CVE Feed

    Dashboard / CVE

    6
    Medium

    CVE-2022-41871

    Last Modified: 14 May 2025

    SEPPmail through 12.1.17 allows command injection within the Admin Portal. An authenticated attacker is able to execute arbitrary code in the context of the user root.

    Published: 28 Apr 2025
    7.2
    High

    CVE-2015-4582

    Last Modified: 30 Apr 2025

    The TheCartPress boot-store (aka Boot Store) theme 1.6.4 for WordPress allows header.php tcp_register_error XSS. NOTE: CVE-2015-4582 is not assigned to any Oracle product.

    Published: 28 Apr 2025
    3.5
    Low

    CVE-2023-35814

    Last Modified: 5 Jun 2025

    DevExpress before 23.1.3 does not properly protect XtraReport serialized data in ASP.NET web forms.

    Published: 28 Apr 2025
    3.5
    Low

    CVE-2023-35815

    Last Modified: 5 Jun 2025

    DevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data.

    Published: 28 Apr 2025
    3.5
    Low

    CVE-2023-35816

    Last Modified: 5 Jun 2025

    DevExpress before 23.1.3 allows arbitrary TypeConverter conversion.

    Published: 28 Apr 2025
    5
    Medium

    CVE-2023-35817

    Last Modified: 5 Jun 2025

    DevExpress before 23.1.3 allows AsyncDownloader SSRF.

    Published: 28 Apr 2025
    4.9
    Medium

    CVE-2023-42404

    Last Modified: 12 May 2025

    OneVision Workspace before WS23.1 SR1 (build w31.040) allows arbitrary Java EL execution.

    Published: 28 Apr 2025
    4.9
    Medium

    CVE-2024-32499

    Last Modified: 22 Oct 2025

    Newforma Project Center Server through 2023.3.0.32259 allows remote code execution because .NET Remoting is exposed.

    Published: 28 Apr 2025
    9.8
    Critical

    CVE-2025-45947

    Last Modified: 30 Apr 2025

    An issue in phpgurukul Online Banquet Booking System V1.2 allows an attacker to execute arbitrary code via the /obbs/change-password.php file of the My Account - Change Password component

    Published: 28 Apr 2025
    9.8
    Critical

    CVE-2025-45949

    Last Modified: 30 Apr 2025

    A critical vulnerability was found in PHPGurukul User Registration & Login and User Management System V3.3 in the /loginsystem/change-password.php file of the user panel - Change Password component. Improper handling of session data allows a Session Hijacking attack, exploitable remotely and leading to account takeover.

    Published: 28 Apr 2025
    9.1
    Critical

    CVE-2025-45953

    Last Modified: 30 Apr 2025

    A vulnerability was found in PHPGurukul Hostel Management System 2.1 in the /hostel/change-password.php file of the user panel - Change Password component. Improper handling of session data allows a Session Hijacking attack, exploitable remotely

    Published: 28 Apr 2025
    6.9
    Medium

    CVE-2025-31144

    Last Modified: 15 Apr 2026

    Quick Agent V3 and Quick Agent V2 contain an issue with improper restriction of communication channel to intended endpoints. If exploited, a remote unauthenticated attacker may attempt to log in to an arbitrary host via Windows system where the product is running.

    Published: 27 Apr 2025
    7.1
    High

    CVE-2025-27937

    Last Modified: 15 Apr 2026

    Quick Agent V3 and Quick Agent V2 contain an issue with improper limitation of a pathname to a restricted directory ('Path Traversal'). If exploited, an arbitrary file in the affected product may be obtained by a remote attacker who can log in to the product.

    Published: 27 Apr 2025
    9.2
    Critical

    CVE-2025-26692

    Last Modified: 15 Apr 2026

    Quick Agent V3 and Quick Agent V2 contain an issue with improper limitation of a pathname to a restricted directory ('Path Traversal'). If exploited, arbitrary code may be executed by a remote unauthenticated attacker with the Windows system privilege where the product is running.

    Published: 27 Apr 2025
    8.7
    High

    CVE-2025-3991

    Last Modified: 12 May 2025

    A vulnerability, which was classified as critical, was found in TOTOLINK N150RT 3.4.0-B20190525. This affects an unknown part of the file /boafrm/formWdsEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 Apr 2025
    8.7
    High

    CVE-2025-3990

    Last Modified: 12 May 2025

    A vulnerability, which was classified as critical, has been found in TOTOLINK N150RT 3.4.0-B20190525. Affected by this issue is some unknown functionality of the file /boafrm/formVlan. The manipulation of the argument submit-url leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 Apr 2025
    8.7
    High

    CVE-2025-3989

    Last Modified: 12 May 2025

    A vulnerability classified as critical was found in TOTOLINK N150RT 3.4.0-B20190525. Affected by this vulnerability is an unknown functionality of the file /boafrm/formStaticDHCP. The manipulation of the argument Hostname leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 Apr 2025
    8.7
    High

