Search

Found 34,069 results in 2250ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-13266 unknown 7mo ago vlife-base has Path Traversal vulnerability
CVE-2025-13265 unknown 7mo ago lsFusion Server is vulnerable to Path Traversal through its unpackFile function
CVE-2025-13261 unknown 7mo ago lsFusion Platform has a Path Traversal vulnerability
CVE-2025-13262 critical 9.8 9.8 lsfusion 7mo ago lsFusion Platform has a Path Traversal vulnerability
CVE-2025-13257 critical 9.8 9.8 janobe 7mo ago A security vulnerability has been detected in itsourcecode Inventory Management System 1.0. The affected element is an unknown function of the file /admin/user/index.php?view=edit. The manipulation o…
CVE-2025-47151 critical 9.5 FIX rocky rheldebian debian 7mo ago RHSA-2025:21628: lasso security update (Critical)
CVE-2025-13248 critical 9.8 9.8 pamzey 7mo ago A weakness has been identified in SourceCodester Patients Waiting Area Queue Management System 1.0. The impacted element is an unknown function of the file /php/api_patient_schedule.php. This manipul…
CVE-2025-13247 critical 9.8 9.8 phpgurukul 7mo ago A security flaw has been discovered in PHPGurukul Tourism Management System 1.0. The affected element is an unknown function of the file /admin/user-bookings.php. The manipulation of the argument uid…
CVE-2025-13242 critical 9.8 9.8 fabian 7mo ago A vulnerability has been found in code-projects Student Information System 2.0. This issue affects some unknown processing of the file /register.php. The manipulation leads to sql injection. The atta…
CVE-2025-13241 critical 9.8 9.8 fabian 7mo ago A flaw has been found in code-projects Student Information System 2.0. This vulnerability affects unknown code of the file /index.php. Executing manipulation of the argument Username can lead to sql …
CVE-2025-13240 critical 9.8 9.8 fabian 7mo ago A vulnerability was detected in code-projects Student Information System 2.0. This affects an unknown part of the file /searchquery.php. Performing manipulation of the argument s results in sql injec…
CVE-2025-13237 critical 9.8 9.8 janobe 7mo ago A security flaw has been discovered in itsourcecode Inventory Management System 1.0. Affected is an unknown function of the file /LogSignModal.PHP. The manipulation of the argument U_USERNAME results…
CVE-2025-13236 critical 9.8 9.8 janobe 7mo ago A vulnerability was identified in itsourcecode Inventory Management System 1.0. This impacts an unknown function of the file /admin/products/index.php?view=edit. The manipulation of the argument ID l…
CVE-2025-13235 critical 9.8 9.8 janobe 7mo ago A vulnerability was determined in itsourcecode Inventory Management System 1.0. This affects an unknown function of the file /admin/login.php. Executing manipulation of the argument user_email can le…
CVE-2025-13234 critical 9.8 9.8 janobe 7mo ago A vulnerability was found in itsourcecode Inventory Management System 1.0. The impacted element is an unknown function of the file /index.php?q=product. Performing manipulation of the argument PROID …
CVE-2025-13233 critical 9.8 9.8 janobe 7mo ago A vulnerability has been found in itsourcecode Inventory Management System 1.0. The affected element is an unknown function of the file /index.php?q=single-item. Such manipulation of the argument ID …
CVE-2025-13210 critical 9.8 9.8 janobe 7mo ago A security vulnerability has been detected in itsourcecode Inventory Management System 1.0. This impacts an unknown function of the file /admin/products/index.php?view=add. Such manipulation of the a…
CVE-2025-13203 critical 9.8 9.8 fabian 7mo ago A weakness has been identified in code-projects Simple Cafe Ordering System 1.0. This vulnerability affects unknown code of the file /addmem.php. Executing manipulation of the argument studentnum can…
CVE-2025-13201 critical 9.8 9.8 fabian 7mo ago A vulnerability was identified in code-projects Simple Cafe Ordering System 1.0. Affected by this issue is some unknown functionality of the file /login.php. Such manipulation of the argument Usernam…
CVE-2025-13170 critical 9.8 9.8 fabian 7mo ago A vulnerability was detected in code-projects Simple Online Hotel Reservation System 1.0. This issue affects some unknown processing of the file /admin/edit_account.php. Performing a manipulation of …
CVE-2025-13169 critical 9.8 9.8 fabian 7mo ago A security vulnerability has been detected in code-projects Simple Online Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /add_query_reserve.php. Such manipulation o…
CVE-2025-13168 critical 9.8 9.8 ury 7mo ago A weakness has been identified in ury-erp ury up to 0.2.0. This affects the function overrided_past_order_list of the file ury/ury/api/pos_extend.py. This manipulation of the argument search_term cau…
CVE-2025-64446 unknown 2.5 KEVEXP 7mo ago Fortinet FortiWeb contains a relative path traversal vulnerability that may allow an unauthenticated attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.
