Latest CVE Feed
-
3.3
LOWCVE-2025-46614
In Snowflake ODBC Driver before 3.7.0, in certain code paths, the Driver logged the whole SQL query at the INFO level, aka Insertion of Sensitive Information into a Log File.... Read more
Affected Products :- Published: Apr. 28, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2025-43857
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.5.7, 0.4.20, 0.3.9, and 0.2.5, there is a possibility for denial of service by memory exhaustion when net-imap reads server responses. At any ti... Read more
Affected Products : net\- Published: Apr. 28, 2025
- Modified: May. 12, 2025
- Vuln Type: Denial of Service
-
6.1
MEDIUMCVE-2025-43854
DIFY is an open-source LLM app development platform. Prior to version 1.3.0, a clickjacking vulnerability was found in the default setup of the DIFY application, allowing malicious actors to trick users into clicking on elements of the web page without th... Read more
Affected Products : dify- Published: Apr. 28, 2025
- Modified: May. 12, 2025
- Vuln Type: Cross-Site Request Forgery
-
9.8
CRITICALCVE-2023-35817
DevExpress before 23.1.3 allows AsyncDownloader SSRF.... Read more
Affected Products : devexpress- Published: Apr. 28, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Server-Side Request Forgery
-
5.3
MEDIUMCVE-2023-35816
DevExpress before 23.1.3 allows arbitrary TypeConverter conversion.... Read more
Affected Products : devexpress- Published: Apr. 28, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2023-35815
DevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data.... Read more
Affected Products : devexpress- Published: Apr. 28, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2023-35814
DevExpress before 23.1.3 does not properly protect XtraReport serialized data in ASP.NET web forms.... Read more
Affected Products : devexpress- Published: Apr. 28, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2022-41871
SEPPmail through 12.1.17 allows command injection within the Admin Portal. An authenticated attacker is able to execute arbitrary code in the context of the user root.... Read more
Affected Products : seppmail- Published: Apr. 28, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
7.2
HIGHCVE-2015-4582
The TheCartPress boot-store (aka Boot Store) theme 1.6.4 for WordPress allows header.php tcp_register_error XSS. NOTE: CVE-2015-4582 is not assigned to any Oracle product.... Read more
Affected Products : boot_store- Published: Apr. 28, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-4025
A vulnerability classified as critical was found in itsourcecode Placement Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /registration.php. The manipulation of the argument Name leads to sql injection. The a... Read more
Affected Products : placement_management_system- Published: Apr. 28, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4024
A vulnerability classified as critical has been found in itsourcecode Placement Management System 1.0. Affected is an unknown function of the file /add_drive.php. The manipulation of the argument drive_title leads to sql injection. It is possible to launc... Read more
Affected Products : placement_management_system- Published: Apr. 28, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Injection
-
5.0
MEDIUMCVE-2025-25776
Cross-Site Scripting (XSS) vulnerability exists in the User Registration and User Profile features of Codeastro Bus Ticket Booking System v1.0 allows an attacker to execute arbitrary code into the Full Name and Address fields during user registration or p... Read more
Affected Products : bus_ticket_booking_system- Published: Apr. 28, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Cross-Site Scripting
-
4.2
MEDIUMCVE-2025-23377
Dell PowerProtect Data Manager Reporting, version(s) 19.17, 19.18 contain(s) an Improper Encoding or Escaping of Output vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to inject arbitrary web script... Read more
Affected Products : powerprotect_data_manager- Published: Apr. 28, 2025
- Modified: May. 13, 2025
- Vuln Type: Cross-Site Scripting
-
4.4
MEDIUMCVE-2025-23376
Dell PowerProtect Data Manager Reporting, version(s) 19.16, 19.17, 19.18, contain(s) an Improper Neutralization of Special Elements Used in a Template Engine vulnerability. A high privileged attacker with local access could potentially exploit this vulner... Read more
Affected Products : powerprotect_data_manager- Published: Apr. 28, 2025
- Modified: May. 13, 2025
- Vuln Type: Information Disclosure
-
7.8
HIGHCVE-2025-23375
Dell PowerProtect Data Manager Reporting, version(s) 19.17, contain(s) an Incorrect Use of Privileged APIs vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.... Read more
Affected Products : powerprotect_data_manager- Published: Apr. 28, 2025
- Modified: May. 13, 2025
- Vuln Type: Authorization
-
9.9
CRITICALCVE-2015-2079
Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the two argument (not three argument) form of Perl open.... Read more
- Published: Apr. 28, 2025
- Modified: May. 14, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4023
A vulnerability was found in itsourcecode Placement Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /add_company.php. The manipulation of the argument Name leads to sql injection. The attack may... Read more
Affected Products : placement_management_system- Published: Apr. 28, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-4022
A vulnerability was found in web-arena-x webarena up to 0.2.0. It has been declared as critical. This vulnerability affects the function HTMLContentEvaluator of the file webarena/evaluation_harness/evaluators.py. The manipulation of the argument target["u... Read more
Affected Products : webarena- Published: Apr. 28, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-4021
A vulnerability was found in code-projects Patient Record Management System 1.0. It has been classified as critical. This affects an unknown part of the file /edit_spatient.php. The manipulation of the argument ID leads to sql injection. It is possible to... Read more
- Published: Apr. 28, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4020
A vulnerability was found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /contact.php. The manipulation of the argument fname leads to sql injection. The attack... Read more
Affected Products : old_age_home_management_system- Published: Apr. 28, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Injection