Search

Found 34,002 results in 1226ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-11556 critical 9.8 9.8 carmelo 8mo ago A flaw has been found in code-projects Simple Leave Manager 1.0. This vulnerability affects unknown code of the file /user.php. This manipulation of the argument table causes sql injection. Remote ex…
CVE-2025-11555 critical 9.8 9.8 campcodes 8mo ago A vulnerability was detected in Campcodes Online Learning Management System 1.0. This affects an unknown part of the file /admin/calendar_of_events.php. The manipulation of the argument date_start re…
CVE-2025-11553 critical 9.8 9.8 carmelogarcia 8mo ago A weakness has been identified in code-projects Courier Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /add-courier.php. Executing manipulation of the a…
CVE-2025-11551 critical 9.8 9.8 carmelo 8mo ago A vulnerability was determined in code-projects Student Result Manager 1.0. This affects an unknown function of the file src/students/Database.java. This manipulation of the argument roll/name/gpa ca…
CVE-2025-62228 unknown 8mo ago Apache Flink CDC is vulnerable to SQL Injection through maliciously crafted identifiers
CVE-2025-11529 critical 9.8 9.8 churchcrm 8mo ago A security flaw has been discovered in ChurchCRM up to 5.18.0. This impacts the function AuthMiddleware of the file src/ChurchCRM/Slim/Middleware/AuthMiddleware.php of the component API Endpoint. The…
CVE-2025-11513 critical 9.8 9.8 fabian 8mo ago A vulnerability was determined in code-projects E-Commerce Website 1.0. This affects an unknown part of the file /pages/supplier_update.php. This manipulation of the argument supp_id causes sql injec…
CVE-2025-9162 unknown 8mo ago Keycloak Potential Variable Reference in Model Storage Services
CVE-2025-11511 critical 9.8 9.8 fabian 8mo ago A flaw has been found in code-projects E-Commerce Website 1.0. Affected is an unknown function of the file /pages/supplier_add.php. Executing manipulation of the argument supp_email can lead to sql i…
CVE-2025-11509 critical 9.8 9.8 fabian 8mo ago A vulnerability was detected in code-projects E-Commerce Website 1.0. This impacts an unknown function of the file /pages/product_add.php. Performing manipulation of the argument prod_name results in…
CVE-2025-11508 critical 9.8 9.8 fabian 8mo ago A security vulnerability has been detected in code-projects Voting System 1.0. This affects an unknown function of the file /admin/voters_add.php. Such manipulation of the argument photo leads to unr…
CVE-2025-11507 critical 9.8 9.8 phpgurukul 8mo ago A weakness has been identified in PHPGurukul Beauty Parlour Management System 1.1. The impacted element is an unknown function of the file /admin/search-invoices.php. This manipulation of the argumen…
CVE-2025-11506 critical 9.8 9.8 phpgurukul 8mo ago A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. The affected element is an unknown function of the file /admin/search-appointment.php. The manipulation of the …
CVE-2025-11505 critical 9.8 9.8 phpgurukul 8mo ago A vulnerability was identified in PHPGurukul Beauty Parlour Management System 1.1. Impacted is an unknown function of the file /admin/new-appointment.php. The manipulation of the argument delid leads…
CVE-2025-61788 unknown 8mo ago Opencast's Paella Player 7 is vulnerable to Cross-Site Scripting
CVE-2025-11503 critical 9.8 9.8 phpgurukul 8mo ago A vulnerability was determined in PHPGurukul Beauty Parlour Management System 1.1. This issue affects some unknown processing of the file /admin/manage-services.php. Executing a manipulation of the a…
CVE-2025-11491 critical 9.8 9.8 wonderwhy-er 8mo ago A vulnerability was found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The impacted element is the function CommandManager of the file src/command-manager.ts. Performing manipulation results in …
CVE-2025-11490 critical 9.8 9.8 wonderwhy-er 8mo ago A vulnerability has been found in wonderwhy-er DesktopCommanderMCP up to 0.2.13. The affected element is the function extractBaseCommand of the file src/command-manager.ts of the component Absolute P…
CVE-2025-11487 critical 9.8 9.8 janobe 8mo ago A security flaw has been discovered in SourceCodester Farm Management System 1.0. Affected by this issue is some unknown functionality of the file /uploadProduct.php. Performing manipulation of the a…
CVE-2025-11486 critical 9.8 9.8 janobe 8mo ago A vulnerability was identified in SourceCodester Farm Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /buyNow.php. Such manipulation of the argument Name…
