CVE-2025-4020 - PHPGurukul Old Age Home Management System SQL Injection
CVE ID : CVE-2025-4020
Published : April 28, 2025, 1:15 p.m. | 3 hours, 29 minutes ago
Description : A vulnerability was found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /contact.php. The manipulation of the argument fname leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-4020
Published : April 28, 2025, 1:15 p.m. | 3 hours, 29 minutes ago
Description : A vulnerability was found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /contact.php. The manipulation of the argument fname leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4021 - Code-projects Patient Record Management System SQL Injection Vulnerability
CVE ID : CVE-2025-4021
Published : April 28, 2025, 1:15 p.m. | 3 hours, 29 minutes ago
Description : A vulnerability was found in code-projects Patient Record Management System 1.0. It has been classified as critical. This affects an unknown part of the file /edit_spatient.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-4021
Published : April 28, 2025, 1:15 p.m. | 3 hours, 29 minutes ago
Description : A vulnerability was found in code-projects Patient Record Management System 1.0. It has been classified as critical. This affects an unknown part of the file /edit_spatient.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4022 - Web-Arena-X Web Content Injection Vulnerability
CVE ID : CVE-2025-4022
Published : April 28, 2025, 2:15 p.m. | 2 hours, 29 minutes ago
Description : A vulnerability was found in web-arena-x webarena up to 0.2.0. It has been declared as critical. This vulnerability affects the function HTMLContentEvaluator of the file webarena/evaluation_harness/evaluators.py. The manipulation of the argument target["url"] leads to code injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-4022
Published : April 28, 2025, 2:15 p.m. | 2 hours, 29 minutes ago
Description : A vulnerability was found in web-arena-x webarena up to 0.2.0. It has been declared as critical. This vulnerability affects the function HTMLContentEvaluator of the file webarena/evaluation_harness/evaluators.py. The manipulation of the argument target["url"] leads to code injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4023 - iSourcecode Placement Management System SQL Injection
CVE ID : CVE-2025-4023
Published : April 28, 2025, 2:15 p.m. | 2 hours, 29 minutes ago
Description : A vulnerability was found in itsourcecode Placement Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /add_company.php. The manipulation of the argument Name leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-4023
Published : April 28, 2025, 2:15 p.m. | 2 hours, 29 minutes ago
Description : A vulnerability was found in itsourcecode Placement Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /add_company.php. The manipulation of the argument Name leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2015-2079 - Usermin File Open Vulnerability
CVE ID : CVE-2015-2079
Published : April 28, 2025, 3:15 p.m. | 1 hour, 28 minutes ago
Description : Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the two argument (not three argument) form of Perl open.
Severity: 9.9 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2015-2079
Published : April 28, 2025, 3:15 p.m. | 1 hour, 28 minutes ago
Description : Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the two argument (not three argument) form of Perl open.
Severity: 9.9 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-23375 - Dell PowerProtect Data Manager Privilege Escalation Vulnerability
CVE ID : CVE-2025-23375
Published : April 28, 2025, 3:15 p.m. | 1 hour, 28 minutes ago
Description : Dell PowerProtect Data Manager Reporting, version(s) 19.17, contain(s) an Incorrect Use of Privileged APIs vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-23375
Published : April 28, 2025, 3:15 p.m. | 1 hour, 28 minutes ago
Description : Dell PowerProtect Data Manager Reporting, version(s) 19.17, contain(s) an Incorrect Use of Privileged APIs vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-23376 - Dell PowerProtect Data Manager Template Engine Template Injection Vulnerability
CVE ID : CVE-2025-23376
Published : April 28, 2025, 3:15 p.m. | 1 hour, 28 minutes ago
Description : Dell PowerProtect Data Manager Reporting, version(s) 19.16, 19.17, 19.18, contain(s) an Improper Neutralization of Special Elements Used in a Template Engine vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.
Severity: 2.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-23376
Published : April 28, 2025, 3:15 p.m. | 1 hour, 28 minutes ago
Description : Dell PowerProtect Data Manager Reporting, version(s) 19.16, 19.17, 19.18, contain(s) an Improper Neutralization of Special Elements Used in a Template Engine vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.
Severity: 2.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-23377 - Dell PowerProtect Data Manager Cross-Site Scripting (XSS)
CVE ID : CVE-2025-23377
Published : April 28, 2025, 3:15 p.m. | 1 hour, 28 minutes ago
Description : Dell PowerProtect Data Manager Reporting, version(s) 19.17, 19.18 contain(s) an Improper Encoding or Escaping of Output vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to inject arbitrary web script or html in reporting outputs.
