Search

Search Results (310626 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-10566 1 Campcodes 1 Grocery Sales And Inventory System 2025-09-18 4.3 Medium
A vulnerability was identified in Campcodes Grocery Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file /index.php?page=users. The manipulation of the argument page leads to cross site scripting. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
CVE-2025-56295 2 Carmelo, Code-projects 2 Computer Laboratory System, Computer Laboratory System 2025-09-18 7.3 High
code-projects Computer Laboratory System 1.0 has a file upload vulnerability. Staff can upload malicious files by uploading PHP backdoor files when modifying personal avatar information and use web shell connection tools to obtain server permissions.
CVE-2025-56293 2 Code-projects, Fabianros 2 Human Resource Integrated System, Human Resource Integrated System 2025-09-18 5.4 Medium
code-projects Human Resource Integrated System 1.0 is vulnerable to Cross Site Scripting (XSS) in the Add Child Information section in the Childs Name field.
CVE-2025-56289 2 Code-projects, Fabian 2 Document Management System, Document Management System 2025-09-18 5.4 Medium
code-projects Document Management System 1.0 has a Cross Site Scripting (XSS) vulnerability, where attackers can leak admin's cookie information by entering malicious XSS code in the Company field when adding files.
CVE-2025-10562 1 Campcodes 1 Grocery Sales And Inventory System 2025-09-18 7.3 High
A flaw has been found in Campcodes Grocery Sales and Inventory System 1.0. This affects an unknown function of the file /ajax.php?action=save_product. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.
CVE-2025-56280 1 Carmelo 1 Food Ordering Review System 2025-09-18 5.4 Medium
code-projects Food Ordering Review System 1.0 is vulnerable to Cross Site Scripting (XSS) in the area where users submit reservation information.
CVE-2025-57119 1 Phpgurukul 1 Online Library Management System 2025-09-18 9.8 Critical
An issue in Online Library Management System v.3.0 allows an attacker to escalate privileges via the adminlogin.php component and the Login function
CVE-2025-56276 1 Carmelo 1 Food Ordering Review System 2025-09-18 5.4 Medium
code-projects Food Ordering Review System 1.0 is vulnerable to Cross Site Scripting (XSS) in the registration function. An attacker enters malicious JavaScript code as a username, which triggers the XSS vulnerability when the admin views user information, resulting in the disclosure of the admin's cookie information.
CVE-2025-56697 1 Askar634 1 Computer Base Test 2025-09-18 6.1 Medium
A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the /users/adminpanel/admin/home.php?page=feedbacks file of Kashipara Computer Base Test v1.0. Attackers can inject malicious scripts via the smyFeedbacks POST parameter in /users/home.php.
CVE-2025-57118 1 Phpgurukul 1 Online Library Management System 2025-09-18 9.8 Critical
An issue in PHPGurukul Online-Library-Management-System v3.0 allows an attacker to escalate privileges via the index.php
CVE-2025-57117 1 Remyandrade 1 Employee Management System 2025-09-18 5.4 Medium
A Clickjacking vulnerability exists in Rems' Employee Management System 1.0. This flaw allows remote attackers to execute arbitrary JavaScript on the department.php page by injecting a malicious payload into the Department Name field under Add Department.
CVE-2025-56274 1 Seniorwalter 1 Web-based Pharmacy Product Management System 2025-09-18 8.1 High
SourceCodester Web-based Pharmacy Product Management System 1.0 is vulnerable to Incorrect Access Control, which allows low-privileged users to forge high privileged (such as admin) sessions and perform sensitive operations such as adding new users.
CVE-2024-28423 1 Feluelle 1 Airflow-diagrams 2025-09-18 9.8 Critical
Airflow-Diagrams v2.1.0 was discovered to contain an arbitrary file upload vulnerability in the unsafe_load function at cli.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted YML file.
CVE-2024-28425 1 Linkedin 1 Greykite 2025-09-18 7.5 High
greykite v1.0.0 was discovered to contain an arbitrary file upload vulnerability in the load_obj function at /templates/pickle_utils.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2024-29154 1 Danielmiessler 1 Fabric 2025-09-18 7.4 High
danielmiessler fabric through 1.3.0 allows installer/client/gui/static/js/index.js XSS because of innerHTML mishandling, such as in htmlToPlainText.
CVE-2025-55241 1 Microsoft 1 Entra Id 2025-09-18 9 Critical
Azure Entra Elevation of Privilege Vulnerability
CVE-2024-28392 1 Prestashop 1 Abandoned Cart Reminder Pro 2025-09-18 9.8 Critical
SQL injection vulnerability in pscartabandonmentpro v.2.0.11 and before allows a remote attacker to escalate privileges via the pscartabandonmentproFrontCAPUnsubscribeJobModuleFrontController::setEmailVisualized() method.
CVE-2024-28395 1 Best-kit 1 Bestkit Popup 2025-09-18 9.8 Critical
SQL injection vulnerability in Best-Kit bestkit_popup v.1.7.2 and before allows a remote attacker to escalate privileges via the bestkit_popup.php component.
CVE-2024-23755 3 Apple, Clickup, Microsoft 3 Macos, Clickup, Windows 2025-09-18 8.8 High
ClickUp Desktop before 3.3.77 on macOS and Windows allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings such as RunAsNode.
CVE-2024-28386 2 Home-made, Home-made Io 2 Fastmag Sync, Fastmagsync 2025-09-18 9.8 Critical
An issue in Home-Made.io fastmagsync v.1.7.51 and before allows a remote attacker to execute arbitrary code via the getPhpBin() component.