CVE-2025-11481 critical 9.8 9.8 varunsardana004 8mo ago A flaw has been found in varunsardana004 Blood-Bank-And-Donation-Management-System up to dc9e0393d826fbc85fad9755b5bc12cba1919df2. The impacted element is an unknown function of the file /donate_bloo…
CVE-2025-43830 unknown 8mo ago Liferay Portal is vulnerable to Stored XSS through Forms text type field
CVE-2025-43829 unknown 8mo ago Liferay Portal Commerce Shop is vulnerable to Stored XSS through SVG file
CVE-2025-43771 unknown 8mo ago Liferay Portal Notifications Widget has multiple XSS vulnerabilities through various text fields
CVE-2025-43821 unknown 8mo ago Liferay Portal is vulnerable to XSS through its Commerce Product's Name text field
CVE-2025-11480 critical 9.8 9.8 janobe 8mo ago A vulnerability was detected in SourceCodester Simple E-Commerce Bookstore 1.0. The affected element is an unknown function of the file /register.php. Performing manipulation of the argument register…
CVE-2025-11479 critical 9.8 9.8 janobe 8mo ago A security vulnerability has been detected in SourceCodester Wedding Reservation Management System 1.0. Impacted is the function insertReservation of the file function.php. Such manipulation of the a…
CVE-2025-11477 critical 9.8 9.8 janobe 8mo ago A security flaw has been discovered in SourceCodester Wedding Reservation Management System 1.0. This vulnerability affects unknown code of the file /global.php. The manipulation of the argument User…
CVE-2025-11476 critical 9.8 9.8 janobe 8mo ago A vulnerability was identified in SourceCodester Simple E-Commerce Bookstore 1.0. This affects an unknown part of the file /index.php. The manipulation of the argument login_username leads to sql inj…
CVE-2025-11475 critical 9.8 9.8 projectworlds 8mo ago A vulnerability was determined in projectworlds Advanced Library Management System 1.0. Affected by this issue is some unknown functionality of the file /view_member.php. Executing a manipulation of …
CVE-2025-11474 critical 9.8 9.8 nikhil-bhalerao 8mo ago A vulnerability was found in SourceCodester Hotel and Lodge Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /edit_booking.php. Performing manipulation of…
CVE-2025-11473 critical 9.8 9.8 nikhil-bhalerao 8mo ago A vulnerability has been found in SourceCodester Hotel and Lodge Management System 1.0. Affected is an unknown function of the file /edit_curr.php. Such manipulation of the argument currsymbol leads …
CVE-2025-11472 critical 9.8 9.8 nikhil-bhalerao 8mo ago A flaw has been found in SourceCodester Hotel and Lodge Management System 1.0. This impacts an unknown function of the file /edit_room.php. This manipulation of the argument ID causes sql injection. …
CVE-2025-11471 critical 9.8 9.8 nikhil-bhalerao 8mo ago A vulnerability was detected in SourceCodester Hotel and Lodge Management System 1.0. This affects an unknown function of the file /edit_customer.php. The manipulation of the argument ID results in s…
CVE-2025-11469 critical 9.8 9.8 nikhil-bhalerao 8mo ago A weakness has been identified in SourceCodester Hotel and Lodge Management System 1.0. The affected element is an unknown function of the file /pages/save_customer.php. Executing manipulation of the…
CVE-2025-11434 critical 9.8 9.8 fabian 8mo ago A weakness has been identified in itsourcecode Student Transcript Processing System 1.0. Affected is an unknown function of the file /login.php. Executing a manipulation of the argument uname can lea…
CVE-2025-11432 critical 9.8 9.8 itsourcecode 8mo ago A vulnerability was identified in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /reset.php. Such manipulation of the argument employid leads to sql injection.…
CVE-2025-11431 critical 9.8 9.8 fabian 8mo ago A vulnerability was determined in code-projects Web-Based Inventory and POS System 1.0. The impacted element is an unknown function of the file /transaction.php. This manipulation of the argument sho…
CVE-2025-11430 critical 9.8 9.8 janobe 8mo ago A vulnerability was found in SourceCodester Simple E-Commerce Bookstore 1.0. The affected element is an unknown function of the file /cart.php. The manipulation of the argument remove results in sql …
CVE-2025-11424 critical 9.8 9.8 fabian 8mo ago A vulnerability was determined in code-projects Web-Based Inventory and POS System 1.0. This impacts an unknown function of the file /login.php. Executing manipulation of the argument emailid can lea…
