Latest CVE Feed
-
8.0
HIGH- Published: Apr. 29, 2025
- Modified: May. 02, 2025
- Vuln Type: Authorization
-
4.8
MEDIUMCVE-2025-0716
Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '<image>' SVG elements in AngularJS allows attackers to bypass common image source restrictions. This can lead to a form of Content Spoofing https://owasp.org/www-community/a... Read more
Affected Products : angular- Published: Apr. 29, 2025
- Modified: May. 02, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-4071
A vulnerability has been found in PHPGurukul COVID19 Testing Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /test-details.php. The manipulation of the argument Status leads to sql injection. The attac... Read more
Affected Products : covid19_testing_management_system- Published: Apr. 29, 2025
- Modified: May. 09, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4070
A vulnerability, which was classified as critical, was found in PHPGurukul Rail Pass Management System 1.0. This affects an unknown part of the file /admin/changeimage.php. The manipulation of the argument editid leads to sql injection. It is possible to ... Read more
Affected Products : rail_pass_management_system- Published: Apr. 29, 2025
- Modified: May. 09, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2025-4069
A vulnerability, which was classified as critical, has been found in code-projects Product Management System 1.0. Affected by this issue is the function add_item. The manipulation of the argument st.productname leads to stack-based buffer overflow. An att... Read more
Affected Products : product_management_system- Published: Apr. 29, 2025
- Modified: May. 28, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-4068
A vulnerability classified as critical was found in code-projects Simple Movie Ticket Booking System 1.0. Affected by this vulnerability is the function changeprize. The manipulation of the argument prize leads to stack-based buffer overflow. The attack n... Read more
Affected Products : simple_movie_ticket_booking_system- Published: Apr. 29, 2025
- Modified: May. 28, 2025
- Vuln Type: Memory Corruption
-
6.3
MEDIUMCVE-2025-46346
YesWiki is a wiki system written in PHP. Prior to version 4.5.4, a stored cross-site scripting (XSS) vulnerability was discovered in the application’s comments feature. This issue allows a malicious actor to inject JavaScript payloads that are stored and ... Read more
Affected Products : yeswiki- Published: Apr. 29, 2025
- Modified: May. 09, 2025
- Vuln Type: Cross-Site Scripting
-
9.3
CRITICALCVE-2025-40619
Bookgy does not provide for proper authorisation control in multiple areas of the application. This deficiency could allow a malicious actor, without authentication, to reach private areas and/or areas intended for other roles.... Read more
Affected Products :- Published: Apr. 29, 2025
- Modified: May. 02, 2025
- Vuln Type: Authorization
-
9.3
CRITICALCVE-2025-40618
SQL injection vulnerability in Bookgy. This vulnerability could allow an attacker to retrieve, create, update and delete databases by sending an HTTP request through the "IDRESERVA" parameter in /bkg_imprimir_comprobante.php... Read more
Affected Products :- Published: Apr. 29, 2025
- Modified: May. 02, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2025-40617
SQL injection vulnerability in Bookgy. This vulnerability could allow an attacker to retrieve, create, update and delete databases by sending an HTTP request through the "IDTIPO", "IDPISTA" and "IDSOCIO" parameters in /bkg_seleccionar_hora_ajax.php.... Read more
Affected Products :- Published: Apr. 29, 2025
- Modified: May. 02, 2025
- Vuln Type: Injection
-
5.1
MEDIUMCVE-2025-40616
Reflected Cross-Site Scripting (XSS) vulnerability in Bookgy. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the "IDRESERVA" parameter in /bkg_imprimir_comprobante.php.... Read more
Affected Products :- Published: Apr. 29, 2025
- Modified: May. 02, 2025
- Vuln Type: Cross-Site Scripting
-
5.1
MEDIUMCVE-2025-40615
Reflected Cross-Site Scripting (XSS) vulnerability in Bookgy. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the "TEXTO" parameter in /api/api_ajustes.php.... Read more
Affected Products :- Published: Apr. 29, 2025
- Modified: May. 02, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-32354
In Zimbra Collaboration (ZCS) 9.0 through 10.1, a Cross-Site Request Forgery (CSRF) vulnerability exists in the GraphQL endpoint (/service/extension/graphql) of Zimbra webmail due to a lack of CSRF token validation. This allows attackers to perform unauth... Read more
Affected Products : zimbra_collaboration_suite- Published: Apr. 29, 2025
- Modified: Jun. 11, 2025
- Vuln Type: Cross-Site Request Forgery
-
9.8
CRITICALCVE-2025-25962
An issue in Coresmartcontracts Uniswap v.3.0 and fixed in v.4.0 allows a remote attacker to escalate privileges via the _modifyPosition function... Read more
Affected Products :- Published: Apr. 29, 2025
- Modified: May. 06, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-25403
Slims (Senayan Library Management Systems) 9 Bulian V9.6.1 is vulnerable to SQL Injection in admin/modules/master_file/coll_type.php.... Read more
Affected Products :- Published: Apr. 29, 2025
- Modified: May. 06, 2025
- Vuln Type: Injection
-
5.5
MEDIUM- Published: Apr. 29, 2025
- Modified: May. 02, 2025
- Vuln Type: Authentication
-
7.6
HIGHCVE-2025-23178
CWE-923: Improper Restriction of Communication Channel to Intended Endpoints... Read more
Affected Products :- Published: Apr. 29, 2025
- Modified: May. 02, 2025
- Vuln Type: Misconfiguration
-
7.6
HIGH- Published: Apr. 29, 2025
- Modified: May. 02, 2025
- Vuln Type: Misconfiguration
-
6.1
MEDIUMCVE-2025-1551
IBM Operational Decision Manager 8.11.0.1, 8.11.1.0, 8.12.0.1, and 9.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionali... Read more
Affected Products : operational_decision_manager- Published: Apr. 29, 2025
- Modified: May. 12, 2025
- Vuln Type: Cross-Site Scripting
-
6.9
MEDIUMCVE-2025-4067
A vulnerability classified as critical has been found in ScriptAndTools Online-Travling-System 1.0. Affected is an unknown function of the file /admin/viewpackage.php. The manipulation leads to improper access controls. It is possible to launch the attack... Read more
Affected Products : online_traveling_system- Published: Apr. 29, 2025
- Modified: May. 12, 2025
- Vuln Type: Authorization