CVE-2025-13123 critical 9.8 9.8 amttgroup 7mo ago A flaw has been found in AMTT Hotel Broadband Operation System 1.0. The impacted element is an unknown function of the file /user/portal/get_firstdate.php. Executing manipulation of the argument uid …
CVE-2025-13122 critical 9.8 9.8 pamzey 7mo ago A vulnerability was detected in SourceCodester Patients Waiting Area Queue Management System 1.0. The affected element is the function getPatientAppointment of the file /php/api_patient_checkin.php. …
CVE-2025-64507 unknown FIX debian debian 7mo ago Incus is a system container and virtual machine manager. An issue in versions prior to 6.0.6 and 6.19.0 affects any Incus user in an environment where an unprivileged user may have root access to a c…
CVE-2025-13076 critical 9.8 9.8 fabian 7mo ago A flaw has been found in code-projects Responsive Hotel Site 1.0. The affected element is an unknown function of the file /admin/usersetting.php. Executing manipulation of the argument usname can lea…
CVE-2025-13075 critical 9.8 9.8 fabian 7mo ago A vulnerability was detected in code-projects Responsive Hotel Site 1.0. Impacted is an unknown function of the file /admin/usersettingdel.php. Performing manipulation of the argument eid results in …
CVE-2025-64500 unknown FIX debian debian 7mo ago Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundation component defines an object-oriented layer for the HTTP specification. Start…
CVE-2025-64099 unknown 7mo ago OpenAM: Using arbitrary OIDC requested claims values in id_token and user_info is allowed
CVE-2025-62780 unknown 7mo ago changedetection.io: Stored XSS in Watch update via API
CVE-2025-63396 unknown debian debian 7mo ago An issue was discovered in PyTorch v2.5 and v2.7.1. Omission of profiler.stop() can cause torch.profiler.profile (PythonTracer) to crash or hang during finalization, leading to a Denial of Service (D…
CVE-2025-13060 critical 9.8 9.8 oretnom23 7mo ago A security vulnerability has been detected in SourceCodester Survey Application System 1.0. This affects an unknown function of the file /view_survey.php. Such manipulation of the argument ID leads t…
CVE-2025-13059 critical 9.8 9.8 oretnom23 7mo ago A weakness has been identified in SourceCodester Alumni Management System 1.0. The impacted element is an unknown function of the file /manage_career.php. This manipulation of the argument ID causes …
CVE-2025-13057 critical 9.8 9.8 campcodes 7mo ago A vulnerability was identified in Campcodes School Fees Payment Management System 1.0. Impacted is an unknown function of the file /ajax.php?action=save_student. The manipulation of the argument ID l…
CVE-2025-40163 unknown FIX slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: sched/deadline: Stop dl_server before CPU goes offline IBM CI tool reported kernel warning[1] when running a CPU removal operatio…
CVE-2025-9242 unknown 1.5 KEV 7mo ago WatchGuard Firebox contains an out-of-bounds write vulnerability in the OS iked process that may allow a remote unauthenticated attacker to execute arbitrary code.
