Latest CVE Feed
-
4.3
MEDIUMCVE-2023-50738
A new feature to prevent Firmware downgrades was recently added to some Lexmark products. A method to override this downgrade protection has been identified.... Read more
Affected Products :- Published: Jan. 17, 2025
- Modified: Jan. 17, 2025
- Vuln Type: Authorization
-
7.4
HIGHCVE-2025-21399
Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability... Read more
- Published: Jan. 17, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-21185
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability... Read more
Affected Products : edge_chromium- Published: Jan. 17, 2025
- Modified: Feb. 07, 2025
-
5.1
MEDIUMCVE-2025-0537
A vulnerability, which was classified as problematic, has been found in code-projects Car Rental Management System 1.0. This issue affects some unknown processing of the file /admin/manage-pages.php. The manipulation of the argument pgdetails leads to cro... Read more
Affected Products : online_car_rental_system- Published: Jan. 17, 2025
- Modified: Feb. 21, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-0536
A vulnerability classified as critical was found in 1000 Projects Attendance Tracking Management System 1.0. This vulnerability affects unknown code of the file /admin/edit_action.php. The manipulation of the argument attendance_id leads to sql injection.... Read more
Affected Products : attendance_tracking_management_system- Published: Jan. 17, 2025
- Modified: Feb. 25, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2024-57372
Cross Site Scripting vulnerability in InformationPush master version allows a remote attacker to obtain sensitive information via the title, time and msg parameters... Read more
Affected Products :- Published: Jan. 17, 2025
- Modified: Jan. 17, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-57370
Cross Site Scripting vulnerability in sunnygkp10 Online Exam System master version allows a remote attacker to obtain sensitive information via the w parameter.... Read more
Affected Products :- Published: Jan. 17, 2025
- Modified: Jan. 23, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2024-57369
Clickjacking vulnerability in typecho v1.2.1.... Read more
Affected Products : typecho- Published: Jan. 17, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Cross-Site Request Forgery
-
9.8
CRITICALCVE-2024-57034
WeGIA < 3.2.0 is vulnerable to SQL Injection in query_geracao_auto.php via the query parameter.... Read more
Affected Products : wegia- Published: Jan. 17, 2025
- Modified: Mar. 14, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-57032
WeGIA < 3.2.0 is vulnerable to Incorrect Access Control in controle/control.php. The application does not validate the value of the old password, so it is possible to change the password by placing any value in the senha_antiga field.... Read more
Affected Products : wegia- Published: Jan. 17, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-57031
WeGIA < 3.2.0 is vulnerable to SQL Injection in /funcionario/remuneracao.php via the id_funcionario parameter.... Read more
Affected Products : wegia- Published: Jan. 17, 2025
- Modified: Mar. 24, 2025
- Vuln Type: Injection
-
8.1
HIGHCVE-2024-57030
Wegia < 3.2.0 is vulnerable to Cross Site Scripting (XSS) in /geral/documentos_funcionario.php via the id parameter.... Read more
Affected Products : wegia- Published: Jan. 17, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2024-52870
Teradata Vantage Editor 1.0.1 is mostly intended for SQL database access and docs.teradata.com access, but provides unintended functionality (including Chromium Developer Tools) that can result in a client user accessing arbitrary remote websites.... Read more
Affected Products :- Published: Jan. 17, 2025
- Modified: Jan. 17, 2025
- Vuln Type: Server-Side Request Forgery
-
6.1
MEDIUMCVE-2024-13026
A vulnerability exists in Algo Edge up to 2.1.1 - a previously used (legacy) component of navify® Algorithm Suite. The vulnerability impacts the authentication mechanism of this component and could allow an attacker with adjacent access to the laboratory... Read more
Affected Products :- Published: Jan. 17, 2025
- Modified: Jan. 17, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-0535
A vulnerability classified as critical has been found in Codezips Gym Management System 1.0. This affects an unknown part of the file /dashboard/admin/edit_mem_submit.php. The manipulation of the argument uid leads to sql injection. It is possible to init... Read more
- Published: Jan. 17, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-0534
A vulnerability was found in 1000 Projects Campaign Management System Platform for Women 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /Code/loginnew.php. The manipulation of the argument Username lea... Read more
Affected Products : campaign_management_system_platform_for_women- Published: Jan. 17, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-0533
A vulnerability was found in 1000 Projects Campaign Management System Platform for Women 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /Code/sc_login.php. The manipulation of the argument una... Read more
Affected Products : campaign_management_system_platform_for_women- Published: Jan. 17, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-0532
A vulnerability was found in Codezips Gym Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /dashboard/admin/new_submit.php. The manipulation of the argument m_id leads to sql injection. It is possible ... Read more
- Published: Jan. 17, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Injection
-
8.7
HIGHCVE-2025-0430
Belledonne Communications Linphone-Desktop is vulnerable to a NULL Dereference vulnerability, which could allow a remote attacker to create a denial-of-service condition.... Read more
Affected Products :- Published: Jan. 17, 2025
- Modified: Jan. 17, 2025
- Vuln Type: Denial of Service
-
8.8
HIGHCVE-2024-12757
Nedap Librix Ecoreader is missing authentication for critical functions that could allow an unauthenticated attacker to potentially execute malicious code.... Read more
Affected Products :- Published: Jan. 17, 2025
- Modified: Jan. 17, 2025
- Vuln Type: Authentication