Latest CVE Feed
-
9.8
CRITICALCVE-2025-4251
A vulnerability was found in PCMan FTP Server 2.0.7 and classified as critical. This issue affects some unknown processing of the component RMDIR Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit... Read more
- Published: May. 04, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4250
A vulnerability was found in code-projects Nero Social Networking Site 1.0. It has been classified as critical. This affects an unknown part of the file /index.php. The manipulation of the argument fname/lname/login/password2/cpassword/address/cnumber/ema... Read more
Affected Products : nero_social_networking_site- Published: May. 04, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4249
A vulnerability was found in PHPGurukul e-Diary Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /manage-categories.php. The manipulation of the argument ID leads to sql injection. The atta... Read more
Affected Products : e-diary_management_system- Published: May. 04, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4248
A vulnerability has been found in SourceCodester Simple To-Do List System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /complete_task.php. The manipulation of the argument ID leads to sql injection... Read more
Affected Products : simple_to-do_list_system- Published: May. 04, 2025
- Modified: May. 13, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-4247
A vulnerability, which was classified as critical, was found in SourceCodester Simple To-Do List System 1.0. Affected is an unknown function of the file /delete_task.php. The manipulation of the argument ID leads to sql injection. It is possible to launch... Read more
Affected Products : simple_to-do_list_system- Published: May. 04, 2025
- Modified: May. 13, 2025
- Vuln Type: Injection
-
8.1
HIGHCVE-2025-47245
In BlueWave Checkmate through 2.0.2 before d4a6072, an invite request can be modified to specify a privileged role.... Read more
Affected Products :- Published: May. 04, 2025
- Modified: May. 05, 2025
- Vuln Type: Authorization
-
7.3
HIGHCVE-2025-47244
Inedo ProGet through 2024.22 allows remote attackers to reach restricted functionality through the C# reflection layer, as demonstrated by causing a denial of service (when an attacker executes a loop calling RestartWeb) or obtaining potentially sensitive... Read more
Affected Products : proget- Published: May. 03, 2025
- Modified: May. 05, 2025
-
4.0
MEDIUMCVE-2025-47241
In browser-use (aka Browser Use) before 0.1.45, URL parsing of allowed_domains is mishandled because userinfo can be placed in the authority component.... Read more
Affected Products :- Published: May. 03, 2025
- Modified: May. 05, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2025-4244
A vulnerability, which was classified as critical, was found in code-projects Online Bus Reservation System 1.0. This affects an unknown part of the file /seatlocation.php. The manipulation of the argument ID leads to sql injection. It is possible to init... Read more
Affected Products : online_bus_reservation_system- Published: May. 03, 2025
- Modified: May. 16, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-4243
A vulnerability, which was classified as critical, has been found in code-projects Online Bus Reservation System 1.0. Affected by this issue is some unknown functionality of the file /print.php. The manipulation of the argument ID leads to sql injection. ... Read more
Affected Products : online_bus_reservation_system- Published: May. 03, 2025
- Modified: May. 16, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4242
A vulnerability classified as critical was found in PHPGurukul Online Birth Certificate System 2.0. Affected by this vulnerability is an unknown functionality of the file /admin/between-dates-report.php. The manipulation of the argument fromdate leads to ... Read more
Affected Products : online_birth_certificate_system- Published: May. 03, 2025
- Modified: May. 09, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-1838
IBM Cloud Pak for Business Automation 24.0.0 and 24.0.1 through 24.0.1 IF001 Authoring allows an authenticated user to bypass client-side data validation in an authoring user interface which could cause a denial of service.... Read more
Affected Products : cloud_pak_for_business_automation- Published: May. 03, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2025-4241
A vulnerability classified as critical has been found in PHPGurukul Teacher Subject Allocation Management System 1.0. Affected is an unknown function of the file /admin/search.php. The manipulation of the argument searchdata leads to sql injection. It is ... Read more
Affected Products : teacher_subject_allocation_management_system- Published: May. 03, 2025
- Modified: May. 09, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4240
A vulnerability was found in PCMan FTP Server 2.0.7. It has been rated as critical. This issue affects some unknown processing of the component LCD Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The explo... Read more
- Published: May. 03, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4239
A vulnerability was found in PCMan FTP Server 2.0.7. It has been declared as critical. This vulnerability affects unknown code of the component TYPE Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remotely. The expl... Read more
- Published: May. 03, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4238
A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as critical. This affects an unknown part of the component MGET Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exp... Read more
- Published: May. 03, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
4.3
MEDIUMCVE-2025-1495
IBM Business Automation Workflow 24.0.0 and 24.0.1 through 24.0.1 IF001 Center may leak sensitive information due to missing authorization validation.... Read more
- Published: May. 03, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Authorization
-
8.1
HIGHCVE-2024-58134
Mojolicious versions from 0.999922 through 9.40 for Perl uses a hard coded string, or the application's class name, as a HMAC session secret by default. These predictable default secrets can be exploited to forge session cookies. An attacker who knows or... Read more
Affected Products : mojolicious- Published: May. 03, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Cryptography
-
6.1
MEDIUMCVE-2024-41753
IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF004 and 24.0.1 through 24.0.1 IF001 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering t... Read more
Affected Products : cloud_pak_for_business_automation- Published: May. 03, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-4237
A vulnerability was found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this issue is some unknown functionality of the component MDELETE Command Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. ... Read more
- Published: May. 03, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption