CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2025-26200

    Last Modified: 1 May 2025

    SQL injection in SLIMS v.9.6.1 allows a remote attacker to escalate privileges via the month parameter in the visitor_report_day.php component.

    Published: 24 Feb 2025
    4.8
    Medium

    CVE-2025-25460

    Last Modified: 12 Jun 2025

    A stored Cross-Site Scripting (XSS) vulnerability was identified in FlatPress 1.3.1 within the "Add Entry" feature. This vulnerability allows authenticated attackers to inject malicious JavaScript payloads into blog posts, which are executed when other users view the posts. The issue arises due to improper input sanitization of the "TextArea" field in the blog entry submission form.

    Published: 24 Feb 2025
    6
    Medium

    CVE-2025-23017

    Last Modified: 15 Apr 2026

    WorkOS Hosted AuthKit before 2025-01-07 allows a password authentication MFA bypass (by enrolling a new authentication factor) when the attacker knows the user's password. No exploitation occurred.

    Published: 24 Feb 2025
    9.8
    Critical

    CVE-2025-22974

    Last Modified: 25 Mar 2025

    SQL Injection vulnerability in SeaCMS v.13.2 and before allows a remote attacker to execute arbitrary code via the DoTranExecSql parameter in the phome.php component.

    Published: 24 Feb 2025
    9.8
    Critical

    CVE-2024-56525

    Last Modified: 15 Apr 2026

    In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journal Editor Role can create a new role as super admin in the journal context, and insert a backdoor plugin, by uploading a crafted XML document as a User XML Plugin.

    Published: 24 Feb 2025
    7.8
    High

    CVE-2023-52926

    Last Modified: 3 Nov 2025

    In the Linux kernel, the following vulnerability has been resolved: IORING_OP_READ did not correctly consume the provided buffer list when read i/o returned < 0 (except for -EAGAIN and -EIOCBQUEUED return). This can lead to a potential use-after-free when the completion via io_rw_done runs at separate context.

    Published: 24 Feb 2025
    6.5
    Medium

    CVE-2024-53542

    Last Modified: 15 Apr 2026

    Incorrect access control in the component /iclock/Settings?restartNCS=1 of NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 allows attackers to arbitrarily restart the NCServiceManger via a crafted GET request.

    Published: 24 Feb 2025
    9.8
    Critical

    CVE-2024-53544

    Last Modified: 15 Apr 2026

    NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability via the getCookieNames method in the smarttimeplus/MySQLConnection endpoint.

    Published: 24 Feb 2025
    9.8
    Critical

    CVE-2024-54820

    Last Modified: 15 Apr 2026

    XOne Web Monitor v02.10.2024.530 framework 1.0.4.9 was discovered to contain a SQL injection vulnerability in the login page. This vulnerability allows attackers to extract all usernames and passwords via a crafted input.

    Published: 24 Feb 2025
    9.8
    Critical

    CVE-2024-56897

    Last Modified: 3 Mar 2025

    Improper access control in the HTTP server in YI Car Dashcam v3.88 allows unrestricted file downloads, uploads, and API commands. API commands can also be made to make unauthorized modifications to the device settings, such as disabling recording, disabling sounds, factory reset.

    Published: 24 Feb 2025
    6.1
    Medium

    CVE-2024-57026

    Last Modified: 3 Mar 2025

    TawkTo Widget Version <= 1.3.7 is vulnerable to Cross Site Scripting (XSS) due to processing user input in a way that allows JavaScript execution.

    Published: 24 Feb 2025
    6.5
    Medium

    CVE-2024-57608

    Last Modified: 15 Apr 2026

    An issue in Via Browser 6.1.0 allows a a remote attacker to execute arbitrary code via the mark.via.Shell component.

    Published: 24 Feb 2025
    5.3
    Medium

    CVE-2024-57685

    Last Modified: 25 Mar 2025

    An issue in sparkshop v.1.1.7 and before allows a remote attacker to execute arbitrary code via a crafted phar file.

    Published: 24 Feb 2025
    9.8
    Critical

    CVE-2025-25513

    Last Modified: 14 Mar 2025

    Seacms <=13.3 is vulnerable to SQL Injection in admin_members.php.

    Published: 24 Feb 2025
    5.3
    Medium

    CVE-2025-1598

    Last Modified: 28 Feb 2025

    A vulnerability was found in SourceCodester Best Church Management Software 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/app/asset_crud.php. The manipulation of the argument photo1 leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 23 Feb 2025
    5.1
    Medium

    CVE-2025-1597

    Last Modified: 28 Feb 2025

    A vulnerability was found in SourceCodester Best Church Management Software 1.0. It has been classified as problematic. Affected is an unknown function of the file /admin/redirect.php. The manipulation of the argument a leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 23 Feb 2025
    6.9
    Medium

    CVE-2025-1596

    Last Modified: 28 Feb 2025

    A vulnerability was found in SourceCodester Best Church Management Software 1.0 and classified as critical. This issue affects some unknown processing of the file /fpassword.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 23 Feb 2025
    7.1
    High

    CVE-2025-22635

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in imithemes Eventer eventer allows Reflected XSS.This issue affects Eventer: from n/a through < 3.9.9.

