Latest CVE Feed
-
8.4
HIGHCVE-2025-46688
quickjs-ng through 0.9.0 has an incorrect size calculation in JS_ReadBigInt for a BigInt, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected.... Read more
- Published: Apr. 27, 2025
- Modified: May. 30, 2025
- Vuln Type: Memory Corruption
-
5.6
MEDIUMCVE-2025-46687
quickjs-ng through 0.9.0 has a missing length check in JS_ReadString for a string, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected.... Read more
Affected Products : quickjs- Published: Apr. 27, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Memory Corruption
-
5.0
MEDIUMCVE-2025-3984
A vulnerability was found in Apereo CAS 5.2.6 and classified as critical. Affected by this issue is the function saveService of the file cas-5.2.6\webapp-mgmt\cas-management-webapp-support\src\main\java\org\apereo\cas\mgmt\services\web\RegisteredServiceSi... Read more
Affected Products : central_authentication_service- Published: Apr. 27, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Injection
-
7.2
HIGHCVE-2025-3983
A vulnerability has been found in AMTT Hotel Broadband Operation System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /manager/system/nlog_down.php. The manipulation of the argument ProtocolType lea... Read more
Affected Products : hotel_broadband_operating_system- Published: Apr. 27, 2025
- Modified: May. 12, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-3982
A vulnerability, which was classified as problematic, was found in nortikin Sverchok 1.3.0. Affected is the function SvSetPropNodeMK2 of the file sverchok/nodes/object_nodes/getsetprop_mk2.py of the component Set Property Mk2 Node. The manipulation leads ... Read more
Affected Products : sverchok- Published: Apr. 27, 2025
- Modified: May. 12, 2025
- Vuln Type: Misconfiguration
-
5.3
MEDIUMCVE-2025-3981
A vulnerability, which was classified as problematic, has been found in wowjoy 浙江湖州华卓信息科技有限公司 Internet Doctor Workstation System 1.0. This issue affects some unknown processing of the file /v1/prescription/details/. The manipulation leads to improper auth... Read more
Affected Products : internet_doctor_workstation_system- Published: Apr. 27, 2025
- Modified: May. 12, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2025-2866
Improper Verification of Cryptographic Signature vulnerability in LibreOffice allows PDF Signature Spoofing by Improper Validation. In the affected versions of LibreOffice a flaw in the verification code for adbe.pkcs7.sha1 signatures could cause inva... Read more
Affected Products : libreoffice- Published: Apr. 27, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Cryptography
-
5.3
MEDIUMCVE-2025-3980
A vulnerability classified as problematic was found in wowjoy 浙江湖州华卓信息科技有限公司 Internet Doctor Workstation System 1.0. This vulnerability affects unknown code of the file /v1/prescription/list. The manipulation leads to improper authorization. The attack ca... Read more
Affected Products : internet_doctor_workstation_system- Published: Apr. 27, 2025
- Modified: May. 12, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-3979
A vulnerability classified as problematic has been found in dazhouda lecms 3.0.3. This affects an unknown part of the file /index.php?my-password-ajax-1 of the component Password Change Handler. The manipulation leads to cross-site request forgery. It is ... Read more
Affected Products : lecms- Published: Apr. 27, 2025
- Modified: May. 12, 2025
- Vuln Type: Cross-Site Request Forgery
-
7.5
HIGHCVE-2025-3978
A vulnerability was found in dazhouda lecms 3.0.3. It has been rated as problematic. Affected by this issue is some unknown functionality of the file admin/view/default/user_set.htm. The manipulation leads to information disclosure. The attack may be laun... Read more
Affected Products : lecms- Published: Apr. 27, 2025
- Modified: May. 12, 2025
- Vuln Type: Information Disclosure
-
5.3
MEDIUMCVE-2025-3977
A vulnerability was found in iteachyou Dreamer CMS up to 4.1.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/attachment/download of the component Attachment Handler. The manipulation of... Read more
Affected Products : dreamer_cms- Published: Apr. 27, 2025
- Modified: May. 12, 2025
- Vuln Type: Authorization
-
7.2
HIGHCVE-2025-46657
Karaz Karazal through 2025-04-14 allows reflected XSS via the lang parameter to the default URI.... Read more
Affected Products : karazal- Published: Apr. 27, 2025
- Modified: May. 12, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-3976
A vulnerability was found in PHPGurukul COVID19 Testing Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /new-user-testing.php. The manipulation of the argument mobilenumber leads to sql injection. It ... Read more
Affected Products : covid19_testing_management_system- Published: Apr. 27, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
6.9
MEDIUMCVE-2025-3975
A vulnerability was found in ScriptAndTools eCommerce-website-in-PHP 3.0 and classified as problematic. This issue affects some unknown processing of the file /admin/subscriber-csv.php. The manipulation leads to information disclosure. The attack may be i... Read more
Affected Products : ecommerce-website-in-php- Published: Apr. 27, 2025
- Modified: May. 12, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-3974
A vulnerability has been found in PHPGurukul COVID19 Testing Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /edit-phlebotomist.php?pid=11. The manipulation of the argument mobilenumber leads to sql in... Read more
Affected Products : covid19_testing_management_system- Published: Apr. 27, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3973
A vulnerability, which was classified as critical, was found in PHPGurukul COVID19 Testing Management System 1.0. This affects an unknown part of the file /check_availability.php. The manipulation of the argument mobnumber leads to sql injection. It is po... Read more
Affected Products : covid19_testing_management_system- Published: Apr. 27, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3972
A vulnerability, which was classified as critical, has been found in PHPGurukul COVID19 Testing Management System 1.0. Affected by this issue is some unknown functionality of the file /bwdates-report-result.php. The manipulation of the argument todate lea... Read more
Affected Products : covid19_testing_management_system- Published: Apr. 27, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3971
A vulnerability classified as critical was found in PHPGurukul COVID19 Testing Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /add-phlebotomist.php. The manipulation of the argument empid leads to sql injecti... Read more
Affected Products : covid19_testing_management_system- Published: Apr. 27, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2025-3970
A vulnerability classified as problematic has been found in baseweb JSite up to 1.0. Affected is an unknown function of the file /sys/office/save. The manipulation of the argument Remarks leads to cross site scripting. It is possible to launch the attack ... Read more
Affected Products : jsite- Published: Apr. 27, 2025
- Modified: May. 12, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-3969
A vulnerability was found in codeprojects News Publishing Site Dashboard 1.0. It has been rated as critical. This issue affects some unknown processing of the file /edit-category.php of the component Edit Category Page. The manipulation of the argument ca... Read more
Affected Products : news_publishing_site_dashboard- Published: Apr. 27, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Authentication