CVE-2025-11422 critical 9.8 9.8 campcodes 8mo ago A vulnerability has been found in Campcodes Advanced Online Voting Management System 1.0. The impacted element is an unknown function of the file /admin/login.php. Such manipulation of the argument U…
CVE-2025-11420 critical 9.8 9.8 fabian 8mo ago A vulnerability was detected in code-projects E-Commerce Website 1.0. Impacted is an unknown function of the file /pages/edit_order_details.php. The manipulation of the argument order_id results in s…
CVE-2025-43823 unknown 8mo ago Liferay Portal is vulnerable to XSS through its Commerce Search Result widget
CVE-2025-43822 unknown 8mo ago Liferay Portal has multiple Stored XSS vulnerabilities on its View Order page
CVE-2025-11416 critical 9.8 9.8 phpgurukul 8mo ago A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown part of the file /admin/invoices.php. Performing a manipulation of the argument delid r…
CVE-2025-11415 critical 9.8 9.8 phpgurukul 8mo ago A vulnerability was identified in PHPGurukul Beauty Parlour Management System 1.1. Affected by this issue is some unknown functionality of the file /admin/customer-list.php. Such manipulation of the …
CVE-2025-11407 critical 9.8 9.8 8mo ago A weakness has been identified in D-Link DI-7001 MINI 24.04.18B1. Impacted is an unknown function of the file /upgrade_filter.asp. This manipulation of the argument path causes os command injection. …
CVE-2025-11405 critical 9.8 9.8 nikhil-bhalerao 8mo ago A vulnerability was identified in SourceCodester Hotel and Lodge Management System 1.0. This vulnerability affects unknown code of the file /del_tax.php. The manipulation of the argument ID leads to …
CVE-2025-11404 critical 9.8 9.8 nikhil-bhalerao 8mo ago A vulnerability was determined in SourceCodester Hotel and Lodge Management System 1.0. This affects an unknown part of the file /pages/save_tax.php. Executing manipulation of the argument percentage…
CVE-2025-11403 critical 9.8 9.8 nikhil-bhalerao 8mo ago A vulnerability was found in SourceCodester Hotel and Lodge Management System 1.0. Affected by this issue is some unknown functionality of the file /del_booking.php. Performing manipulation of the ar…
CVE-2025-11402 critical 9.8 9.8 nikhil-bhalerao 8mo ago A vulnerability has been found in SourceCodester Hotel and Lodge Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /del_curr.php. Such manipulation of the …
CVE-2025-11401 critical 9.8 9.8 nikhil-bhalerao 8mo ago A flaw has been found in SourceCodester Hotel and Lodge Management System 1.0. Affected is an unknown function of the file /pages/save_curr.php. This manipulation of the argument currcode causes sql …
CVE-2025-11400 critical 9.8 9.8 nikhil-bhalerao 8mo ago A vulnerability was detected in SourceCodester Hotel and Lodge Management System 1.0. This impacts an unknown function of the file /del_room.php. The manipulation of the argument ID results in sql in…
CVE-2025-11399 critical 9.8 9.8 nikhil-bhalerao 8mo ago A security vulnerability has been detected in SourceCodester Hotel and Lodge Management System 1.0. This affects an unknown function of the file /pages/save_room.php. The manipulation of the argument…
CVE-2025-11397 critical 9.8 9.8 nikhil-bhalerao 8mo ago A security flaw has been discovered in SourceCodester Hotel and Lodge Management System 1.0. The affected element is an unknown function of the file /login.php. Performing manipulation of the argumen…
CVE-2025-11396 critical 9.8 9.8 fabian 8mo ago A vulnerability was identified in code-projects Simple Food Ordering System 1.0. Impacted is an unknown function of the file /product.php. Such manipulation of the argument Category leads to sql inje…
CVE-2025-0603 critical 9.8 9.8 8mo ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Callvision Healthcare Callvision Emergency Code allows SQL Injection, Blind SQL Injection. This …
CVE-2025-11354 critical 9.8 9.8 fabian 8mo ago A flaw has been found in code-projects Online Hotel Reservation System 1.0. Affected is an unknown function of the file /admin/addslideexec.php. Executing manipulation of the argument image can lead …
CVE-2025-11350 critical 9.8 9.8 campcodes 8mo ago A security flaw has been discovered in Campcodes Online Apartment Visitor Management System 1.0. The affected element is an unknown function of the file /bwdates-reports-details.php. The manipulation…
CVE-2025-11349 critical 9.8 9.8 campcodes 8mo ago A vulnerability was identified in Campcodes Online Apartment Visitor Management System 1.0. Impacted is an unknown function of the file /search-visitor.php. The manipulation of the argument searchdat…