    CVE-2025-3988

    Last Modified: 7 May 2025

    A vulnerability classified as critical has been found in TOTOLINK N150RT 3.4.0-B20190525. Affected is an unknown function of the file /boafrm/formPortFw. The manipulation of the argument service_type leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 Apr 2025
    5.3
    Medium

    CVE-2025-3987

    Last Modified: 7 May 2025

    A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been rated as critical. This issue affects some unknown processing of the file /boafrm/formWsc. The manipulation of the argument localPin leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 Apr 2025
    5.3
    Medium

    CVE-2025-3986

    Last Modified: 5 Nov 2025

    A vulnerability was found in Apereo CAS 5.2.6. It has been declared as problematic. This vulnerability affects unknown code of the file cas-5.2.6\core\cas-server-core-configuration-metadata-repository\src\main\java\org\apereo\cas\metadata\rest\CasConfigurationMetadataServerController.java. The manipulation of the argument Name leads to inefficient regular expression complexity. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 27 Apr 2025
    5.1
    Medium

    CVE-2025-3985

    Last Modified: 5 Nov 2025

    A vulnerability was found in Apereo CAS 5.2.6. It has been classified as problematic. This affects the function ResponseEntity of the file cas-5.2.6\webapp-mgmt\cas-management-webapp-support\src\main\java\org\apereo\cas\mgmt\services\web\ManageRegisteredServicesMultiActionController.java. The manipulation of the argument Query leads to inefficient regular expression complexity. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 27 Apr 2025
    2.3
    Low

    CVE-2025-3984

    Last Modified: 5 Nov 2025

    A vulnerability was found in Apereo CAS 5.2.6 and classified as critical. Affected by this issue is the function saveService of the file cas-5.2.6\webapp-mgmt\cas-management-webapp-support\src\main\java\org\apereo\cas\mgmt\services\web\RegisteredServiceSimpleFormController.java of the component Groovy Code Handler. The manipulation leads to code injection. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 27 Apr 2025
    5.1
    Medium

    CVE-2025-3983

    Last Modified: 17 Oct 2025

    A vulnerability has been found in AMTT Hotel Broadband Operation System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /manager/system/nlog_down.php. The manipulation of the argument ProtocolType leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 27 Apr 2025
    2.4
    Low

    CVE-2025-2866

    Last Modified: 3 Nov 2025

    Improper Verification of Cryptographic Signature vulnerability in LibreOffice allows PDF Signature Spoofing by Improper Validation. In the affected versions of LibreOffice a flaw in the verification code for adbe.pkcs7.sha1 signatures could cause invalid signatures to be accepted as valid This issue affects LibreOffice: from 24.8 before < 24.8.6, from 25.2 before < 25.2.2.

    Published: 27 Apr 2025
    5.3
    Medium

    CVE-2025-3982

    Last Modified: 12 May 2025

    A vulnerability, which was classified as problematic, was found in nortikin Sverchok 1.3.0. Affected is the function SvSetPropNodeMK2 of the file sverchok/nodes/object_nodes/getsetprop_mk2.py of the component Set Property Mk2 Node. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 27 Apr 2025
    5.3
    Medium

    CVE-2025-3981

    Last Modified: 12 May 2025

    A vulnerability, which was classified as problematic, has been found in wowjoy 浙江湖州华卓信息科技有限公司 Internet Doctor Workstation System 1.0. This issue affects some unknown processing of the file /v1/prescription/details/. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 27 Apr 2025
    5.3
    Medium

    CVE-2025-3980

    Last Modified: 12 May 2025

    A vulnerability classified as problematic was found in wowjoy 浙江湖州华卓信息科技有限公司 Internet Doctor Workstation System 1.0. This vulnerability affects unknown code of the file /v1/prescription/list. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 27 Apr 2025
    5.3
    Medium

    CVE-2025-3979

    Last Modified: 12 May 2025

    A vulnerability classified as problematic has been found in dazhouda lecms 3.0.3. This affects an unknown part of the file /index.php?my-password-ajax-1 of the component Password Change Handler. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 Apr 2025
    5.3
    Medium

    CVE-2025-3978

    Last Modified: 12 May 2025

    A vulnerability was found in dazhouda lecms 3.0.3. It has been rated as problematic. Affected by this issue is some unknown functionality of the file admin/view/default/user_set.htm. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 Apr 2025
    5.3
    Medium

    CVE-2025-3977

    Last Modified: 12 May 2025

    A vulnerability was found in iteachyou Dreamer CMS up to 4.1.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/attachment/download of the component Attachment Handler. The manipulation of the argument ID leads to improper authorization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 27 Apr 2025
    6.9
    Medium

    CVE-2025-3976

    Last Modified: 7 May 2025

    A vulnerability was found in PHPGurukul COVID19 Testing Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /new-user-testing.php. The manipulation of the argument mobilenumber leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

    Published: 27 Apr 2025
    6.9
    Medium

    CVE-2025-3975

    Last Modified: 12 May 2025

    A vulnerability was found in ScriptAndTools eCommerce-website-in-PHP 3.0 and classified as problematic. This issue affects some unknown processing of the file /admin/subscriber-csv.php. The manipulation leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 Apr 2025
    6.9
    Medium

