Latest CVE Feed
-
4.3
MEDIUMCVE-2024-57252
OtCMS <=V7.46 is vulnerable to Server-Side Request Forgery (SSRF) in /admin/read.php, which can Read system files arbitrarily.... Read more
Affected Products : otcms- Published: Jan. 17, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Server-Side Request Forgery
-
9.8
CRITICALCVE-2024-57035
WeGIA v3.2.0 is vulnerable to SQL Injection viathe nextPage parameter in /controle/control.php.... Read more
Affected Products : wegia- Published: Jan. 17, 2025
- Modified: Mar. 18, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2024-57033
WeGIA < 3.2.0 is vulnerable to Cross Site Scripting (XSS) via the dados_addInfo parameter of documentos_funcionario.php.... Read more
Affected Products : wegia- Published: Jan. 17, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2023-50738
A new feature to prevent Firmware downgrades was recently added to some Lexmark products. A method to override this downgrade protection has been identified.... Read more
Affected Products :- Published: Jan. 17, 2025
- Modified: Jan. 17, 2025
- Vuln Type: Authorization
-
7.4
HIGHCVE-2025-21399
Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability... Read more
- Published: Jan. 17, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-21185
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability... Read more
Affected Products : edge_chromium- Published: Jan. 17, 2025
- Modified: Feb. 07, 2025
-
5.1
MEDIUMCVE-2025-0537
A vulnerability, which was classified as problematic, has been found in code-projects Car Rental Management System 1.0. This issue affects some unknown processing of the file /admin/manage-pages.php. The manipulation of the argument pgdetails leads to cro... Read more
Affected Products : online_car_rental_system- Published: Jan. 17, 2025
- Modified: Feb. 21, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-0536
A vulnerability classified as critical was found in 1000 Projects Attendance Tracking Management System 1.0. This vulnerability affects unknown code of the file /admin/edit_action.php. The manipulation of the argument attendance_id leads to sql injection.... Read more
Affected Products : attendance_tracking_management_system- Published: Jan. 17, 2025
- Modified: Feb. 25, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2024-57372
Cross Site Scripting vulnerability in InformationPush master version allows a remote attacker to obtain sensitive information via the title, time and msg parameters... Read more
Affected Products :- Published: Jan. 17, 2025
- Modified: Jan. 17, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-57370
Cross Site Scripting vulnerability in sunnygkp10 Online Exam System master version allows a remote attacker to obtain sensitive information via the w parameter.... Read more
Affected Products :- Published: Jan. 17, 2025
- Modified: Jan. 23, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2024-57369
Clickjacking vulnerability in typecho v1.2.1.... Read more
Affected Products : typecho- Published: Jan. 17, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Cross-Site Request Forgery
-
9.8
CRITICALCVE-2024-57034
WeGIA < 3.2.0 is vulnerable to SQL Injection in query_geracao_auto.php via the query parameter.... Read more
Affected Products : wegia- Published: Jan. 17, 2025
- Modified: Mar. 14, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-57032
WeGIA < 3.2.0 is vulnerable to Incorrect Access Control in controle/control.php. The application does not validate the value of the old password, so it is possible to change the password by placing any value in the senha_antiga field.... Read more
Affected Products : wegia- Published: Jan. 17, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-57031
WeGIA < 3.2.0 is vulnerable to SQL Injection in /funcionario/remuneracao.php via the id_funcionario parameter.... Read more
Affected Products : wegia- Published: Jan. 17, 2025
- Modified: Mar. 24, 2025
- Vuln Type: Injection
-
8.1
HIGHCVE-2024-57030
Wegia < 3.2.0 is vulnerable to Cross Site Scripting (XSS) in /geral/documentos_funcionario.php via the id parameter.... Read more
Affected Products : wegia- Published: Jan. 17, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2024-52870
Teradata Vantage Editor 1.0.1 is mostly intended for SQL database access and docs.teradata.com access, but provides unintended functionality (including Chromium Developer Tools) that can result in a client user accessing arbitrary remote websites.... Read more
Affected Products :- Published: Jan. 17, 2025
- Modified: Jan. 17, 2025
- Vuln Type: Server-Side Request Forgery
-
6.1
MEDIUMCVE-2024-13026
A vulnerability exists in Algo Edge up to 2.1.1 - a previously used (legacy) component of navify® Algorithm Suite. The vulnerability impacts the authentication mechanism of this component and could allow an attacker with adjacent access to the laboratory... Read more
Affected Products :- Published: Jan. 17, 2025
- Modified: Jan. 17, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-0535
A vulnerability classified as critical has been found in Codezips Gym Management System 1.0. This affects an unknown part of the file /dashboard/admin/edit_mem_submit.php. The manipulation of the argument uid leads to sql injection. It is possible to init... Read more
- Published: Jan. 17, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-0534
A vulnerability was found in 1000 Projects Campaign Management System Platform for Women 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /Code/loginnew.php. The manipulation of the argument Username lea... Read more
Affected Products : campaign_management_system_platform_for_women- Published: Jan. 17, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-0533
A vulnerability was found in 1000 Projects Campaign Management System Platform for Women 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /Code/sc_login.php. The manipulation of the argument una... Read more
Affected Products : campaign_management_system_platform_for_women- Published: Jan. 17, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Injection