CVE-2025-62215 unknown 2.5 KEVEXP 7mo ago Microsoft Windows Kernel contains a race condition vulnerability that allows a local attacker with low-level privileges to escalate privileges. Successful exploitation of this vulnerability could ena…
CVE-2025-12480 unknown 1.5 KEV 7mo ago Gladinet Triofox contains an improper access control vulnerability that allows access to initial setup pages even after setup is complete.
CVE-2025-60724 critical 9.8 9.8 FIX windows windows microsoft 7mo ago Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
CVE-2025-64518 unknown 7mo ago CycloneDX Core (Java): BOM validation is vulnerable to XML External Entity injection
CVE-2025-12939 critical 9.8 9.8 janobe 7mo ago A security flaw has been discovered in SourceCodester Interview Management System up to 1.0. Affected by this issue is some unknown functionality of the file /addCandidate.php. The manipulation of th…
CVE-2025-12938 critical 9.8 9.8 projectworlds 7mo ago A vulnerability was identified in projectworlds Online Admission System 1.0. Affected by this vulnerability is an unknown functionality of the file /process_login.php. The manipulation of the argumen…
CVE-2025-12933 critical 9.8 9.8 janobe 7mo ago A vulnerability was identified in SourceCodester Baby Care System 1.0. This affects an unknown part of the file /updatewelcome.php?id=siteoptions&action=welcome. Such manipulation of the argument rol…
CVE-2025-12932 critical 9.8 9.8 janobe 7mo ago A vulnerability was determined in SourceCodester Baby Care System 1.0. Affected by this issue is some unknown functionality of the file /admin.php?id=inbox. This manipulation of the argument msgid ca…
CVE-2025-12931 critical 9.8 9.8 janobe 7mo ago A vulnerability was found in SourceCodester Food Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file /routers/edit-orders.php. The manipulation of the argument…
CVE-2025-12930 critical 9.8 9.8 janobe 7mo ago A vulnerability has been found in SourceCodester Food Ordering System 1.0. Affected is an unknown function of the file /view-ticket.php. The manipulation of the argument ID leads to sql injection. It…
CVE-2025-12929 critical 9.8 9.8 oretnom23 7mo ago A flaw has been found in SourceCodester Survey Application System 1.0. This impacts the function save_user/update_user of the file /LoginRegistration.php. Executing manipulation of the argument fulln…
CVE-2025-12928 critical 9.8 9.8 fabian 7mo ago A vulnerability was detected in code-projects Online Job Search Engine 1.0. This affects an unknown function of the file /login.php. Performing manipulation of the argument username/phone results in …
CVE-2025-21042 unknown 1.5 KEV 7mo ago Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so. This vulnerability could allow remote attackers to execute arbitrary code.
CVE-2025-12916 critical 9.8 9.8 sangfor 7mo ago A vulnerability was determined in Sangfor Operation and Maintenance Security Management System 3.0. Impacted is an unknown function of the file /fort/portal_login of the component Frontend. This mani…
CVE-2025-12913 critical 9.8 9.8 fabian 7mo ago A flaw has been found in code-projects Responsive Hotel Site 1.0. This affects an unknown part of the file /admin/roomdel.php. Executing manipulation of the argument ID can lead to sql injection. It …
CVE-2025-12873 critical 9.8 9.8 campcodes 7mo ago A security flaw has been discovered in Campcodes School File Management 1.0. This affects an unknown part of the file /admin/update_user.php. Performing manipulation of the argument user_id results i…
CVE-2025-12862 critical 9.8 9.8 projectworlds 7mo ago A vulnerability was identified in projectworlds Online Notes Sharing Platform 1.0. Affected by this issue is some unknown functionality of the file /dashboard/userprofile.php. Such manipulation of th…
CVE-2025-12857 critical 9.8 9.8 fabian 7mo ago A security vulnerability has been detected in code-projects Responsive Hotel Site 1.0. The affected element is an unknown function of the file /admin/roombook.php. Such manipulation of the argument r…
CVE-2025-12856 critical 9.8 9.8 fabian 7mo ago A weakness has been identified in code-projects Responsive Hotel Site 1.0. Impacted is an unknown function of the file /admin/reservation.php. This manipulation of the argument email causes sql injec…
