Latest CVE Feed
-
9.8
CRITICALCVE-2025-4031
A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/aboutus.php. The manipulation of the argument pagetitle leads to sql injection. The atta... Read more
Affected Products : pre-school_enrollment_system- Published: Apr. 28, 2025
- Modified: May. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4030
A vulnerability was found in PHPGurukul COVID19 Testing Management System 1.0. It has been classified as critical. This affects an unknown part of the file /search-report-result.php. The manipulation of the argument serachdata leads to sql injection. It i... Read more
Affected Products : covid19_testing_management_system- Published: Apr. 28, 2025
- Modified: May. 10, 2025
- Vuln Type: Injection
-
2.1
LOWCVE-2024-12706
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenText™ Digital Asset Management. T he vulnerability could allow an authenticated user to run arbitrary SQL commands on the underlying database. Thi... Read more
Affected Products :- Published: Apr. 28, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2025-4029
A vulnerability was found in code-projects Personal Diary Management System 1.0 and classified as critical. Affected by this issue is the function addrecord of the component New Record Handler. The manipulation of the argument filename leads to stack-base... Read more
Affected Products : personal_diary_management_system- Published: Apr. 28, 2025
- Modified: May. 10, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4028
A vulnerability has been found in PHPGurukul COVID19 Testing Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /profile.php. The manipulation of the argument mobilenumber leads to sql ... Read more
Affected Products : covid19_testing_management_system- Published: Apr. 28, 2025
- Modified: May. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-32499
Newforma Project Center Server through 2023.3.0.32259 allows remote code execution because .NET Remoting is exposed.... Read more
Affected Products : project_center_server- Published: Apr. 28, 2025
- Modified: May. 10, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2023-42404
OneVision Workspace before WS23.1 SR1 (build w31.040) allows arbitrary Java EL execution.... Read more
Affected Products : workspace- Published: Apr. 28, 2025
- Modified: May. 12, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4027
A vulnerability, which was classified as critical, was found in PHPGurukul Old Age Home Management System 1.0. Affected is an unknown function of the file /admin/rules.php. The manipulation of the argument pagetitle leads to sql injection. It is possible ... Read more
Affected Products : old_age_home_management_system- Published: Apr. 28, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4026
A vulnerability, which was classified as critical, has been found in PHPGurukul Nipah Virus Testing Management System 1.0. This issue affects some unknown processing of the file /profile.php. The manipulation of the argument adminname/mobilenumber leads t... Read more
Affected Products : nipah_virus_testing_management_system- Published: Apr. 28, 2025
- Modified: May. 05, 2025
- Vuln Type: Injection
-
3.3
LOWCVE-2025-46614
In Snowflake ODBC Driver before 3.7.0, in certain code paths, the Driver logged the whole SQL query at the INFO level, aka Insertion of Sensitive Information into a Log File.... Read more
Affected Products :- Published: Apr. 28, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2025-43857
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.5.7, 0.4.20, 0.3.9, and 0.2.5, there is a possibility for denial of service by memory exhaustion when net-imap reads server responses. At any ti... Read more
Affected Products : net\- Published: Apr. 28, 2025
- Modified: May. 12, 2025
- Vuln Type: Denial of Service
-
6.1
MEDIUMCVE-2025-43854
DIFY is an open-source LLM app development platform. Prior to version 1.3.0, a clickjacking vulnerability was found in the default setup of the DIFY application, allowing malicious actors to trick users into clicking on elements of the web page without th... Read more
Affected Products : dify- Published: Apr. 28, 2025
- Modified: May. 12, 2025
- Vuln Type: Cross-Site Request Forgery
-
9.8
CRITICALCVE-2023-35817
DevExpress before 23.1.3 allows AsyncDownloader SSRF.... Read more
Affected Products : devexpress- Published: Apr. 28, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Server-Side Request Forgery
-
5.3
MEDIUMCVE-2023-35816
DevExpress before 23.1.3 allows arbitrary TypeConverter conversion.... Read more
Affected Products : devexpress- Published: Apr. 28, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2023-35815
DevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data.... Read more
Affected Products : devexpress- Published: Apr. 28, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2023-35814
DevExpress before 23.1.3 does not properly protect XtraReport serialized data in ASP.NET web forms.... Read more
Affected Products : devexpress- Published: Apr. 28, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2022-41871
SEPPmail through 12.1.17 allows command injection within the Admin Portal. An authenticated attacker is able to execute arbitrary code in the context of the user root.... Read more
Affected Products : seppmail- Published: Apr. 28, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
7.2
HIGHCVE-2015-4582
The TheCartPress boot-store (aka Boot Store) theme 1.6.4 for WordPress allows header.php tcp_register_error XSS. NOTE: CVE-2015-4582 is not assigned to any Oracle product.... Read more
Affected Products : boot_store- Published: Apr. 28, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-4025
A vulnerability classified as critical was found in itsourcecode Placement Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /registration.php. The manipulation of the argument Name leads to sql injection. The a... Read more
Affected Products : placement_management_system- Published: Apr. 28, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4024
A vulnerability classified as critical has been found in itsourcecode Placement Management System 1.0. Affected is an unknown function of the file /add_drive.php. The manipulation of the argument drive_title leads to sql injection. It is possible to launc... Read more
Affected Products : placement_management_system- Published: Apr. 28, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Injection