CVE-2025-11348 critical 9.8 9.8 campcodes 8mo ago A vulnerability was determined in Campcodes Online Apartment Visitor Management System 1.0. This issue affects some unknown processing of the file /index.php. Executing a manipulation of the argument…
CVE-2025-11347 critical 9.8 9.8 code-projects 8mo ago A vulnerability was found in code-projects Student Crud Operation up to 3.3. This vulnerability affects the function move_uploaded_file of the file add.php of the component Add Student Page/Edit Stud…
CVE-2025-43824 unknown 8mo ago Liferay Profile Widget does not prevent vCard extension spoofing
CVE-2025-27915 unknown 1.5 KEV 8mo ago Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that exists in the Classic Web Client due to insufficient sanitization of HTML content in ICS files. When a user…
CVE-2025-52472 unknown 8mo ago XWiki Platform is vulnerable to HQL injection via wiki and space search REST API
CVE-2025-11342 critical 9.8 9.8 fabian 8mo ago A weakness has been identified in code-projects Online Course Registration 1.0. This impacts an unknown function of the file /admin/edit-course.php. Executing manipulation of the argument coursecode …
CVE-2025-49594 unknown 8mo ago XWiki OIDC Authenticator: Users with "view" access can create tokens for any users they can view
CVE-2025-11341 critical 9.8 9.8 jinher 8mo ago A security flaw has been discovered in Jinher OA up to 2.0. This affects an unknown function of the file /c6/Jhsoft.Web.module/eformaspx/WebDesign.aspx/?type=SystemUserInfo&style=1. Performing manipu…
CVE-2025-11334 critical 9.8 9.8 campcodes 8mo ago A security flaw has been discovered in Campcodes Online Apartment Visitor Management System 1.0. Affected is an unknown function of the file /visitor-detail.php. The manipulation of the argument edit…
CVE-2025-11329 critical 9.8 9.8 fabian 8mo ago A flaw has been found in code-projects Online Course Registration 1.0. Impacted is an unknown function of the file /admin/manage-students.php. This manipulation of the argument ID causes sql injectio…
CVE-2025-11318 critical 9.8 9.8 tipray 8mo ago A security flaw has been discovered in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. This vulnerability affects unknown code of the file uploadWxFile.do. The manipulation of the …
CVE-2025-11317 critical 9.8 9.8 tipray 8mo ago A vulnerability was identified in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. This affects the function findRolePage of the file findSingConfigPage.do. The manipulation of the …
CVE-2025-11316 critical 9.8 9.8 tipray 8mo ago A vulnerability was determined in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. Affected by this issue is the function findCategoryPage of the file findCategoryPage.do. Executing…
CVE-2025-11315 critical 9.8 9.8 tipray 8mo ago A vulnerability was found in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. Affected by this vulnerability is the function findUserPage of the file findUserPage.do. Performing man…
CVE-2025-11314 critical 9.8 9.8 tipray 8mo ago A vulnerability has been found in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. Affected is the function findRolePage of the file findSingConfigPage.do. Such manipulation of the …
CVE-2025-11313 critical 9.8 9.8 tipray 8mo ago A flaw has been found in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. This impacts the function findRolePage of the file findRolePage.do. This manipulation of the argument sort …
CVE-2025-11312 critical 9.8 9.8 tipray 8mo ago A vulnerability was detected in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. This affects the function findModulePage of the file findModulePage.do. The manipulation of the argu…
CVE-2025-11311 critical 9.8 9.8 tipray 8mo ago A security vulnerability has been detected in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. The impacted element is the function findTenantPage of the file findTenantPage.do. The…
CVE-2025-11310 critical 9.8 9.8 tipray 8mo ago A weakness has been identified in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. The affected element is the function findFileServerPage of the file findFileServerPage.do. Executi…
CVE-2025-61882 unknown 2.5 KEVEXP 8mo ago Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise O…
CVE-2021-43226 unknown 1.5 KEV 8mo ago Microsoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a local, privileged attacker to bypass certain security mechanisms.
