Latest CVE Feed
-
6.1
MEDIUMCVE-2025-1467
Versions of the package tarteaucitronjs before 1.17.0 are vulnerable to Cross-site Scripting (XSS) via the getElemWidth() and getElemHeight(). This is related to [SNYK-JS-TARTEAUCITRONJS-8366541](https://security.snyk.io/vuln/SNYK-JS-TARTEAUCITRONJS-83665... Read more
Affected Products :- Published: Feb. 23, 2025
- Modified: Feb. 23, 2025
- Vuln Type: Cross-Site Scripting
-
7.8
HIGHCVE-2025-1587
A vulnerability was found in SourceCodester Telecom Billing Management System 1.0. It has been rated as critical. This issue affects the function addrecords of the file main.cpp of the component Add New Record. The manipulation of the argument name/phonen... Read more
Affected Products : telecom_billing_management_system- Published: Feb. 23, 2025
- Modified: May. 14, 2025
- Vuln Type: Memory Corruption
-
6.1
MEDIUMCVE-2025-1586
A vulnerability was found in code-projects Blood Bank System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /Blood/A-.php. The manipulation of the argument Bloodname leads to cross site scripting. The attack ... Read more
- Published: Feb. 23, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-1585
A vulnerability, which was classified as problematic, has been found in otale tale up to 2.0.5. This issue affects the function OptionsService of the file src/main/resources/templates/themes/default/partial/header.html. The manipulation of the argument lo... Read more
Affected Products :- Published: Feb. 23, 2025
- Modified: Feb. 23, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2025-1584
A vulnerability classified as problematic was found in opensolon Solon up to 3.0.8. This vulnerability affects unknown code of the file solon-projects/solon-web/solon-web-staticfiles/src/main/java/org/noear/solon/web/staticfiles/StaticMappings.java. The m... Read more
Affected Products :- Published: Feb. 23, 2025
- Modified: Feb. 23, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-1583
A vulnerability classified as critical has been found in PHPGurukul Online Nurse Hiring System 1.0. This affects an unknown part of the file /admin/search-report-details.php. The manipulation of the argument searchinput leads to sql injection. It is possi... Read more
Affected Products : online_nurse_hiring_system- Published: Feb. 23, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-1582
A vulnerability was found in PHPGurukul Online Nurse Hiring System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/all-request.php. The manipulation of the argument viewid leads to sql injection.... Read more
Affected Products : online_nurse_hiring_system- Published: Feb. 23, 2025
- Modified: Feb. 23, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-1581
A vulnerability was found in PHPGurukul Online Nurse Hiring System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /book-nurse.php?bookid=1. The manipulation of the argument contactname leads t... Read more
Affected Products : online_nurse_hiring_system- Published: Feb. 23, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-1580
A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /search-report-result.php. The manipulation of the argument searchdata leads to sql injectio... Read more
Affected Products : nipah_virus_testing_management_system- Published: Feb. 23, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-1579
A vulnerability was found in code-projects Blood Bank System 1.0 and classified as problematic. This issue affects some unknown processing of the file /admin/user.php. The manipulation of the argument email leads to cross site scripting. The attack may be... Read more
- Published: Feb. 23, 2025
- Modified: Feb. 23, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-1578
A vulnerability, which was classified as critical, was found in PHPGurukul/Campcodes Online Shopping Portal 2.1. This affects an unknown part of the file /search-result.php. The manipulation of the argument Product leads to sql injection. It is possible t... Read more
- Published: Feb. 23, 2025
- Modified: May. 16, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2025-1577
A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank System 1.0. Affected by this issue is some unknown functionality of the file /prostatus.php. The manipulation of the argument message leads to cross site scri... Read more
- Published: Feb. 23, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-13728
The Accept Donations with PayPal & Stripe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the rf parameter in all versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping. This makes it possi... Read more
Affected Products : accept_donations_with_paypal- Published: Feb. 23, 2025
- Modified: Feb. 23, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-1576
A vulnerability classified as critical was found in code-projects Real Estate Property Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax_state.php. The manipulation of the argument StateName as part of Str... Read more
- Published: Feb. 23, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2025-1575
A vulnerability classified as problematic has been found in Harpia DiagSystem 12. Affected is an unknown function of the file /diagsystem/PACS/atualatendimento_jpeg.php. The manipulation of the argument cod/codexame leads to improper control of resource i... Read more
Affected Products :- Published: Feb. 23, 2025
- Modified: Feb. 23, 2025
- Vuln Type: Path Traversal
-
7.8
HIGHCVE-2022-28339
Trend Micro HouseCall for Home Networks version 5.3.1302 and below contains an uncontrolled search patch element vulnerability that could allow an attacker with low user privileges to create a malicious DLL that could lead to escalated privileges.... Read more
- Published: Feb. 22, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2025-27012
Cross-Site Request Forgery (CSRF) vulnerability in a1post A1POST.BG Shipping for Woo allows Privilege Escalation. This issue affects A1POST.BG Shipping for Woo: from n/a through 1.5.1.... Read more
Affected Products :- Published: Feb. 22, 2025
- Modified: Feb. 22, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.5
MEDIUMCVE-2025-26973
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WarfarePlugins Social Warfare allows DOM-Based XSS. This issue affects Social Warfare: from n/a through 4.5.4.... Read more
Affected Products : social_warfare- Published: Feb. 22, 2025
- Modified: Feb. 22, 2025
- Vuln Type: Cross-Site Scripting
-
10.0
CRITICALCVE-2025-26776
Unrestricted Upload of File with Dangerous Type vulnerability in NotFound Chaty Pro allows Upload a Web Shell to a Web Server. This issue affects Chaty Pro: from n/a through 3.3.3.... Read more
Affected Products :- Published: Feb. 22, 2025
- Modified: Feb. 22, 2025
- Vuln Type: Misconfiguration
-
7.1
HIGHCVE-2025-26774
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rock Solid Responsive Modal Builder for High Conversion – Easy Popups allows Reflected XSS. This issue affects Responsive Modal Builder for High Conversi... Read more
Affected Products :- Published: Feb. 22, 2025
- Modified: Feb. 22, 2025
- Vuln Type: Cross-Site Scripting