CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2024-51101

    Last Modified: 29 May 2025

    PHPGURUKUL Restaurant Table Booking System using PHP and MySQL v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter at /rtbs/check-status.php.

    Published: 23 May 2025
    4.4
    Medium

    CVE-2024-51102

    Last Modified: 3 Jun 2025

    PHPGURUKUL Student Management System using PHP and MySQL v1 was discovered to contain multiple SQL injection vulnerabilities at /studentrecordms/login.php via the username and password parameters.

    Published: 23 May 2025
    4.8
    Medium

    CVE-2024-51107

    Last Modified: 29 May 2025

    Multiple stored cross-site scripting (XSS) vulnerabilities in the component /mcgs/admin/contactus.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the pagetitle, pagedes, and email parameters.

    Published: 23 May 2025
    5.4
    Medium

    CVE-2024-51108

    Last Modified: 29 May 2025

    Multiple stored cross-site scripting (XSS) vulnerabilities in the component /admin/card-bwdates-report.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the fromdate and todate parameters.

    Published: 23 May 2025
    9.8
    Critical

    CVE-2024-51360

    Last Modified: 29 May 2025

    An issue in Hospital Management System In PHP V4.0 allows a remote attacker to execute arbitrary code via the hms/doctor/edit-profile.php file

    Published: 23 May 2025
    Unknown

    CVE-2025-48745

    Last Modified: 2 Jun 2025

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-49113. Reason: This candidate is a reservation duplicate of CVE-2025-49113. Notes: All CVE users should reference CVE-2025-49113 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 23 May 2025
    6.1
    Medium

    CVE-2025-44998

    Last Modified: 31 Dec 2025

    A stored cross-site scripting (XSS) vulnerability in the component /tinyfilemanager.php of TinyFileManager v2.4.7 allows attackers to execute arbitrary JavaScript or HTML via injecting a crafted payload into the js-theme-3 parameter.

    Published: 23 May 2025
    5.4
    Medium

    CVE-2025-48701

    Last Modified: 15 Apr 2026

    openDCIM through 23.04 allows SQL injection in people_depts.php because prepared statements are not used.

    Published: 23 May 2025
    Unknown

    CVE-2025-48699

    Last Modified: 12 Jun 2025

    DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 23 May 2025
    4.3
    Medium

    CVE-2025-48735

    Last Modified: 15 Apr 2026

    A SQL Injection issue in the request body processing in BOS IPCs with firmware 21.45.8.2.2_220219 before 21.45.8.2.3_230220 allows remote attackers to obtain sensitive information from the database via crafted input in the request body.

    Published: 23 May 2025
    6.9
    Medium

    CVE-2025-48738

    Last Modified: 15 Apr 2026

    An e-mail flooding vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, 5.4.0 before 5.4.10, and 5.5.0 before 5.5.1 allows unauthenticated remote attackers to use the password reset feature without limits. This can lead to several consequences, including mailbox storage exhaustion for targeted users, reputation damage to the SMTP server, potentially causing it to be blacklisted, and overload of the SMTP server's outbound mail queue.

    Published: 23 May 2025
    5.9
    Medium

    CVE-2025-4692

    Last Modified: 15 Apr 2026

    Actors can use a maliciously crafted JavaScript object notation (JSON) web token (JWT) to perform privilege escalation by submitting the malicious JWT to a vulnerable method exposed on the cloud platform. If the exploit is successful, the user can escalate privileges to access any device managed by the ABUP Cloud Update Platform.

    Published: 22 May 2025
    6.9
    Medium

    CVE-2025-4338

    Last Modified: 15 Apr 2026

    Lantronix Device installer is vulnerable to XML external entity (XXE) attacks in configuration files read from the network device. An attacker could obtain credentials, access these network devices, and modify their configurations. An attacker may also gain access to the host running the Device Installer software or the password hash of the user running the application.

    Published: 22 May 2025
    5.8
    Medium

    CVE-2025-48371

    Last Modified: 15 Jan 2026

    OpenFGA is an authorization/permission engine. OpenFGA versions 1.8.0 through 1.8.12 (corresponding to Helm chart openfga-0.2.16 through openfga-0.2.30 and docker 1.8.0 through 1.8.12) are vulnerable to authorization bypass when certain Check and ListObject calls are executed. Users are affected under four specific conditions: First, calling Check API or ListObjects with an authorization model that has a relationship directly assignable by both type bound public access and userset; second, there are check or list object queries with contextual tuples for the relationship that can be directly assignable by both type bound public access and userset; third, those contextual tuples’s user field is an userset; and finally, type bound public access tuples are not assigned to the relationship. Users should upgrade to version 1.8.13 to receive a patch. The upgrade is backwards compatible.

    Published: 22 May 2025
    8.8
    High

    CVE-2025-47181

    Last Modified: 13 Feb 2026

    Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.

