Latest CVE Feed
-
8.7
HIGHCVE-2025-0064
Under specific conditions, the Central Management Console of the SAP BusinessObjects Business Intelligence platform allows an attacker with admin rights to generate or retrieve a secret passphrase, enabling them to impersonate any user in the system. This... Read more
Affected Products :- Published: Feb. 11, 2025
- Modified: Feb. 18, 2025
- Vuln Type: Authentication
-
5.4
MEDIUMCVE-2025-0054
SAP NetWeaver Application Server Java does not sufficiently handle user input, resulting in a stored cross-site scripting vulnerability. The application allows attackers with basic user privileges to store a Javascript payload on the server, which could b... Read more
Affected Products :- Published: Feb. 11, 2025
- Modified: Feb. 18, 2025
- Vuln Type: Cross-Site Scripting
-
5.5
MEDIUMCVE-2025-1164
A vulnerability, which was classified as problematic, has been found in code-projects Police FIR Record Management System 1.0. This issue affects some unknown processing of the component Add Record Handler. The manipulation leads to stack-based buffer ove... Read more
Affected Products : police_fir_record_management_system- Published: Feb. 11, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Memory Corruption
-
7.5
HIGHCVE-2025-1163
A vulnerability classified as critical was found in code-projects Vehicle Parking Management System 1.0. This vulnerability affects the function login of the component Authentication. The manipulation of the argument username leads to stack-based buffer o... Read more
Affected Products : vehicle_parking_management_system- Published: Feb. 11, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Authentication
-
4.0
MEDIUMCVE-2025-25194
Lemmy, a link aggregator and forum for the fediverse, is vulnerable to server-side request forgery via a dependency on activitypub_federation, a framework for ActivityPub federation in Rust. This vulnerability, which is present in versions 0.6.2 and prior... Read more
Affected Products : lemmy- Published: Feb. 10, 2025
- Modified: Feb. 10, 2025
- Vuln Type: Server-Side Request Forgery
-
7.5
HIGHCVE-2025-1162
A vulnerability classified as critical has been found in code-projects Job Recruitment 1.0. This affects an unknown part of the file /\_parse/load\_user-profile.php. The manipulation of the argument userhash leads to sql injection. It is possible to initi... Read more
Affected Products : job_recruitment- Published: Feb. 10, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-1160
A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file index.php. The manipulation of the argument username/password leads to use of defau... Read more
- Published: Feb. 10, 2025
- Modified: Feb. 18, 2025
- Vuln Type: Authentication
-
5.5
MEDIUMCVE-2025-25193
Netty, an asynchronous, event-driven network application framework, has a vulnerability in versions up to and including 4.1.118.Final. An unsafe reading of environment file could potentially cause a denial of service in Netty. When loaded on an Windows ap... Read more
- Published: Feb. 10, 2025
- Modified: Jun. 11, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2025-25190
The ZOO-Project is an open source processing platform. The ZOO-Project Web Processing Service (WPS) Server contains a Cross-Site Scripting (XSS) vulnerability in its EchoProcess service prior to commit 7a5ae1a. The vulnerability exists because the EchoPro... Read more
Affected Products :- Published: Feb. 10, 2025
- Modified: Feb. 11, 2025
- Vuln Type: Cross-Site Scripting
-
5.5
MEDIUMCVE-2025-25189
The ZOO-Project is an open source processing platform. A reflected Cross-Site Scripting vulnerability exists in the ZOO-Project Web Processing Service (WPS) publish.py CGI script prior to commit 7a5ae1a. The script reflects user input from the `jobid` par... Read more
Affected Products :- Published: Feb. 10, 2025
- Modified: Feb. 11, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-24970
Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final and prior to version 4.1.118.Final. When a special crafted packet is received via SslHandler it doesn't correctly handle validation of... Read more
Affected Products : netty- Published: Feb. 10, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Misconfiguration
-
5.4
MEDIUMCVE-2025-1159
A vulnerability was found in CampCodes School Management Software 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /academic-calendar. The manipulation leads to cross site scripting. The atta... Read more
Affected Products : school_management_software- Published: Feb. 10, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-1158
A vulnerability was found in ESAFENET CDG 5.6.3.154.205_20250114. It has been classified as critical. Affected is an unknown function of the file addPolicyToSafetyGroup.jsp. The manipulation of the argument safetyGroupId leads to sql injection. It is poss... Read more
Affected Products : cdg- Published: Feb. 10, 2025
- Modified: Feb. 10, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-1157
A vulnerability was found in Allims lab.online up to 20250201 and classified as critical. This issue affects some unknown processing of the file /model/model_recuperar_senha.php. The manipulation of the argument recuperacao leads to sql injection. The att... Read more
Affected Products :- Published: Feb. 10, 2025
- Modified: Feb. 10, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-1156
A vulnerability has been found in Pix Software Vivaz 6.0.10 and classified as critical. This vulnerability affects unknown code of the file /servlet?act=login. The manipulation of the argument usuario leads to sql injection. The attack can be initiated re... Read more
Affected Products :- Published: Feb. 10, 2025
- Modified: Feb. 10, 2025
- Vuln Type: Injection
-
5.7
MEDIUMCVE-2025-1002
MicroDicom DICOM Viewer version 2024.03 fails to adequately verify the update server's certificate, which could make it possible for attackers in a privileged network position to alter network traffic and carry out a machine-in-the-middle (MITM) attack. ... Read more
Affected Products : dicom_viewer- Published: Feb. 10, 2025
- Modified: Feb. 10, 2025
- Vuln Type: Misconfiguration
-
9.9
CRITICALCVE-2025-24016
Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 and prior to version 4.9.1, an unsafe deserialization vulnerability allows for remote code execution on Wazuh servers. DistributedAPI p... Read more
Affected Products : wazuh- Actively Exploited
- Published: Feb. 10, 2025
- Modified: Jun. 11, 2025
- Vuln Type: Misconfiguration
-
6.1
MEDIUMCVE-2025-1155
A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. This affects an unknown part of the file /stores of the component Your Location Search. The manipulation leads to cross site scripting. It is possible to initiate the... Read more
Affected Products : qloapps- Published: Feb. 10, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-1154
A vulnerability, which was classified as critical, has been found in xxyopen Novel up to 3.4.1. Affected by this issue is some unknown functionality of the file /api/front/search/books. The manipulation of the argument sort leads to sql injection. The att... Read more
Affected Products : novel- Published: Feb. 10, 2025
- Modified: Feb. 10, 2025
- Vuln Type: Injection
-
5.9
MEDIUMCVE-2024-57178
An SQL injection vulnerability exists in Stock-Forecaster <=01-04-2020. By sending a specially crafted 'stock-symbol' parameter to the portofolio() endpoint, it is possible to trigger an SQL injection in the application. As a result, the attacker will be ... Read more
Affected Products :- Published: Feb. 10, 2025
- Modified: Feb. 10, 2025
- Vuln Type: Injection