Severity: 4.2 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-23377
Published : April 28, 2025, 3:15 p.m. | 1 hour, 28 minutes ago
Description : Dell PowerProtect Data Manager Reporting, version(s) 19.17, 19.18 contain(s) an Improper Encoding or Escaping of Output vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to inject arbitrary web script or html in reporting outputs.
Severity: 4.2 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-25776 - Codeastro Bus Ticket Booking System XSS
CVE ID : CVE-2025-25776
Published : April 28, 2025, 3:15 p.m. | 1 hour, 28 minutes ago
Description : Cross-Site Scripting (XSS) vulnerability exists in the User Registration and User Profile features of Codeastro Bus Ticket Booking System v1.0 allows an attacker to execute arbitrary code into the Full Name and Address fields during user registration or profile editing.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-25776
Published : April 28, 2025, 3:15 p.m. | 1 hour, 28 minutes ago
Description : Cross-Site Scripting (XSS) vulnerability exists in the User Registration and User Profile features of Codeastro Bus Ticket Booking System v1.0 allows an attacker to execute arbitrary code into the Full Name and Address fields during user registration or profile editing.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4024 - iSourcecode Placement Management System SQL Injection Vulnerability
CVE ID : CVE-2025-4024
Published : April 28, 2025, 3:15 p.m. | 1 hour, 28 minutes ago
Description : A vulnerability classified as critical has been found in itsourcecode Placement Management System 1.0. Affected is an unknown function of the file /add_drive.php. The manipulation of the argument drive_title leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-4024
Published : April 28, 2025, 3:15 p.m. | 1 hour, 28 minutes ago
Description : A vulnerability classified as critical has been found in itsourcecode Placement Management System 1.0. Affected is an unknown function of the file /add_drive.php. The manipulation of the argument drive_title leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4025 - iSourcecode Placement Management System SQL Injection
CVE ID : CVE-2025-4025
Published : April 28, 2025, 3:15 p.m. | 1 hour, 28 minutes ago
Description : A vulnerability classified as critical was found in itsourcecode Placement Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /registration.php. The manipulation of the argument Name leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-4025
Published : April 28, 2025, 3:15 p.m. | 1 hour, 28 minutes ago
Description : A vulnerability classified as critical was found in itsourcecode Placement Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /registration.php. The manipulation of the argument Name leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2015-4582 - TheCartPress Boot Store WordPress Header PHP TCP Register Error XSS
CVE ID : CVE-2015-4582
Published : April 28, 2025, 4:15 p.m. | 29 minutes ago
Description : The TheCartPress boot-store (aka Boot Store) theme 1.6.4 for WordPress allows header.php tcp_register_error XSS. NOTE: CVE-2015-4582 is not assigned to any Oracle product.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2015-4582
Published : April 28, 2025, 4:15 p.m. | 29 minutes ago
Description : The TheCartPress boot-store (aka Boot Store) theme 1.6.4 for WordPress allows header.php tcp_register_error XSS. NOTE: CVE-2015-4582 is not assigned to any Oracle product.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2022-41871 - SEPPmail Root Command Injection Vulnerability
CVE ID : CVE-2022-41871
Published : April 28, 2025, 4:15 p.m. | 29 minutes ago
Description : SEPPmail through 12.1.17 allows command injection within the Admin Portal. An authenticated attacker is able to execute arbitrary code in the context of the user root.
Severity: 6.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2022-41871
Published : April 28, 2025, 4:15 p.m. | 29 minutes ago
Description : SEPPmail through 12.1.17 allows command injection within the Admin Portal. An authenticated attacker is able to execute arbitrary code in the context of the user root.
Severity: 6.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-35814 - DevExpress ASP.NET XtraReport Data Serialization Deserialization Vulnerability
CVE ID : CVE-2023-35814
Published : April 28, 2025, 4:15 p.m. | 29 minutes ago
Description : DevExpress before 23.1.3 does not properly protect XtraReport serialized data in ASP.NET web forms.
Severity: 3.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2023-35814
Published : April 28, 2025, 4:15 p.m. | 29 minutes ago
Description : DevExpress before 23.1.3 does not properly protect XtraReport serialized data in ASP.NET web forms.
Severity: 3.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-35815 - DevExpress XML Deserialization Data-Sourcing Protection Bypass
CVE ID : CVE-2023-35815
Published : April 28, 2025, 4:15 p.m. | 29 minutes ago
Description : DevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data.
Severity: 3.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2023-35815
Published : April 28, 2025, 4:15 p.m. | 29 minutes ago
Description : DevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data.
Severity: 3.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-35816 - DevExpress TypeConverter Remote Code Execution Vulnerability
CVE ID : CVE-2023-35816
Published : April 28, 2025, 4:15 p.m. | 29 minutes ago
Description : DevExpress before 23.1.3 allows arbitrary TypeConverter conversion.