    Published: 22 May 2025
    Unknown

    CVE-2025-5102

    Last Modified: 16 Jan 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 22 May 2025
    4.8
    Medium

    CVE-2025-4975

    Last Modified: 15 Apr 2026

    When a notification relating to low battery appears for a user with whom the device has been shared, tapping the notification grants full access to the power settings of that device.

    Published: 22 May 2025
    5.5
    Medium

    CVE-2025-48374

    Last Modified: 15 Apr 2026

    zot is ancontainer image/artifact registry based on the Open Container Initiative Distribution Specification. Prior to version 2.1.3 (corresponding to pseudoversion 1.4.4-0.20250522160828-8a99a3ed231f), when using Keycloak as an oidc provider, the clientsecret gets printed into the container stdout logs for an example at container startup. Version 2.1.3 (corresponding to pseudoversion 1.4.4-0.20250522160828-8a99a3ed231f) fixes the issue.

    Published: 22 May 2025
    6.6
    Medium

    CVE-2025-48373

    Last Modified: 5 Sept 2025

    Schule is open-source school management system software. The application relies on client-side JavaScript (index.js) to redirect users to different panels based on their role. Prior to version 1.0.1, this implementation poses a serious security risk because it assumes that the value of data.role is trustworthy on the client side. Attackers can manipulate JavaScript in the browser (e.g., via browser dev tools or intercepting API responses) and set data.role to any arbitrary value (e.g., "admin"), gaining unauthorized access to restricted areas of the application.

    Published: 22 May 2025
    6.6
    Medium

    CVE-2025-48372

    Last Modified: 5 Sept 2025

    Schule is open-source school management system software. The generateOTP() function generates a 4-digit numeric One-Time Password (OTP). Prior to version 1.0.1, even if a secure random number generator is used, the short length and limited range (1000–9999) results in only 9000 possible combinations. This small keyspace makes the OTP highly vulnerable to brute-force attacks, especially in the absence of strong rate-limiting or lockout mechanisms. Version 1.0.1 fixes the issue.

    Published: 22 May 2025
    Unknown

    CVE-2025-5097

    Last Modified: 7 Jun 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 22 May 2025
    6.1
    Medium

    CVE-2024-5962

    Last Modified: 6 Oct 2025

    A reflected cross-site scripting (XSS) vulnerability exists in the authentication endpoint of multiple WSO2 products due to missing output encoding of user-supplied input. A malicious actor can exploit this vulnerability to inject arbitrary JavaScript into the authentication flow, potentially leading to UI modifications, redirections to malicious websites, or data exfiltration from the browser. While this issue could allow an attacker to manipulate the user’s browser, session-related sensitive cookies remain protected with the httpOnly flag, preventing session hijacking.

    Published: 22 May 2025
    5.8
    Medium

    CVE-2024-7487

    Last Modified: 6 Oct 2025

    An improper authentication vulnerability exists in WSO2 Identity Server 7.0.0 due to an implementation flaw that allows app-native authentication to be bypassed when an invalid object is passed. Exploitation of this vulnerability could enable malicious actors to circumvent the client verification mechanism, compromising the integrity of the authentication process.

    Published: 22 May 2025
    4.6
    Medium

    CVE-2024-7103

    Last Modified: 6 Oct 2025

    A reflected cross-site scripting (XSS) vulnerability exists in the sub-organization login flow of WSO2 Identity Server 7.0.0 due to improper input validation. A malicious actor can exploit this vulnerability to inject arbitrary JavaScript into the login flow, potentially leading to UI modifications, redirections to malicious websites, or data exfiltration from the browser. While this issue could allow an attacker to manipulate the user’s browser, session-related sensitive cookies remain protected with the httpOnly flag, preventing session hijacking.

    Published: 22 May 2025
    7.1
    High

    CVE-2024-51552

    Last Modified: 15 Apr 2026

    Weak password storage vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

    Published: 22 May 2025
    4.6
    Medium

    CVE-2024-13958

    Last Modified: 15 Apr 2026

    Stored Cross Site Scripting vulnerabilities exist in ASPECT if administrator creden-tials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

    Published: 22 May 2025
    7
    High

    CVE-2024-13957

    Last Modified: 15 Apr 2026

    SSRF Server Side Request Forgery vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

    Published: 22 May 2025
    8.8
    High

    CVE-2024-13956

    Last Modified: 15 Apr 2026

    SSL Verification Bypass vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

    Published: 22 May 2025
    9.4
    Critical

    CVE-2024-13955

    Last Modified: 15 Apr 2026

    2nd Order SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if administrator credentials become compromised.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

    Published: 22 May 2025
    5.1
    Medium

    CVE-2024-13954

    Last Modified: 15 Apr 2026

    Serialized configuration information may be disclosed during device commissioning while using ASPECT's configuration toolsetThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