    Published: 23 Feb 2025
    5.8
    Medium

    CVE-2025-22633

    Last Modified: 29 Apr 2026

    Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in StellarWP Give – Divi Donation Modules give-donation-modules-for-divi allows Retrieve Embedded Sensitive Data.This issue affects Give – Divi Donation Modules: from n/a through <= 2.0.0.

    Published: 23 Feb 2025
    7.1
    High

    CVE-2025-22632

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in totalsoft WooCommerce Pricing – Product Pricing woo-pricing-table allows Stored XSS.This issue affects WooCommerce Pricing – Product Pricing: from n/a through <= 1.0.9.

    Published: 23 Feb 2025
    7.1
    High

    CVE-2025-22631

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vbout Marketing Automation marketing-automation allows Reflected XSS.This issue affects Marketing Automation: from n/a through <= 1.2.6.8.

    Published: 23 Feb 2025
    6.9
    Medium

    CVE-2025-1595

    Last Modified: 15 Apr 2026

    A vulnerability has been found in Anhui Xufan Information Technology EasyCVR up to 2.7.0 and classified as problematic. This vulnerability affects unknown code of the file /api/v1/getbaseconfig. The manipulation leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 23 Feb 2025
    5.3
    Medium

    CVE-2025-1594

    Last Modified: 3 Jun 2025

    A vulnerability, which was classified as critical, was found in FFmpeg up to 7.1. This affects the function ff_aac_search_for_tns of the file libavcodec/aacenc_tns.c of the component AAC Encoder. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 23 Feb 2025
    5.1
    Medium

    CVE-2025-1593

    Last Modified: 28 Feb 2025

    A vulnerability classified as critical has been found in SourceCodester Best Employee Management System 1.0. This affects an unknown part of the file /_hr_soft/assets/uploadImage/Profile/ of the component Profile Picture Handler. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely.

    Published: 23 Feb 2025
    4.8
    Medium

    CVE-2025-1592

    Last Modified: 28 Feb 2025

    A vulnerability was found in SourceCodester Best Employee Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/Operations/Role.php of the component Add Role Page. The manipulation of the argument assign_name/description leads to cross site scripting. The attack may be launched remotely.

    Published: 23 Feb 2025
    4.8
    Medium

    CVE-2025-1591

    Last Modified: 28 Feb 2025

    A vulnerability was found in SourceCodester Employee Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /department.php of the component Department Page. The manipulation of the argument Department Name leads to cross site scripting. The attack can be launched remotely.

    Published: 23 Feb 2025
    5.1
    Medium

    CVE-2025-1590

    Last Modified: 28 Feb 2025

    A vulnerability was found in SourceCodester E-Learning System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/modules/lesson/index.php of the component List of Lessons Page. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely.

    Published: 23 Feb 2025
    5.3
    Medium

    CVE-2025-1589

    Last Modified: 24 Feb 2025

    A vulnerability was found in SourceCodester E-Learning System 1.0 and classified as problematic. This issue affects some unknown processing of the file /register.php of the component User Registration Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely.

    Published: 23 Feb 2025
    —
    Unknown

    CVE-2025-1628

    Last Modified: 19 Mar 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 23 Feb 2025
    6.9
    Medium

    CVE-2025-1588

    Last Modified: 13 Jul 2025

    A vulnerability has been found in PHPGurukul Online Nurse Hiring System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/manage-nurse.php. The manipulation of the argument profilepic leads to path traversal: '../filedir'. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions contradicting vulnerability classes.

    Published: 23 Feb 2025
    2
    Low

    CVE-2025-1467

    Last Modified: 15 Apr 2026

    Versions of the package tarteaucitronjs before 1.17.0 are vulnerable to Cross-site Scripting (XSS) via the getElemWidth() and getElemHeight(). This is related to [SNYK-JS-TARTEAUCITRONJS-8366541](https://security.snyk.io/vuln/SNYK-JS-TARTEAUCITRONJS-8366541)

    Published: 23 Feb 2025
    4.8
    Medium

    CVE-2025-1587

    Last Modified: 14 May 2025

    A vulnerability was found in SourceCodester Telecom Billing Management System 1.0. It has been rated as critical. This issue affects the function addrecords of the file main.cpp of the component Add New Record. The manipulation of the argument name/phonenumber leads to buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

    Published: 23 Feb 2025
    5.1
    Medium

    CVE-2025-1586

    Last Modified: 28 Feb 2025

    A vulnerability was found in code-projects Blood Bank System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /Blood/A-.php. The manipulation of the argument Bloodname leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 23 Feb 2025
    4.8
    Medium

