Latest CVE Feed
-
6.5
MEDIUMCVE-2025-0001
Abacus ERP is versions older than 2024.210.16036, 2023.205.15833, 2022.105.15542 are affected by an authenticated arbitrary file read vulnerability.... Read more
Affected Products :- Published: Feb. 17, 2025
- Modified: Feb. 17, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2025-1381
A vulnerability was found in code-projects Real Estate Property Management System 1.0. It has been classified as critical. This affects an unknown part of the file /ajax_city.php. The manipulation of the argument CityName leads to sql injection. It is pos... Read more
- Published: Feb. 17, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-1380
A vulnerability was found in Codezips Gym Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /dashboard/admin/del_plan.php. The manipulation of the argument name leads to sql injection. The a... Read more
- Published: Feb. 17, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-1379
A vulnerability has been found in code-projects Real Estate Property Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /Admin/CustomerReport.php. The manipulation of the argument city ... Read more
- Published: Feb. 17, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Injection
-
4.8
MEDIUMCVE-2025-1378
A vulnerability, which was classified as problematic, was found in radare2 5.9.9 33286. Affected is an unknown function in the library /libr/main/rasm2.c of the component rasm2. The manipulation leads to memory corruption. An attack has to be approached l... Read more
Affected Products : radare2- Published: Feb. 17, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Memory Corruption
-
6.7
MEDIUMCVE-2024-47935
Improper Validation of Integrity Check Value vulnerability in TXOne Networks StellarProtect (Legacy Mode), StellarEnforce, and Safe Lock allows an attacker to escalate their privileges in the victim’s device. The attacker needs to hijack the DLL file in a... Read more
Affected Products :- Published: Feb. 17, 2025
- Modified: Feb. 17, 2025
- Vuln Type: Authentication
-
8.6
HIGHCVE-2024-13726
The Coder WordPress plugin through 1.3.4 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection... Read more
Affected Products : themes_coder- Published: Feb. 17, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
4.7
MEDIUMCVE-2024-13627
The OWL Carousel Slider WordPress plugin through 2.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.... Read more
Affected Products : owl_carousel_slider- Published: Feb. 17, 2025
- Modified: May. 23, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2024-13626
The VR-Frases (collect & share quotes) WordPress plugin through 3.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admi... Read more
Affected Products : vr-frases- Published: Feb. 17, 2025
- Modified: May. 23, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2024-13625
The Tube Video Ads Lite WordPress plugin through 1.5.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.... Read more
Affected Products : tube_video_ads_lite- Published: Feb. 17, 2025
- Modified: May. 14, 2025
- Vuln Type: Cross-Site Scripting
-
4.7
MEDIUMCVE-2024-13608
The Track Logins WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks... Read more
Affected Products : track_logins- Published: Feb. 17, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2024-13603
The Wise Forms WordPress plugin through 1.2.0 does not sanitise and escape some of its settings, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks via malicious form submissions.... Read more
Affected Products : wise_forms- Published: Feb. 17, 2025
- Modified: May. 14, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-1389
Orca HCM from Learning Digital has a SQL Injection vulnerability, allowing attackers with regular privileges to inject arbitrary SQL commands to read, modify, and delete database contents.... Read more
Affected Products : orca_hcm- Published: Feb. 17, 2025
- Modified: Feb. 17, 2025
- Vuln Type: Injection
-
4.8
MEDIUMCVE-2025-1377
A vulnerability, which was classified as problematic, has been found in GNU elfutils 0.192. This issue affects the function gelf_getsymshndx of the file strip.c of the component eu-strip. The manipulation leads to denial of service. The attack needs to be... Read more
Affected Products :- Published: Feb. 17, 2025
- Modified: Feb. 17, 2025
- Vuln Type: Denial of Service
-
2.5
LOWCVE-2025-1376
A vulnerability classified as problematic was found in GNU elfutils 0.192. This vulnerability affects the function elf_strptr in the library /libelf/elf_strptr.c of the component eu-strip. The manipulation leads to denial of service. It is possible to lau... Read more
Affected Products :- Published: Feb. 17, 2025
- Modified: Feb. 17, 2025
- Vuln Type: Denial of Service
-
7.2
HIGHCVE-2025-0924
The WP Activity Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in all versions up to, and including, 5.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenti... Read more
Affected Products : wp_activity_log- Published: Feb. 17, 2025
- Modified: May. 23, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-1388
Orca HCM from LEARNING DIGITAL has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privileges to upload and run web shells... Read more
Affected Products : orca_hcm- Published: Feb. 17, 2025
- Modified: Feb. 17, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-1387
Orca HCM from LEARNING DIGITAL has an Improper Authentication vulnerability, allowing unauthenticated remote attackers to log in to the system as any user.... Read more
Affected Products : orca_hcm- Published: Feb. 17, 2025
- Modified: Feb. 17, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-1374
A vulnerability classified as critical has been found in code-projects Real Estate Property Management System 1.0. This affects an unknown part of the file /search.php. The manipulation of the argument StateName/CityName/AreaName/CatId leads to sql inject... Read more
- Published: Feb. 17, 2025
- Modified: Feb. 24, 2025
- Vuln Type: Injection
-
5.5
MEDIUMCVE-2025-1373
A vulnerability was found in FFmpeg up to 7.1. It has been rated as problematic. Affected by this issue is the function mov_read_trak of the file libavformat/mov.c of the component MOV Parser. The manipulation leads to null pointer dereference. Local acce... Read more
Affected Products : ffmpeg- Published: Feb. 17, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Memory Corruption