Latest CVE Feed
-
7.8
HIGHCVE-2025-4500
A vulnerability, which was classified as critical, has been found in code-projects Hotel Management System 1.0. Affected by this issue is the function Edit of the component Edit Room. The manipulation of the argument roomnumber leads to stack-based buffer... Read more
Affected Products : hotel_management_system- Published: May. 10, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-4499
A vulnerability classified as critical was found in code-projects Simple Hospital Management System 1.0. Affected by this vulnerability is the function Add of the component Add Information. The manipulation of the argument x[i].name/x[i].disease leads to ... Read more
Affected Products : simple_hospital_management_system- Published: May. 10, 2025
- Modified: May. 28, 2025
- Vuln Type: Memory Corruption
-
6.4
MEDIUMCVE-2025-3878
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sa_verify shortcode in all versions up to, and including, 3.8.1 due to insufficient input sanitization and output escaping o... Read more
Affected Products : sms_alert_order_notifications- Published: May. 10, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-3876
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to insufficient user OTP validation in the handleWpLoginCreateUserAction() function in all versions up to, and including, 3.8.1. This makes it p... Read more
Affected Products : sms_alert_order_notifications- Published: May. 10, 2025
- Modified: May. 21, 2025
- Vuln Type: Authentication
-
7.8
HIGHCVE-2025-4498
A vulnerability classified as critical has been found in code-projects Simple Bus Reservation System 1.0. Affected is the function a::install of the component Install Bus. The manipulation of the argument bus leads to stack-based buffer overflow. It is po... Read more
Affected Products : simple_bus_reservation_system- Published: May. 10, 2025
- Modified: May. 28, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-2158
The WordPress Review Plugin: The Ultimate Solution for Building a Review Website plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.3.5 via the Post custom fields. This makes it possible for authenticated at... Read more
Affected Products :- Published: May. 10, 2025
- Modified: May. 12, 2025
- Vuln Type: Path Traversal
-
7.8
HIGHCVE-2025-4497
A vulnerability was found in code-projects Simple Banking System up to 1.0. It has been rated as critical. This issue affects some unknown processing of the component Sign In. The manipulation of the argument password2 leads to buffer overflow. Attacking ... Read more
Affected Products : simple_banking_system- Published: May. 10, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
6.4
MEDIUMCVE-2025-2944
The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video Button and Countdown Widgets in all versions up to, and including, 2.6.12 due to insufficient input sanitization and output escaping on user sup... Read more
Affected Products : jeg_elementor_kit- Published: May. 10, 2025
- Modified: May. 12, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-4496
A vulnerability was found in TOTOLINK T10, A3100R, A950RG, A800R, N600R, A3000RU and A810R 4.1.8cu.5241_B20210927. It has been declared as critical. This vulnerability affects the function CloudACMunualUpdate of the file /cgi-bin/cstecgi.cgi. The manipula... Read more
Affected Products : a3100r_firmware n600r_firmware a950rg_firmware a800r_firmware a3000ru_firmware a810r_firmware t10_firmware a3100r a3000ru t10 +4 more products- Published: May. 10, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-1137
IBM Storage Scale 5.2.2.0 and 5.2.2.1, under certain configurations, could allow an authenticated user to execute privileged commands due to improper input neutralization.... Read more
- Published: May. 10, 2025
- Modified: Aug. 12, 2025
-
5.1
MEDIUMCVE-2025-4495
A vulnerability has been found in JAdmin-JAVA JAdmin 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /memoAjax/save. The manipulation of the argument ID leads to cross site scripting. The attack ca... Read more
Affected Products :- Published: May. 10, 2025
- Modified: May. 12, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-47424
Retool (self-hosted) before 3.196.0 allows Host header injection. When the BASE_DOMAIN environment variable is not set, the HTTP host header can be manipulated.... Read more
Affected Products : retool- Published: May. 09, 2025
- Modified: May. 12, 2025
- Vuln Type: Misconfiguration
-
5.4
MEDIUMCVE-2025-3794
The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the start_timestamp parameter in all versions up to, and including, 1.9.5 due to insufficie... Read more
Affected Products : wpforms- Published: May. 09, 2025
- Modified: May. 12, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-4494
A vulnerability, which was classified as critical, was found in JAdmin-JAVA JAdmin 1.0. Affected is the function toLogin of the file NoNeedLoginController.java of the component Admin Backend. The manipulation leads to improper authentication. It is possib... Read more
Affected Products :- Published: May. 09, 2025
- Modified: May. 12, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-4492
A vulnerability, which was classified as critical, has been found in Campcodes Online Food Ordering System 1.0. This issue affects some unknown processing of the file /routers/ticket-message.php. The manipulation of the argument ticket_id leads to sql inj... Read more
Affected Products : online_food_ordering_system- Published: May. 09, 2025
- Modified: May. 13, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4491
A vulnerability classified as critical was found in Campcodes Online Food Ordering System 1.0. This vulnerability affects unknown code of the file /routers/ticket-status.php. The manipulation of the argument ticket_id leads to sql injection. The attack ca... Read more
Affected Products : online_food_ordering_system- Published: May. 09, 2025
- Modified: May. 13, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4490
A vulnerability classified as critical has been found in Campcodes Online Food Ordering System 1.0. This affects an unknown part of the file /view-ticket-admin.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the... Read more
Affected Products : online_food_ordering_system- Published: May. 09, 2025
- Modified: May. 13, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4489
A vulnerability was found in Campcodes Online Food Ordering System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /routers/user-router.php. The manipulation of the argument t1_verified leads to sql inj... Read more
Affected Products : online_food_ordering_system- Published: May. 09, 2025
- Modified: May. 13, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4447
In Eclipse OpenJ9 versions up to 0.51, when used with OpenJDK version 8 a stack based buffer overflow can be caused by modifying a file on disk that is read when the JVM starts.... Read more
Affected Products : openj9- Published: May. 09, 2025
- Modified: Sep. 05, 2025
- Vuln Type: Memory Corruption
-
8.3
HIGHCVE-2025-47269
code-server runs VS Code on any machine anywhere through browser access. Prior to version 4.99.4, a maliciously crafted URL using the proxy subpath can result in the attacker gaining access to the session token. Failure to properly validate the port for a... Read more
Affected Products : code-server- Published: May. 09, 2025
- Modified: May. 12, 2025
- Vuln Type: Authentication