CVE-2013-3918 unknown 2.5 KEVEXP 8mo ago Microsoft Windows contains an out-of-bounds write vulnerability in the InformationCardSigninHelper Class ActiveX control, icardie.dll. An attacker could exploit the vulnerability by constructing a sp…
CVE-2011-3402 unknown 2.5 KEVEXP 8mo ago Microsoft Windows Kernel contains an unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers that allows remote attackers to execute arbitrary code via …
CVE-2010-3962 unknown 2.5 KEVEXP 8mo ago Microsoft Internet Explorer contains an uninitialized memory corruption vulnerability that could allow for remote code execution. The impacted product could be end-of-life (EoL) and/or end-of-service…
CVE-2010-3765 unknown 2.5 KEVEXP 8mo ago Mozilla Firefox, SeaMonkey, and Thunderbird contain an unspecified vulnerability when JavaScript is enabled. This allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameCo…
CVE-2025-11309 critical 9.8 9.8 tipray 8mo ago A security flaw has been discovered in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. Impacted is the function doFilter of the file findDeptPage.do. Performing manipulation of the…
CVE-2025-11287 critical 9.8 9.8 mcphubx 8mo ago MCPHub has an Improper Authorization vulnerability via its handleSseConnection function
CVE-2025-43825 unknown 8mo ago Liferay Portal exposes sensitive user data through its Freemarker template
CVE-2025-54286 unknown FIX debian debian 8mo ago Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions >= 5.0 on Linux allows an attacker to create and start container instances without user consent via crafted HTML form submissions…
CVE-2025-54287 unknown FIX debian debian 8mo ago Template Injection in instance snapshot creation component in Canonical LXD (>= 4.0) allows an attacker with instance configuration permissions to read arbitrary files on the host system via special…
CVE-2025-54288 unknown FIX debian debian 8mo ago Information Spoofing in devLXD Server in Canonical LXD versions 4.0 and above on Linux container platforms allows attackers with root privileges within any container to impersonate other containers a…
CVE-2025-54289 unknown FIX debian debian 8mo ago Privilege Escalation in operations API in Canonical LXD <6.5 on multiple platforms allows attacker with read permissions to hijack terminal or console sessions and execute arbitrary commands via WebS…
CVE-2025-54290 unknown FIX debian debian 8mo ago Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to determine project existence without authentication via crafted requests using wi…
CVE-2025-54293 unknown FIX debian debian 8mo ago Path Traversal in the log file retrieval function in Canonical LXD 5.0 LTS on Linux allows authenticated remote attackers to read arbitrary files on the host system via crafted log file names or symb…
CVE-2025-54291 unknown FIX debian debian 8mo ago Information disclosure in images API in Canonical LXD before 6.5 and 5.21.4 on all platforms allows unauthenticated remote attackers to determine project existence via differing HTTP status code resp…
CVE-2025-61735 unknown 8mo ago Apache Kylin Server-Side Request Forgery (SSRF) Vulnerability
CVE-2025-61734 unknown 8mo ago Apache Kylin Files or Directories Accessible to External Parties
CVE-2025-61733 unknown 8mo ago Apache Kylin Authentication Bypass Vulnerability
CVE-2025-4008 unknown 1.5 KEV 8mo ago Smartbedded Meteobridge contains a command injection vulnerability that could allow remote unauthenticated attackers to gain arbitrary command execution with elevated privileges (root) on affected de…
CVE-2025-21043 unknown 1.5 KEV 8mo ago Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so which allows remote attackers to execute arbitrary code.