CVE-2025-12855 critical 9.8 9.8 fabian 7mo ago A security flaw has been discovered in code-projects Responsive Hotel Site 1.0. This issue affects some unknown processing of the file /admin/newsletterdel.php. The manipulation of the argument eid r…
CVE-2025-12853 critical 9.8 9.8 mayurik 7mo ago A vulnerability was determined in SourceCodester Best House Rental Management System 1.0. This affects the function delete_house of the file /admin_class.php. Executing manipulation of the argument I…
CVE-2025-67897 unknown FIX debian debian 7mo ago In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted me…
CVE-2025-48089 critical 9.3 9.3 7mo ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rainbow-Themes Education WordPress Theme | HiStudy histudy allows SQL Injection.This issue affect…
CVE-2025-64326 unknown 7mo ago Weblate leaks the IP of project member inviting user to be reviewer in Audit log
CVE-2025-10713 unknown 7mo ago WSO2 Carbon Mediation vulnerable to XML External Entity (XXE) attacks
CVE-2025-64459 unknown 1.0 EXPFIX debian debian 7mo ago Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.
CVE-2025-64458 unknown FIX debian debian 7mo ago Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
CVE-2025-48703 unknown 1.5 KEV 7mo ago CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command Injection vulnerability that allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in…
CVE-2025-11371 unknown 2.5 KEVEXP 7mo ago Gladinet CentreStack and Triofox contains a files or directories accessible to external parties vulnerability that allows unintended disclosure of system files.
CVE-2025-11953 unknown 1.5 KEV 7mo ago React Native Community CLI contains an OS command injection vulnerability which could allow unauthenticated network attackers to send POST requests to the Metro Development Server and run arbitrary e…
CVE-2025-0987 critical 9.9 9.9 7mo ago Authorization Bypass Through User-Controlled Key vulnerability in CB Project Ltd. Co. CVLand allows Parameter Injection. This issue affects CVLand: from 2.1.0 through 20251103. NOTE: The vendor was …
CVE-2025-12617 critical 9.8 9.8 angeljudesuarez 7mo ago A flaw has been found in itsourcecode Billing System 1.0. This affects an unknown function of the file /admin/app/login_crud.php. Executing a manipulation of the argument Password can lead to sql inj…
CVE-2025-12614 critical 9.8 9.8 mayurik 7mo ago A weakness has been identified in SourceCodester Best House Rental Management System 1.0. Impacted is the function delete_payment of the file /admin_class.php. This manipulation of the argument ID ca…
CVE-2025-12612 critical 9.8 9.8 campcodes 7mo ago A security flaw has been discovered in Campcodes School Fees Payment Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=delete_course. The manipulation of …
CVE-2025-12608 critical 9.8 9.8 angeljudesuarez 7mo ago A security flaw has been discovered in itsourcecode Online Loan Management System 1.0. The affected element is an unknown function of the file /manage_user.php. Performing manipulation of the argumen…
CVE-2025-12607 critical 9.8 9.8 angeljudesuarez 7mo ago A vulnerability was identified in itsourcecode Online Loan Management System 1.0. Impacted is an unknown function of the file /manage_payment.php. Such manipulation of the argument ID leads to sql in…
CVE-2025-12606 critical 9.8 9.8 angeljudesuarez 7mo ago A vulnerability was determined in itsourcecode Online Loan Management System 1.0. This issue affects some unknown processing of the file /manage_borrower.php. This manipulation of the argument ID cau…
CVE-2025-12605 critical 9.8 9.8 angeljudesuarez 7mo ago A vulnerability was found in itsourcecode Online Loan Management System 1.0. This vulnerability affects unknown code of the file /manage_loan.php. The manipulation of the argument ID results in sql i…
CVE-2025-12604 critical 9.8 9.8 angeljudesuarez 7mo ago A vulnerability has been found in itsourcecode Online Loan Management System 1.0. This affects an unknown part of the file /load_fields.php. The manipulation of the argument loan_id leads to sql inje…
