Latest CVE Feed
-
10.0
CRITICALCVE-2025-26617
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `historico_paciente.php` endpoint. This vulnerability could allow an attacker to execute... Read more
Affected Products : wegia- Published: Feb. 18, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Injection
-
10.0
CRITICALCVE-2025-26616
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Path Traversal vulnerability was discovered in the WeGIA application, `exportar_dump.php` endpoint. This vulnerability could allow an attacker to gain unauth... Read more
Affected Products : wegia- Published: Feb. 18, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Path Traversal
-
10.0
CRITICALCVE-2025-26615
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Path Traversal vulnerability was discovered in the WeGIA application, `examples.php` endpoint. This vulnerability could allow an attacker to gain unauthorize... Read more
Affected Products : wegia- Published: Feb. 18, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Path Traversal
-
9.4
CRITICALCVE-2025-26614
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `deletar_documento.php` endpoint. This vulnerability allow an authorized attacker to exe... Read more
Affected Products : wegia- Published: Feb. 18, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Injection
-
10.0
CRITICALCVE-2025-26613
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. An OS Command Injection vulnerability was discovered in the WeGIA application, `gerenciar_backup.php` endpoint. This vulnerability could allow an attacker to e... Read more
Affected Products : wegia- Published: Feb. 18, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Injection
-
10.0
CRITICALCVE-2025-26612
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `adicionar_almoxarife.php` endpoint. This vulnerability could allow an attacker to execu... Read more
Affected Products : wegia- Published: Feb. 18, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Injection
-
10.0
CRITICALCVE-2025-26611
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `remover_produto.php` endpoint. This vulnerability could allow an attacker to execute ar... Read more
Affected Products : wegia- Published: Feb. 18, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-26610
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `restaurar_produto_desocultar.php` endpoint. This vulnerability allow an authorized atta... Read more
Affected Products : wegia- Published: Feb. 18, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Injection
-
10.0
CRITICALCVE-2025-26609
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `familiar_docfamiliar.php` endpoint. This vulnerability could allow an attacker to execu... Read more
Affected Products : wegia- Published: Feb. 18, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Injection
-
10.0
CRITICALCVE-2025-26608
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `dependente_docdependente.php` endpoint. This vulnerability could allow an attacker to e... Read more
Affected Products : wegia- Published: Feb. 18, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Injection
-
10.0
CRITICALCVE-2025-26607
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `documento_excluir.php` endpoint. This vulnerability could allow an attacker to execute ... Read more
Affected Products : wegia- Published: Feb. 18, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Injection
-
10.0
CRITICALCVE-2025-26606
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `informacao_adicional.php` endpoint. This vulnerability could allow an attacker to execu... Read more
Affected Products : wegia- Published: Feb. 18, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-26605
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `deletar_cargo.php` endpoint. This vulnerability could allow an authorized attacker to e... Read more
Affected Products : wegia- Published: Feb. 18, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-27016
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in awsm.in Drivr Lite – Google Drive Plugin allows Stored XSS. This issue affects Drivr Lite – Google Drive Plugin: from n/a through 1.0.1.... Read more
Affected Products :- Published: Feb. 18, 2025
- Modified: Feb. 18, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2025-27013
Missing Authorization vulnerability in EPC MediCenter - Health Medical Clinic WordPress Theme allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MediCenter - Health Medical Clinic WordPress Theme: from n/a through ... Read more
Affected Products :- Published: Feb. 18, 2025
- Modified: Feb. 18, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2025-26623
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A heap buffer overflow was found in Exiv2 versions v0.28.0 to v0.28.4. Versions prior to v0.28.0, such as v0.27.7, are **not** affe... Read more
Affected Products : exiv2- Published: Feb. 18, 2025
- Modified: Feb. 18, 2025
- Vuln Type: Memory Corruption
-
8.3
HIGHCVE-2025-26604
Discord-Bot-Framework-Kernel is a Discord bot framework built with interactions.py, featuring modular extension management and secure execution. Because of the nature of arbitrary user-submited code execution, this allows user to execute potentially malic... Read more
Affected Products : linux_kernel- Published: Feb. 18, 2025
- Modified: Feb. 18, 2025
- Vuln Type: Authentication
-
8.6
HIGHCVE-2025-22663
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in videowhisper Paid Videochat Turnkey Site allows Path Traversal. This issue affects Paid Videochat Turnkey Site: from n/a through 7.2.12.... Read more
Affected Products :- Published: Feb. 18, 2025
- Modified: Feb. 18, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2025-22657
Missing Authorization vulnerability in Vito Peleg Atarim allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Atarim: from n/a through 4.0.9.... Read more
Affected Products : atarim- Published: Feb. 18, 2025
- Modified: Feb. 18, 2025
- Vuln Type: Authorization
-
8.1
HIGHCVE-2025-22656
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Oscar Alvarez Cookie Monster allows PHP Local File Inclusion. This issue affects Cookie Monster: from n/a through 1.2.2.... Read more
Affected Products :- Published: Feb. 18, 2025
- Modified: Feb. 18, 2025
- Vuln Type: Path Traversal