Type: Injection
-
5.8
MEDIUMCVE-2025-2043
A vulnerability was found in LinZhaoguan pb-cms 1.0.0 and classified as critical. This issue affects some unknown processing of the file /admin#themes of the component Add New Topic Handler. The manipulation of the argument Topic Key leads to deserializat... Read more
Affected Products : pb-cms- Published: Mar. 06, 2025
- Modified: Mar. 06, 2025
- Vuln Type: Information Disclosure
-
5.3
MEDIUMCVE-2025-2042
A vulnerability has been found in huang-yk student-manage 1.0 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclose... Read more
Affected Products :- Published: Mar. 06, 2025
- Modified: Mar. 06, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.5
MEDIUMCVE-2025-2041
A vulnerability, which was classified as critical, has been found in s-a-zhd Ecommerce-Website-using-PHP 1.0. Affected by this issue is some unknown functionality of the file /shop.php. The manipulation of the argument p_cat leads to sql injection. The at... Read more
Affected Products :- Published: Mar. 06, 2025
- Modified: Mar. 06, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-25763
crmeb CRMEB-KY v5.4.0 and before has a SQL Injection vulnerability at getRead() in /system/SystemDatabackupServices.php... Read more
Affected Products : crmeb- Published: Mar. 06, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2024-57972
The pairing API request handler in Microsoft HoloLens 1 (Windows Holographic) through 10.0.17763.3046 and HoloLens 2 (Windows Holographic) through 10.0.22621.1244 allows remote attackers to cause a Denial of Service (resource consumption and device unusab... Read more
Affected Products :- Published: Mar. 06, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-2040
A vulnerability classified as critical was found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected by this vulnerability is an unknown functionality of the file /admin-api/bpm/model/deploy. The manipulation leads to improper neutralization of special element... Read more
- Published: Mar. 06, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Injection
-
7.2
HIGHCVE-2025-2039
A vulnerability classified as critical has been found in code-projects Blood Bank Management System 1.0. Affected is an unknown function of the file /admin/delete_members.php. The manipulation of the argument member_id leads to sql injection. It is possib... Read more
- Published: Mar. 06, 2025
- Modified: May. 13, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-2038
A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /upload/. The manipulation leads to exposure of information through directory listing. The a... Read more
- Published: Mar. 06, 2025
- Modified: May. 13, 2025
- Vuln Type: Information Disclosure
-
8.1
HIGHCVE-2025-25497
An issue in account management interface in Netsweeper Server v.8.2.6 and earlier (fixed in v.8.2.7) allows unauthorized changes to the "Account Owner" field due to client-side-only restrictions and a lack of server-side validation. This vulnerability ena... Read more
Affected Products :- Published: Mar. 06, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2025-2037
A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /user_dashboard/delete_requester.php. The manipulation of the argument requester_id leads to... Read more
- Published: Mar. 06, 2025
- Modified: May. 13, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-2036
A vulnerability was found in s-a-zhd Ecommerce-Website-using-PHP 1.0. It has been classified as critical. This affects an unknown part of the file details.php. The manipulation of the argument pro_id leads to sql injection. It is possible to initiate the ... Read more
Affected Products :- Published: Mar. 06, 2025
- Modified: Mar. 06, 2025
- Vuln Type: Injection
-
6.9
MEDIUMCVE-2025-27600
FastGPT is a knowledge-based platform built on the LLMs. Since the web crawling plug-in does not perform intranet IP verification, an attacker can initiate an intranet IP request, causing the system to initiate a request through the intranet and potential... Read more
Affected Products :- Published: Mar. 06, 2025
- Modified: Mar. 06, 2025
- Vuln Type: Server-Side Request Forgery
-
9.3
CRITICALCVE-2025-27509
fleetdm/fleet is an open source device management, built on osquery. In vulnerable versions of Fleet, an attacker could craft a specially-formed SAML response to forge authentication assertions, provision a new administrative user account if Just-In-Time ... Read more
Affected Products : fleet- Published: Mar. 06, 2025
- Modified: Mar. 06, 2025
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2025-27506
NocoDB is software for building databases as spreadsheets. The API endpoint related to the password reset function is vulnerable to Reflected Cross-Site-Scripting. The endpoint /api/v1/db/auth/password/reset/:tokenId is vulnerable to Reflected Cross-Site-... Read more
- Published: Mar. 06, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Cross-Site Scripting
-
5.0
MEDIUMCVE-2025-26699
An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-service attack when used with very long strings.... Read more
Affected Products : django- Published: Mar. 06, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2025-26167
Buffalo LS520D 4.53 is vulnerable to Arbitrary file read, which allows unauthenticated attackers to access the NAS web UI and read arbitrary internal files.... Read more
Affected Products :- Published: Mar. 06, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Information Disclosure