Latest CVE Feed
-
6.5
MEDIUMCVE-2025-0921
Execution with Unnecessary Privileges vulnerability in multiple services of Mitsubishi Electric Iconics Digital Solutions GENESIS64 all versions, Mitsubishi Electric Iconics Digital Solutions GENESIS version 11.00, Mitsubishi Electric GENESIS64 all versio... Read more
Affected Products : mc_works64- Published: May. 15, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-4725
A vulnerability, which was classified as critical, was found in itsourcecode Placement Management System 1.0. This affects an unknown part of the file /view_drive.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate ... Read more
Affected Products : placement_management_system- Published: May. 15, 2025
- Modified: May. 27, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4724
A vulnerability, which was classified as critical, has been found in itsourcecode Placement Management System 1.0. Affected by this issue is some unknown functionality of the file /student_profile.php. The manipulation of the argument ID leads to sql inje... Read more
Affected Products : placement_management_system- Published: May. 15, 2025
- Modified: May. 27, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4723
A vulnerability classified as critical was found in itsourcecode Placement Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /all_student.php. The manipulation of the argument delete leads to sql injection. The ... Read more
Affected Products : placement_management_system- Published: May. 15, 2025
- Modified: May. 27, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4722
A vulnerability classified as critical has been found in itsourcecode Placement Management System 1.0. Affected is an unknown function of the file /edit_profile.php. The manipulation of the argument Name leads to sql injection. It is possible to launch th... Read more
Affected Products : placement_management_system- Published: May. 15, 2025
- Modified: May. 27, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-47287
Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to gene... Read more
Affected Products : tornado- Published: May. 15, 2025
- Modified: May. 29, 2025
- Vuln Type: Denial of Service
-
9.1
CRITICALCVE-2025-47275
Auth0-PHP provides the PHP SDK for Auth0 Authentication and Management APIs. Starting in version 8.0.0-BETA1 and prior to version 8.14.0, session cookies of applications using the Auth0-PHP SDK configured with CookieStore have authentication tags that can... Read more
Affected Products : auth0- Published: May. 15, 2025
- Modified: May. 16, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-4721
A vulnerability was found in itsourcecode Placement Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /drive.php. The manipulation of the argument ID leads to sql injection. The attack may be init... Read more
Affected Products : placement_management_system- Published: May. 15, 2025
- Modified: May. 27, 2025
- Vuln Type: Injection
-
5.5
MEDIUMCVE-2025-4720
A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file academic/core/drop_student.php. The manipulation of the argument img leads to path trav... Read more
- Published: May. 15, 2025
- Modified: May. 27, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-4719
A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /pages/cash_transaction.php. The manipulation of the argument cid leads to sql injection. Th... Read more
Affected Products : sales_and_inventory_system- Published: May. 15, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4718
A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /pages/customer_add.php. The manipulation of the argument last leads to sql injec... Read more
Affected Products : sales_and_inventory_system- Published: May. 15, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
2.1
LOWCVE-2025-47929
DumbDrop, a file upload application that provides an interface for dragging and dropping files, has a DOM cross-site scripting vulnerability in the upload functionality prior to commit db27b25372eb9071e63583d8faed2111a2b79f1b. A user could be tricked into... Read more
Affected Products :- Published: May. 15, 2025
- Modified: May. 16, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-1138
IBM InfoSphere Information Server 11.7 could disclose sensitive information to an authenticated user that could aid in further attacks against the system through a directory listing.... Read more
- Published: May. 15, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-4717
A vulnerability, which was classified as critical, was found in PHPGurukul Company Visitor Management System 2.0. Affected is an unknown function of the file /visitors-form.php. The manipulation of the argument fullname leads to sql injection. It is possi... Read more
Affected Products : company_visitor_management_system- Published: May. 15, 2025
- Modified: May. 27, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4716
A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /pages/credit_transaction_add.php. The manipulation of the argument prod_name leads to s... Read more
Affected Products : sales_and_inventory_system- Published: May. 15, 2025
- Modified: May. 27, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4715
A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /pages/view_application.php. The manipulation of the argument cid leads to sql ... Read more
Affected Products : sales_and_inventory_system- Published: May. 15, 2025
- Modified: May. 27, 2025
- Vuln Type: Injection
-
9.1
CRITICALCVE-2025-47928
Spotipy is a Python library for the Spotify Web API. As of commit 4f5759dbfb4506c7b6280572a4db1aabc1ac778d, using `pull_request_target` on `.github/workflows/integration_tests.yml` followed by the checking out the head.sha of a forked PR can be exploited ... Read more
Affected Products : spotipy- Published: May. 15, 2025
- Modified: May. 16, 2025
- Vuln Type: Misconfiguration
-
6.1
MEDIUMCVE-2025-47789
Horilla is a free and open source Human Resource Management System (HRMS). In versions up to and including 1.3, an attacker can craft a Horilla URL that refers to an external domain. Upon clicking and logging in, the user is redirected to an external doma... Read more
Affected Products :- Published: May. 15, 2025
- Modified: May. 16, 2025
- Vuln Type: Authentication
-
9.4
CRITICALCVE-2025-47788
Atheos is a self-hosted browser-based cloud IDE. Prior to v602, similar to GHSA-rgjm-6p59-537v/CVE-2025-22152, the `$target` parameter in `/controller.php` was not properly validated, which could allow an attacker to execute arbitrary files on the server ... Read more
Affected Products :- Published: May. 15, 2025
- Modified: May. 19, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-47787
Emlog is an open source website building system. Emlog Pro prior to version 2.5.10 contains a file upload vulnerability. The store.php component contains a critical security flaw where it fails to properly validate the contents of remotely downloaded ZIP ... Read more
Affected Products : emlog- Published: May. 15, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Authentication