Latest CVE Feed
-
7.8
HIGHCVE-2025-4029
A vulnerability was found in code-projects Personal Diary Management System 1.0 and classified as critical. Affected by this issue is the function addrecord of the component New Record Handler. The manipulation of the argument filename leads to stack-base... Read more
Affected Products : personal_diary_management_system- Published: Apr. 28, 2025
- Modified: May. 10, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4028
A vulnerability has been found in PHPGurukul COVID19 Testing Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /profile.php. The manipulation of the argument mobilenumber leads to sql ... Read more
Affected Products : covid19_testing_management_system- Published: Apr. 28, 2025
- Modified: May. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-32499
Newforma Project Center Server through 2023.3.0.32259 allows remote code execution because .NET Remoting is exposed.... Read more
Affected Products : project_center_server- Published: Apr. 28, 2025
- Modified: May. 10, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2023-42404
OneVision Workspace before WS23.1 SR1 (build w31.040) allows arbitrary Java EL execution.... Read more
Affected Products : workspace- Published: Apr. 28, 2025
- Modified: May. 12, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4027
A vulnerability, which was classified as critical, was found in PHPGurukul Old Age Home Management System 1.0. Affected is an unknown function of the file /admin/rules.php. The manipulation of the argument pagetitle leads to sql injection. It is possible ... Read more
Affected Products : old_age_home_management_system- Published: Apr. 28, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4026
A vulnerability, which was classified as critical, has been found in PHPGurukul Nipah Virus Testing Management System 1.0. This issue affects some unknown processing of the file /profile.php. The manipulation of the argument adminname/mobilenumber leads t... Read more
Affected Products : nipah_virus_testing_management_system- Published: Apr. 28, 2025
- Modified: May. 05, 2025
- Vuln Type: Injection
-
3.3
LOWCVE-2025-46614
In Snowflake ODBC Driver before 3.7.0, in certain code paths, the Driver logged the whole SQL query at the INFO level, aka Insertion of Sensitive Information into a Log File.... Read more
Affected Products :- Published: Apr. 28, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2025-43857
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.5.7, 0.4.20, 0.3.9, and 0.2.5, there is a possibility for denial of service by memory exhaustion when net-imap reads server responses. At any ti... Read more
Affected Products : net\- Published: Apr. 28, 2025
- Modified: May. 12, 2025
- Vuln Type: Denial of Service
-
6.1
MEDIUMCVE-2025-43854
DIFY is an open-source LLM app development platform. Prior to version 1.3.0, a clickjacking vulnerability was found in the default setup of the DIFY application, allowing malicious actors to trick users into clicking on elements of the web page without th... Read more
Affected Products : dify- Published: Apr. 28, 2025
- Modified: May. 12, 2025
- Vuln Type: Cross-Site Request Forgery
-
9.8
CRITICALCVE-2023-35817
DevExpress before 23.1.3 allows AsyncDownloader SSRF.... Read more
Affected Products : devexpress- Published: Apr. 28, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Server-Side Request Forgery
-
5.3
MEDIUMCVE-2023-35816
DevExpress before 23.1.3 allows arbitrary TypeConverter conversion.... Read more
Affected Products : devexpress- Published: Apr. 28, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2023-35815
DevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data.... Read more
Affected Products : devexpress- Published: Apr. 28, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2023-35814
DevExpress before 23.1.3 does not properly protect XtraReport serialized data in ASP.NET web forms.... Read more
Affected Products : devexpress- Published: Apr. 28, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2022-41871
SEPPmail through 12.1.17 allows command injection within the Admin Portal. An authenticated attacker is able to execute arbitrary code in the context of the user root.... Read more
Affected Products : seppmail- Published: Apr. 28, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
7.2
HIGHCVE-2015-4582
The TheCartPress boot-store (aka Boot Store) theme 1.6.4 for WordPress allows header.php tcp_register_error XSS. NOTE: CVE-2015-4582 is not assigned to any Oracle product.... Read more
Affected Products : boot_store- Published: Apr. 28, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-4025
A vulnerability classified as critical was found in itsourcecode Placement Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /registration.php. The manipulation of the argument Name leads to sql injection. The a... Read more
Affected Products : placement_management_system- Published: Apr. 28, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4024
A vulnerability classified as critical has been found in itsourcecode Placement Management System 1.0. Affected is an unknown function of the file /add_drive.php. The manipulation of the argument drive_title leads to sql injection. It is possible to launc... Read more
Affected Products : placement_management_system- Published: Apr. 28, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Injection
-
5.0
MEDIUMCVE-2025-25776
Cross-Site Scripting (XSS) vulnerability exists in the User Registration and User Profile features of Codeastro Bus Ticket Booking System v1.0 allows an attacker to execute arbitrary code into the Full Name and Address fields during user registration or p... Read more
Affected Products : bus_ticket_booking_system- Published: Apr. 28, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Cross-Site Scripting
-
4.2
MEDIUMCVE-2025-23377
Dell PowerProtect Data Manager Reporting, version(s) 19.17, 19.18 contain(s) an Improper Encoding or Escaping of Output vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to inject arbitrary web script... Read more
Affected Products : powerprotect_data_manager- Published: Apr. 28, 2025
- Modified: May. 13, 2025
- Vuln Type: Cross-Site Scripting
-
4.4
MEDIUMCVE-2025-23376
Dell PowerProtect Data Manager Reporting, version(s) 19.16, 19.17, 19.18, contain(s) an Improper Neutralization of Special Elements Used in a Template Engine vulnerability. A high privileged attacker with local access could potentially exploit this vulner... Read more
Affected Products : powerprotect_data_manager- Published: Apr. 28, 2025
- Modified: May. 13, 2025
- Vuln Type: Information Disclosure