Latest CVE Feed
-
4.7
MEDIUMCVE-2025-5016
The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Excerpt Highlights in all versions up to, and including, 4.24.5 (Free) and 2.27.6 (Premium) due to insufficient input sanitization and output escapi... Read more
Affected Products : relevanssi- Published: May. 31, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-5367
A vulnerability was found in PHPGurukul Online Shopping Portal Project 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /category.php. The manipulation of the argument Product leads to sql injection. The attack ca... Read more
- Published: May. 31, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5365
A vulnerability was found in Campcodes Online Hospital Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/patient-search.php. The manipulation of the argument searchdata leads to sql injection. It is... Read more
Affected Products : online_hospital_management_system- Published: May. 31, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Injection
-
5.1
MEDIUMCVE-2018-25111
django-helpdesk before 1.0.0 allows Sensitive Data Exposure because of os.umask(0) in models.py.... Read more
Affected Products : django-helpdesk- Published: May. 31, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-5364
A vulnerability was found in Campcodes Online Hospital Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /doctor/add-patient.php. The manipulation of the argument patname leads to sql inject... Read more
Affected Products : online_hospital_management_system- Published: May. 30, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5363
A vulnerability has been found in Campcodes Online Hospital Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /doctor/index.php. The manipulation of the argument Username leads to sql ... Read more
Affected Products : online_hospital_management_system- Published: May. 30, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5362
A vulnerability, which was classified as critical, was found in Campcodes Online Hospital Management System 1.0. Affected is an unknown function of the file /admin/doctor-specilization.php. The manipulation of the argument doctorspecilization leads to sql... Read more
Affected Products : online_hospital_management_system- Published: May. 30, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5361
A vulnerability, which was classified as critical, has been found in Campcodes Online Hospital Management System 1.0. This issue affects some unknown processing of the file /contact.php. The manipulation of the argument fullname leads to sql injection. Th... Read more
Affected Products : online_hospital_management_system- Published: May. 30, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5360
A vulnerability classified as critical was found in Campcodes Online Hospital Management System 1.0. This vulnerability affects unknown code of the file /book-appointment.php. The manipulation of the argument doctor leads to sql injection. The attack can ... Read more
Affected Products : online_hospital_management_system- Published: May. 30, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-48949
Navidrome is an open source web-based music collection server and streamer. Versions 0.55.0 through 0.55.2 have a vulnerability due to improper input validation on the `role` parameter within the API endpoint `/api/artist`. Attackers can exploit this flaw... Read more
Affected Products : navidrome- Published: May. 30, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Injection
-
7.4
HIGHCVE-2025-48948
Navidrome is an open source web-based music collection server and streamer. A permission verification flaw in versions prior to 0.56.0 allows any authenticated regular user to bypass authorization checks and perform administrator-only transcoding configur... Read more
Affected Products : navidrome- Published: May. 30, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Authorization
-
3.7
LOWCVE-2025-48946
liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. liboqs prior to version 0.13.0 supports the HQC algorithm, an algorithm with a theoretical design flaw which leads to large numbers of malf... Read more
Affected Products : liboqs- Published: May. 30, 2025
- Modified: Aug. 25, 2025
- Vuln Type: Cryptography
-
8.7
HIGHCVE-2025-48882
PHPOffice Math is a library that provides a set of classes to manipulate different formula file formats. Prior to version 0.3.0, loading XML data using the standard `libxml` extension and the `LIBXML_DTDLOAD` flag without additional filtration, leads to X... Read more
Affected Products :- Published: May. 30, 2025
- Modified: Jun. 02, 2025
- Vuln Type: XML External Entity
-
7.1
HIGHCVE-2025-2503
An improper permission handling vulnerability was reported in Lenovo PC Manager that could allow a local attacker to perform arbitrary file deletions as an elevated user.... Read more
Affected Products : pc_manager- Published: May. 30, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Authorization
-
8.5
HIGHCVE-2025-2502
An improper default permissions vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges.... Read more
Affected Products : pc_manager- Published: May. 30, 2025
- Modified: Jun. 02, 2025
-
8.5
HIGHCVE-2025-2501
An untrusted search path vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges.... Read more
Affected Products : pc_manager- Published: May. 30, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Path Traversal
-
5.3
MEDIUMCVE-2025-1479
An open debug interface was reported in the Legion Space software included on certain Legion devices that could allow a local attacker to execute arbitrary code.... Read more
- Published: May. 30, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-5359
A vulnerability classified as critical has been found in Campcodes Online Hospital Management System 1.0. This affects an unknown part of the file /appointment-history.php. The manipulation of the argument ID leads to sql injection. It is possible to init... Read more
Affected Products : online_hospital_management_system- Published: May. 30, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-48944
vLLM is an inference and serving engine for large language models (LLMs). In version 0.8.0 up to but excluding 0.9.0, the vLLM backend used with the /v1/chat/completions OpenAPI endpoint fails to validate unexpected or malformed input in the "pattern" and... Read more
Affected Products : vllm- Published: May. 30, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-48943
vLLM is an inference and serving engine for large language models (LLMs). Version 0.8.0 up to but excluding 0.9.0 have a Denial of Service (ReDoS) that causes the vLLM server to crash if an invalid regex was provided while using structured output. This vu... Read more
Affected Products : vllm- Published: May. 30, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Denial of Service