    Published: 22 May 2025
    6.9
    Medium

    CVE-2024-13953

    Last Modified: 15 Apr 2026

    Sensitive device logger information in ASPECT may be exposed if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

    Published: 22 May 2025
    8.7
    High

    CVE-2024-13952

    Last Modified: 15 Apr 2026

    Predictable filename vulnerabilities in ASPECT may expose sensitive information to a potential attacker if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

    Published: 22 May 2025
    9.8
    Critical

    CVE-2024-6914

    Last Modified: 6 Oct 2025

    An incorrect authorization vulnerability exists in multiple WSO2 products due to a business logic flaw in the account recovery-related SOAP admin service. A malicious actor can exploit this vulnerability to reset the password of any user account, leading to a complete account takeover, including accounts with elevated privileges. This vulnerability is exploitable only through the account recovery SOAP admin services exposed via the "/services" context path in affected products. The impact may be reduced if access to these endpoints has been restricted based on the "Security Guidelines for Production Deployment" by disabling exposure to untrusted networks.

    Published: 22 May 2025
    7
    High

    CVE-2024-51553

    Last Modified: 15 Apr 2026

    Predictable filename vulnerabilities in ASPECT may expose sensitive information to a potential attacker if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

    Published: 22 May 2025
    6.1
    Medium

    CVE-2024-13951

    Last Modified: 15 Apr 2026

    One way hash with predictable salt vulnerabilities in ASPECT may expose sensitive information to a potential attackerThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

    Published: 22 May 2025
    6.9
    Medium

    CVE-2024-13950

    Last Modified: 15 Apr 2026

    Log injection vulnerabilities in ASPECT provide attacker access to inject malicious browser scripts if administrator credentials become compromised.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

    Published: 22 May 2025
    6.9
    Medium

    CVE-2024-13949

    Last Modified: 15 Apr 2026

    Large content vulnerabilities are present in ASPECT exposing a device to disk overutilization on a system if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

    Published: 22 May 2025
    7
    High

    CVE-2024-48848

    Last Modified: 15 Apr 2026

    Large content vulnerabilities are present in ASPECT exposing a device to disk overutilization on a system if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

    Published: 22 May 2025
    6.9
    Medium

    CVE-2024-13948

    Last Modified: 15 Apr 2026

    Windows permissions for ASPECT configuration toolsets are not fully secured allow-ing exposure of configuration informationThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

    Published: 22 May 2025
    7.1
    High

    CVE-2024-13947

    Last Modified: 15 Apr 2026

    Device commissioning parameters in ASPECT may be modified by an external source if administrative credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

    Published: 22 May 2025
    7.1
    High

    CVE-2024-13946

    Last Modified: 15 Apr 2026

    DLL's are not digitally signed when loaded in ASPECT's configuration toolset exposing the application to binary planting during device commissioning.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

    Published: 22 May 2025
    7.5
    High

    CVE-2024-13931

    Last Modified: 15 Apr 2026

    Relative Path Traversal vulnerabilities in ASPECT allow access to file resources if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.

    Published: 22 May 2025
    5.9
    Medium

    CVE-2024-13930

    Last Modified: 15 Apr 2026

    An Unchecked Loop Condition in ASPECT provides an attacker the ability to maliciously consume system resources if session administrator credentials become compromised This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.

    Published: 22 May 2025
    7.5
    High

    CVE-2024-13929

    Last Modified: 15 Apr 2026

    Servlet injection vulnerabilities in ASPECT allow remote code execution if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.

    Published: 22 May 2025
    7.5
    High

    CVE-2024-13928

    Last Modified: 15 Apr 2026

    SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.

    Published: 22 May 2025
    6
    Medium

    CVE-2025-30169

    Last Modified: 15 Apr 2026

    File upload and execute vulnerabilities in ASPECT allow PHP script injection if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.

    Published: 22 May 2025
    6
    Medium

    CVE-2025-30173

    Last Modified: 15 Apr 2026

    File upload vulnerabilities are present in ASPECT if session administrator credentials become compromised This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.

    Published: 22 May 2025
    8.9
    High

    CVE-2025-30172

    Last Modified: 15 Apr 2026

    Remote Code Execution vulnerabilities are present in ASPECT if session administrator credentials become compromised This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.

    Published: 22 May 2025
    7.3
    High

    CVE-2025-30171

    Last Modified: 15 Apr 2026

    System File Deletion vulnerabilities in ASPECT provide attackers access to delete system files if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.

    Published: 22 May 2025
    5.9
    Medium

    CVE-2025-30170

    Last Modified: 15 Apr 2026

    Exposure of file path, file size or file existence vulnerabilities in ASPECT provide attackers access to file system information if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.

    Published: 22 May 2025