    CVE-2025-1585

    Last Modified: 4 Nov 2025

    A vulnerability, which was classified as problematic, has been found in otale tale up to 2.0.5. This issue affects the function OptionsService of the file src/main/resources/templates/themes/default/partial/header.html. The manipulation of the argument logo_url leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 23 Feb 2025
    5.3
    Medium

    CVE-2025-1584

    Last Modified: 15 Apr 2026

    A vulnerability classified as problematic was found in opensolon Solon up to 3.0.8. This vulnerability affects unknown code of the file solon-projects/solon-web/solon-web-staticfiles/src/main/java/org/noear/solon/web/staticfiles/StaticMappings.java. The manipulation leads to path traversal: '../filedir'. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.0.9 is able to address this issue. The name of the patch is f46e47fd1f8455b9467d7ead3cdb0509115b2ef1. It is recommended to upgrade the affected component.

    Published: 23 Feb 2025
    5.3
    Medium

    CVE-2025-1583

    Last Modified: 28 Feb 2025

    A vulnerability classified as critical has been found in PHPGurukul Online Nurse Hiring System 1.0. This affects an unknown part of the file /admin/search-report-details.php. The manipulation of the argument searchinput leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 23 Feb 2025
    5.3
    Medium

    CVE-2025-1582

    Last Modified: 12 Jul 2025

    A vulnerability was found in PHPGurukul Online Nurse Hiring System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/all-request.php. The manipulation of the argument viewid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 23 Feb 2025
    5.3
    Medium

    CVE-2025-1581

    Last Modified: 28 Feb 2025

    A vulnerability was found in PHPGurukul Online Nurse Hiring System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /book-nurse.php?bookid=1. The manipulation of the argument contactname leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 23 Feb 2025
    5.3
    Medium

    CVE-2025-1580

    Last Modified: 7 May 2025

    A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /search-report-result.php. The manipulation of the argument searchdata leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions contradicting parameter names to be affected.

    Published: 23 Feb 2025
    4.8
    Medium

    CVE-2025-1579

    Last Modified: 12 Jul 2025

    A vulnerability was found in code-projects Blood Bank System 1.0 and classified as problematic. This issue affects some unknown processing of the file /admin/user.php. The manipulation of the argument email leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

    Published: 23 Feb 2025
    5.3
    Medium

    CVE-2025-1578

    Last Modified: 20 May 2025

    A vulnerability, which was classified as critical, was found in PHPGurukul/Campcodes Online Shopping Portal 2.1. This affects an unknown part of the file /search-result.php. The manipulation of the argument Product leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 23 Feb 2025
    5.1
    Medium

    CVE-2025-1577

    Last Modified: 3 Mar 2025

    A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank System 1.0. Affected by this issue is some unknown functionality of the file /prostatus.php. The manipulation of the argument message leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 23 Feb 2025
    6.1
    Medium

    CVE-2024-13728

    Last Modified: 15 Apr 2026

    The Accept Donations with PayPal & Stripe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the rf parameter in all versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

    Published: 23 Feb 2025
    5.3
    Medium

    CVE-2025-1576

    Last Modified: 23 Oct 2025

    A vulnerability classified as critical was found in code-projects Real Estate Property Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax_state.php. The manipulation of the argument StateName as part of String leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 23 Feb 2025
    5.3
    Medium

    CVE-2025-1575

    Last Modified: 15 Apr 2026

    A vulnerability classified as problematic has been found in Harpia DiagSystem 12. Affected is an unknown function of the file /diagsystem/PACS/atualatendimento_jpeg.php. The manipulation of the argument cod/codexame leads to improper control of resource identifiers. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 23 Feb 2025
    7.3
    High

    CVE-2022-28339

    Last Modified: 29 Jul 2025

    Trend Micro HouseCall for Home Networks version 5.3.1302 and below contains an uncontrolled search patch element vulnerability that could allow an attacker with low user privileges to create a malicious DLL that could lead to escalated privileges.

    Published: 22 Feb 2025
    10
    Critical

    CVE-2025-26776

    Last Modified: 28 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in NotFound Chaty Pro allows Upload a Web Shell to a Web Server. This issue affects Chaty Pro: from n/a through 3.3.3.

    Published: 22 Feb 2025
    7.1
    High

    CVE-2025-26774

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rock Solid Responsive Modal Builder for High Conversion – Easy Popups easy-popups allows Reflected XSS.This issue affects Responsive Modal Builder for High Conversion – Easy Popups: from n/a through <= 1.5.0.

    Published: 22 Feb 2025
    6.5
    Medium

    CVE-2025-26764

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in enituretechnology Distance Based Shipping Calculator distance-based-shipping-calculator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Distance Based Shipping Calculator: from n/a through <= 2.0.22.

    Published: 22 Feb 2025
    9.8
    Critical

    CVE-2025-26763

    Last Modified: 23 Apr 2026

    Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider ml-slider allows Object Injection.This issue affects Responsive Slider by MetaSlider: from n/a through <= 3.94.0.

    Published: 22 Feb 2025