    CVE-2025-3974

    Last Modified: 7 May 2025

    A vulnerability has been found in PHPGurukul COVID19 Testing Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /edit-phlebotomist.php?pid=11. The manipulation of the argument mobilenumber leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

    Published: 27 Apr 2025
    6.9
    Medium

    CVE-2025-3973

    Last Modified: 7 May 2025

    A vulnerability, which was classified as critical, was found in PHPGurukul COVID19 Testing Management System 1.0. This affects an unknown part of the file /check_availability.php. The manipulation of the argument mobnumber leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

    Published: 27 Apr 2025
    6.9
    Medium

    CVE-2025-3972

    Last Modified: 7 May 2025

    A vulnerability, which was classified as critical, has been found in PHPGurukul COVID19 Testing Management System 1.0. Affected by this issue is some unknown functionality of the file /bwdates-report-result.php. The manipulation of the argument todate leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

    Published: 27 Apr 2025
    6.9
    Medium

    CVE-2025-3971

    Last Modified: 7 May 2025

    A vulnerability classified as critical was found in PHPGurukul COVID19 Testing Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /add-phlebotomist.php. The manipulation of the argument empid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 Apr 2025
    5.1
    Medium

    CVE-2025-3970

    Last Modified: 12 May 2025

    A vulnerability classified as problematic has been found in baseweb JSite up to 1.0. Affected is an unknown function of the file /sys/office/save. The manipulation of the argument Remarks leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 Apr 2025
    5.3
    Medium

    CVE-2025-3969

    Last Modified: 30 Apr 2025

    A vulnerability was found in codeprojects News Publishing Site Dashboard 1.0. It has been rated as critical. This issue affects some unknown processing of the file /edit-category.php of the component Edit Category Page. The manipulation of the argument category_image leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 Apr 2025
    5.3
    Medium

    CVE-2025-3968

    Last Modified: 30 Apr 2025

    A vulnerability was found in codeprojects News Publishing Site Dashboard 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /api.php. The manipulation of the argument cat_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 Apr 2025
    5.7
    Medium

    CVE-2025-3886

    Last Modified: 12 May 2025

    An issue in CatoNetworks CatoClient before v.5.8.0 allows attackers to escalate privileges and achieve a race condition (TOCTOU) via the PrivilegedHelperTool component.

    Published: 27 Apr 2025
    5.3
    Medium

    CVE-2025-3967

    Last Modified: 12 May 2025

    A vulnerability was found in itwanger paicoding 1.0.3. It has been classified as critical. This affects an unknown part of the file /article/api/post of the component Article Handler. The manipulation of the argument articleId leads to improper authorization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 Apr 2025
    5.3
    Medium

    CVE-2025-3966

    Last Modified: 12 May 2025

    A vulnerability was found in itwanger paicoding 1.0.3 and classified as problematic. Affected by this issue is some unknown functionality of the file /user/home?userId=1&homeSelectType=read of the component Browsing History Handler. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 Apr 2025
    5.1
    Medium

    CVE-2025-3965

    Last Modified: 12 May 2025

    A vulnerability has been found in itwanger paicoding 1.0.3 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /article/app/post. The manipulation of the argument content leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 27 Apr 2025
    5.3
    Medium

    CVE-2025-3964

    Last Modified: 12 May 2025

    A vulnerability, which was classified as problematic, was found in withstars Books-Management-System 1.0. Affected is an unknown function of the file /api/article/del of the component Article Handler. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 27 Apr 2025
    5.4
    Medium

    CVE-2024-52888

    Last Modified: 2 Sept 2025

    For an authenticated end-user the portal may run a script while attempting to display a directory or some file's properties.

    Published: 27 Apr 2025
    3.5
    Low

    CVE-2024-52887

    Last Modified: 2 Sept 2025

    Authenticated end-user may set a specially crafted SNX bookmark that can make their browser run a script while accessing their own bookmark list.

    Published: 27 Apr 2025
    6.9
    Medium

    CVE-2025-3963

    Last Modified: 12 May 2025

    A vulnerability, which was classified as critical, has been found in withstars Books-Management-System 1.0. This issue affects some unknown processing of the file /admin/article/list of the component Background Interface. The manipulation leads to missing authorization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 27 Apr 2025
    5.1
    Medium

    CVE-2025-3962

    Last Modified: 12 May 2025

    A vulnerability classified as problematic was found in withstars Books-Management-System 1.0. This vulnerability affects unknown code of the file /api/comment/add of the component Comment Handler. The manipulation of the argument content leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 27 Apr 2025
    5.1
    Medium

    CVE-2025-3961

    Last Modified: 12 May 2025

    A vulnerability classified as problematic has been found in withstars Books-Management-System 1.0. This affects an unknown part of the file /admin/article/add/do. The manipulation of the argument Title leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 27 Apr 2025
    6.9
    Medium

    CVE-2025-3960

    Last Modified: 12 May 2025

    A vulnerability was found in withstars Books-Management-System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /allreaders.html of the component Background Interface. The manipulation leads to missing authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 27 Apr 2025