Search Results (324521 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-43196 1 Dedebiz 1 Dedecmsv6 2025-04-28 9.1 Critical
dedecmdv6 v6.1.9 is vulnerable to Arbitrary file deletion via file_manage_control.php.
CVE-2022-42095 1 Backdropcms 1 Backdrop Cms 2025-04-28 4.8 Medium
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page content.
CVE-2022-3849 1 Wp User Merger Project 1 Wp User Merger 2025-04-28 8.8 High
The WP User Merger WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as admin
CVE-2024-46331 1 Modstart 2 Modstartcms, Mostartcms 2025-04-28 7.2 High
ModStartCMS v8.8.0 was discovered to contain an open redirect vulnerability in the redirect parameter at /admin/login. This vulnerability allows attackers to redirect users to an arbitrary website via a crafted URL.
CVE-2022-3562 1 Librenms 1 Librenms 2025-04-28 5.4 Medium
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.
CVE-2024-46293 2 Online Medicine Ordering System Project, Oretnom23 2 Online Medicine Ordering System, Online Medicine Ordering System 2025-04-28 9.8 Critical
Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Incorrect Access Control. There is a lack of authorization checks for admin operations. Specifically, an attacker can perform admin-level actions without possessing a valid session token. The application does not verify whether the user is logged in as an admin or even check for a session token at all.
CVE-2024-45870 1 Bandisoft 1 Bandiview 2025-04-28 6.5 Medium
Bandisoft BandiView 7.05 is vulnerable to Incorrect Access Control in sub_0x3d80fc via a crafted POC file.
CVE-2024-45871 1 Bandisoft 1 Bandiview 2025-04-28 6.3 Medium
Bandisoft BandiView 7.05 is Incorrect Access Control via sub_0x232bd8 resulting in denial of service (DOS).
CVE-2024-45872 1 Bandisoft 1 Bandiview 2025-04-28 6.3 Medium
Bandisoft BandiView 7.05 is vulnerable to Buffer Overflow via sub_0x410d1d. The vulnerability occurs due to insufficient validation of PSD files.
CVE-2024-46077 2 Mayurik, Online Tours And Travels Management System Project 2 Online Tours And Travels Management System, Online Tours And Travels Management System 2025-04-28 5.4 Medium
itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the val-username, val-email, val-suggestions, val-digits and state_name parameters in travellers.php.
CVE-2024-46654 1 Maccms 1 Maccms 2025-04-28 4.8 Medium
A stored cross-site scripting (XSS) vulnerability in the Add Scheduled Task module of Maccms10 v2024.1000.4040 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2024-48579 2 Mayurik, Php 2 Best House Rental Management System, Best House Rental Management System 2025-04-28 9.8 Critical
SQL Injection vulnerability in Best House rental management system project in php v.1.0 allows a remote attacker to execute arbitrary code via the username parameter of the login request.
CVE-2025-3827 1 Phpgurukul 1 Men Salon Management System 2025-04-28 7.3 High
A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/forgot-password.php. The manipulation of the argument email leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-3828 1 Phpgurukul 1 Men Salon Management System 2025-04-28 7.3 High
A vulnerability was found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/view-appointment.php?viewid=11. The manipulation of the argument remark leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
CVE-2025-3829 1 Phpgurukul 1 Men Salon Management System 2025-04-28 7.3 High
A vulnerability was found in PHPGurukul Men Salon Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/sales-reports-detail.php. The manipulation of the argument fromdate/todate leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-28072 1 Phpgurukul 1 Pre-school Enrollment System 2025-04-28 7.5 High
PHPGurukul Pre-School Enrollment System is vulnerable to Directory Traversal in manage-teachers.php.
CVE-2024-48357 1 Lylme 1 Lylme Spage 2025-04-28 9.8 Critical
LyLme Spage 1.2.0 through 1.6.0 is vulnerable to SQL Injection via /admin/apply.php.
CVE-2024-33868 2 Linqi, Microsoft 2 Linqi, Windows 2025-04-28 9.8 Critical
An issue was discovered in linqi before 1.4.0.1 on Windows. There is LDAP injection.
CVE-2024-33867 2 Linqi, Microsoft 2 Linqi, Windows 2025-04-28 4.8 Medium
An issue was discovered in linqi before 1.4.0.1 on Windows. There is a hardcoded password salt.
CVE-2024-33866 2 Linqi, Microsoft 2 Linqi, Windows 2025-04-28 5.5 Medium
An issue was discovered in linqi before 1.4.0.1 on Windows. There is /api/DocumentTemplate/{GUID] XSS.