Latest CVE Feed
-
8.8
HIGHCVE-2025-51629
A cross-site scripting (XSS) vulnerability in the PdfViewer component of Agenzia Impresa Eccobook 2.81.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Temp parameter.... Read more
Affected Products :- Published: Aug. 07, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2023-41532
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the doctor_contact parameter in doctorsearch.php.... Read more
Affected Products : hospital_management_system- Published: Aug. 07, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2023-41531
Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func3.php via the username1 and password2 parameters.... Read more
Affected Products : hospital_management_system- Published: Aug. 07, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2023-41530
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the app_contact parameter in appsearch.php.... Read more
Affected Products : hospital_management_system- Published: Aug. 07, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2023-41529
Hospital Management System v4 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in func2.php via the fname and lname parameters.... Read more
Affected Products : hospital_management_system- Published: Aug. 07, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2023-41528
Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in contact.php via the txtname, txtphone, and txtmail parameters.... Read more
Affected Products : hospital_management_system- Published: Aug. 07, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2023-41527
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the password2 parameter in func.php.... Read more
Affected Products : hospital_management_system- Published: Aug. 07, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2023-41526
Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func1.php via the username3 and password3 parameters.... Read more
Affected Products : hospital_management_system- Published: Aug. 07, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2023-41525
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the patient_contact parameter in patientsearch.php.... Read more
Affected Products : hospital_management_system- Published: Aug. 07, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2023-41524
Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the username parameter at index.php.... Read more
Affected Products : student_attendance_management_system- Published: Aug. 07, 2025
- Modified: Aug. 13, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2023-41523
Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the emailAddress parameter at createClassTeacher.php.... Read more
Affected Products : student_attendance_management_system- Published: Aug. 07, 2025
- Modified: Aug. 13, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2023-41522
Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createStudents.php via the Id, firstname, and admissionNumber parameters.... Read more
Affected Products : student_attendance_management_system- Published: Aug. 07, 2025
- Modified: Aug. 13, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2023-41521
Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createSessionTerm.php via the id, termId, and sessionName parameters.... Read more
Affected Products : student_attendance_management_system- Published: Aug. 07, 2025
- Modified: Aug. 13, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2023-41520
Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createClassArms.php via the classId and classArmName parameters.... Read more
Affected Products : student_attendance_management_system- Published: Aug. 07, 2025
- Modified: Aug. 13, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2023-41519
Student Attendance Management System v1 was discovered to contain a cross-site scripting (XSS) vulnerability via the sessionName parameter at createSessionTerm.php.... Read more
Affected Products : student_attendance_management_system- Published: Aug. 07, 2025
- Modified: Aug. 13, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2023-40992
Hospital Management System 4 is vulnerable to a SQL injection in /Hospital-Management-System-master/func.php via the password2 parameter.... Read more
Affected Products : hospital_management_system- Published: Aug. 07, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Injection
-
7.4
HIGHCVE-2025-55138
LinkJoin through 882f196 mishandles token ownership in password reset.... Read more
Affected Products :- Published: Aug. 07, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Authentication
-
7.4
HIGHCVE-2025-55137
LinkJoin through 882f196 mishandles lacks type checking in password reset.... Read more
Affected Products :- Published: Aug. 07, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Authentication
-
4.3
MEDIUMCVE-2025-54397
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 inserts Sensitive Information Into Sent Data to authenticated users.... Read more
Affected Products : directory_manager- Published: Aug. 07, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Information Disclosure
-
5.4
MEDIUMCVE-2025-54396
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows SQL Injection. Authenticated users can exploit this.... Read more
Affected Products : directory_manager- Published: Aug. 07, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Injection