CVE-2025-12598 critical 9.8 9.8 mayurik 7mo ago A flaw has been found in SourceCodester Best House Rental Management System 1.0. Affected by this issue is the function save_tenant of the file /admin_class.php. Executing manipulation of the argumen…
CVE-2025-12597 critical 9.8 9.8 mayurik 7mo ago A vulnerability was detected in SourceCodester Best House Rental Management System 1.0. Affected by this vulnerability is the function save_category of the file /admin_class.php. Performing manipulat…
CVE-2025-62275 unknown 7mo ago Liferay Portal and DXP do not check permissions of images in a blog entry
CVE-2025-62276 unknown 7mo ago Liferay Portal and DXP use an incorrect cache-control header
CVE-2025-62267 unknown 7mo ago Liferay Portal and DXP affected by multiple cross-site scripting (XSS) vulnerabilities in web content template’s select structure page
CVE-2025-62264 unknown 7mo ago Liferay Portal Vulnerable to Reflected XSS via the selectedLanguageId Parameter
CVE-2025-57108 unknown debian debian 7mo ago Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests during mesh object copy operations where vector me…
CVE-2025-57107 unknown debian debian 7mo ago Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader. When processing specially crafted GLTF files, the copy constructor of Accesso…
CVE-2025-57106 unknown debian debian 7mo ago Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerability occurs in the BufferDataExtractionWorker template function when processing…
CVE-2025-6520 critical 9.8 9.8 7mo ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Abis Technology BAPSIS allows Blind SQL Injection. This issue affects BAPSIS: before 20251027160…
CVE-2025-62265 unknown 7mo ago Liferay Portal is vulnerable to XSS in the Blogs widget
CVE-2025-62266 unknown 7mo ago Liferay Portal is vulnerable to DNS rebinding attacks
CVE-2025-62257 unknown 7mo ago Liferay Portal vulnerable to password enumeration
CVE-2025-13327 unknown FIX slesdebian debian 7mo ago A flaw was found in uv. This vulnerability allows an attacker to execute malicious code during package resolution or installation via specially crafted ZIP (Zipped Information Package) archives that …
CVE-2025-61724 unknown FIX debian debian sles 7mo ago The Reader.ReadResponse function constructs a response string through repeated string concatenation of lines. When the number of lines in a response is large, this can cause excessive CPU consumption.
CVE-2025-58188 unknown FIX debian debian sles google 7mo ago Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method. This affects programs which validate arb…
CVE-2025-58186 unknown FIX debian debian sles 7mo ago Despite HTTP headers having a default limit of 1MB, the number of cookies that can be parsed does not have a limit. By sending a lot of very small cookies such as "a=;", an attacker can make an HTTP …
CVE-2025-58185 unknown FIX debian debian sles 7mo ago Parsing a maliciously crafted DER payload could allocate large amounts of memory, causing memory exhaustion.
CVE-2025-47912 unknown FIX debian debian sles 7mo ago The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits IPv6 addresses to be included within the host compon…
CVE-2025-61723 unknown FIX debian debian sles google 7mo ago The processing time for parsing some invalid inputs scales non-linearly with respect to the size of the input. This affects programs which parse untrusted PEM inputs.
CVE-2025-58189 unknown FIX debian debian sles 7mo ago When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.
CVE-2025-58187 unknown FIX debian debian sles google 7mo ago Due to the design of the name constraint checking algorithm, the processing time of some inputs scale non-linearly with respect to the size of the certificate. This affects programs which validate ar…
CVE-2025-61725 unknown FIX debian debian sles 7mo ago The ParseAddress function constructs domain-literal address components through repeated string concatenation. When parsing large domain-literal components, this can cause excessive CPU consumption.
CVE-2025-64150 unknown 7mo ago Jenkins Publish to Bitbucket Plugin is missing a permissions check