Severity: 3.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2023-35816
Published : April 28, 2025, 4:15 p.m. | 29 minutes ago
Description : DevExpress before 23.1.3 allows arbitrary TypeConverter conversion.
Severity: 3.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2023-35817 - DevExpress AsyncDownloader SSRF
CVE ID : CVE-2023-35817
Published : April 28, 2025, 4:15 p.m. | 29 minutes ago
Description : DevExpress before 23.1.3 allows AsyncDownloader SSRF.
Severity: 5.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2023-35817
Published : April 28, 2025, 4:15 p.m. | 29 minutes ago
Description : DevExpress before 23.1.3 allows AsyncDownloader SSRF.
Severity: 5.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-43854 - DIFY Clickjacking Vulnerability
CVE ID : CVE-2025-43854
Published : April 28, 2025, 4:15 p.m. | 29 minutes ago
Description : DIFY is an open-source LLM app development platform. Prior to version 1.3.0, a clickjacking vulnerability was found in the default setup of the DIFY application, allowing malicious actors to trick users into clicking on elements of the web page without their knowledge or consent. This can lead to unauthorized actions being performed, potentially compromising the security and privacy of users. This issue has been fixed in version 1.3.0.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-43854
Published : April 28, 2025, 4:15 p.m. | 29 minutes ago
Description : DIFY is an open-source LLM app development platform. Prior to version 1.3.0, a clickjacking vulnerability was found in the default setup of the DIFY application, allowing malicious actors to trick users into clicking on elements of the web page without their knowledge or consent. This can lead to unauthorized actions being performed, potentially compromising the security and privacy of users. This issue has been fixed in version 1.3.0.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-43857 - Net::IMAP Denial of Service Memory Exhaustion Vulnerability
CVE ID : CVE-2025-43857
Published : April 28, 2025, 4:15 p.m. | 29 minutes ago
Description : Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.5.7, 0.4.20, 0.3.9, and 0.2.5, there is a possibility for denial of service by memory exhaustion when net-imap reads server responses. At any time while the client is connected, a malicious server can send can send a "literal" byte count, which is automatically read by the client's receiver thread. The response reader immediately allocates memory for the number of bytes indicated by the server response. This should not be an issue when securely connecting to trusted IMAP servers that are well-behaved. It can affect insecure connections and buggy, untrusted, or compromised servers (for example, connecting to a user supplied hostname). This issue has been patched in versions 0.5.7, 0.4.20, 0.3.9, and 0.2.5.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-43857
Published : April 28, 2025, 4:15 p.m. | 29 minutes ago
Description : Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.5.7, 0.4.20, 0.3.9, and 0.2.5, there is a possibility for denial of service by memory exhaustion when net-imap reads server responses. At any time while the client is connected, a malicious server can send can send a "literal" byte count, which is automatically read by the client's receiver thread. The response reader immediately allocates memory for the number of bytes indicated by the server response. This should not be an issue when securely connecting to trusted IMAP servers that are well-behaved. It can affect insecure connections and buggy, untrusted, or compromised servers (for example, connecting to a user supplied hostname). This issue has been patched in versions 0.5.7, 0.4.20, 0.3.9, and 0.2.5.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-46614 - Snowflake ODBC Driver Information Disclosure
CVE ID : CVE-2025-46614
Published : April 28, 2025, 4:15 p.m. | 29 minutes ago
Description : In Snowflake ODBC Driver before 3.7.0, in certain code paths, the Driver logged the whole SQL query at the INFO level, aka Insertion of Sensitive Information into a Log File.
Severity: 3.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-46614
Published : April 28, 2025, 4:15 p.m. | 29 minutes ago
Description : In Snowflake ODBC Driver before 3.7.0, in certain code paths, the Driver logged the whole SQL query at the INFO level, aka Insertion of Sensitive Information into a Log File.
Severity: 3.3 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-4026 - PHPGurukul Nipah Virus Testing Management System SQL Injection Vulnerability
CVE ID : CVE-2025-4026
Published : April 28, 2025, 4:15 p.m. | 28 minutes ago
Description : A vulnerability, which was classified as critical, has been found in PHPGurukul Nipah Virus Testing Management System 1.0. This issue affects some unknown processing of the file /profile.php. The manipulation of the argument adminname leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-4026
Published : April 28, 2025, 4:15 p.m. | 28 minutes ago
Description : A vulnerability, which was classified as critical, has been found in PHPGurukul Nipah Virus Testing Management System 1.0. This issue affects some unknown processing of the file /profile.php. The manipulation of the argument adminname leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...