Export limit exceeded: 374173 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 374173 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 374173 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (374173 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-10565 | 1 Campcodes | 1 Grocery Sales And Inventory System | 2025-09-18 | 7.3 High |
| A vulnerability was determined in Campcodes Grocery Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=delete_receiving. Executing manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. | ||||
| CVE-2025-10566 | 1 Campcodes | 1 Grocery Sales And Inventory System | 2025-09-18 | 4.3 Medium |
| A vulnerability was identified in Campcodes Grocery Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file /index.php?page=users. The manipulation of the argument page leads to cross site scripting. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. | ||||
| CVE-2025-56295 | 2 Carmelo, Code-projects | 2 Computer Laboratory System, Computer Laboratory System | 2025-09-18 | 7.3 High |
| code-projects Computer Laboratory System 1.0 has a file upload vulnerability. Staff can upload malicious files by uploading PHP backdoor files when modifying personal avatar information and use web shell connection tools to obtain server permissions. | ||||
| CVE-2025-56289 | 2 Code-projects, Fabian | 2 Document Management System, Document Management System | 2025-09-18 | 5.4 Medium |
| code-projects Document Management System 1.0 has a Cross Site Scripting (XSS) vulnerability, where attackers can leak admin's cookie information by entering malicious XSS code in the Company field when adding files. | ||||
| CVE-2025-10562 | 1 Campcodes | 1 Grocery Sales And Inventory System | 2025-09-18 | 7.3 High |
| A flaw has been found in Campcodes Grocery Sales and Inventory System 1.0. This affects an unknown function of the file /ajax.php?action=save_product. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used. | ||||
| CVE-2025-56280 | 1 Carmelo | 1 Food Ordering Review System | 2025-09-18 | 5.4 Medium |
| code-projects Food Ordering Review System 1.0 is vulnerable to Cross Site Scripting (XSS) in the area where users submit reservation information. | ||||
| CVE-2025-57119 | 1 Phpgurukul | 1 Online Library Management System | 2025-09-18 | 9.8 Critical |
| An issue in Online Library Management System v.3.0 allows an attacker to escalate privileges via the adminlogin.php component and the Login function | ||||
| CVE-2025-56276 | 1 Carmelo | 1 Food Ordering Review System | 2025-09-18 | 5.4 Medium |
| code-projects Food Ordering Review System 1.0 is vulnerable to Cross Site Scripting (XSS) in the registration function. An attacker enters malicious JavaScript code as a username, which triggers the XSS vulnerability when the admin views user information, resulting in the disclosure of the admin's cookie information. | ||||
| CVE-2025-56697 | 1 Askar634 | 1 Computer Base Test | 2025-09-18 | 6.1 Medium |
| A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the /users/adminpanel/admin/home.php?page=feedbacks file of Kashipara Computer Base Test v1.0. Attackers can inject malicious scripts via the smyFeedbacks POST parameter in /users/home.php. | ||||
| CVE-2025-57118 | 1 Phpgurukul | 1 Online Library Management System | 2025-09-18 | 9.8 Critical |
| An issue in PHPGurukul Online-Library-Management-System v3.0 allows an attacker to escalate privileges via the index.php | ||||
| CVE-2025-57117 | 1 Remyandrade | 1 Employee Management System | 2025-09-18 | 5.4 Medium |
| A Clickjacking vulnerability exists in Rems' Employee Management System 1.0. This flaw allows remote attackers to execute arbitrary JavaScript on the department.php page by injecting a malicious payload into the Department Name field under Add Department. | ||||
| CVE-2024-28423 | 2 Airflow-diagrams Project, Feluelle | 2 Airflow-diagrams, Airflow-diagrams | 2025-09-18 | 9.8 Critical |
| Airflow-Diagrams v2.1.0 was discovered to contain an arbitrary file upload vulnerability in the unsafe_load function at cli.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted YML file. | ||||
| CVE-2024-28425 | 1 Linkedin | 1 Greykite | 2025-09-18 | 7.5 High |
| greykite v1.0.0 was discovered to contain an arbitrary file upload vulnerability in the load_obj function at /templates/pickle_utils.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted file. | ||||
| CVE-2024-29154 | 1 Danielmiessler | 1 Fabric | 2025-09-18 | 7.4 High |
| danielmiessler fabric through 1.3.0 allows installer/client/gui/static/js/index.js XSS because of innerHTML mishandling, such as in htmlToPlainText. | ||||
| CVE-2024-28392 | 1 Prestashop | 1 Abandoned Cart Reminder Pro | 2025-09-18 | 9.8 Critical |
| SQL injection vulnerability in pscartabandonmentpro v.2.0.11 and before allows a remote attacker to escalate privileges via the pscartabandonmentproFrontCAPUnsubscribeJobModuleFrontController::setEmailVisualized() method. | ||||
| CVE-2024-28395 | 2 Best-kit, Prestashopmodules | 2 Bestkit Popup, Bestkit Popup | 2025-09-18 | 9.8 Critical |
| SQL injection vulnerability in Best-Kit bestkit_popup v.1.7.2 and before allows a remote attacker to escalate privileges via the bestkit_popup.php component. | ||||
| CVE-2024-23755 | 3 Apple, Clickup, Microsoft | 3 Macos, Clickup, Windows | 2025-09-18 | 8.8 High |
| ClickUp Desktop before 3.3.77 on macOS and Windows allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings such as RunAsNode. | ||||
| CVE-2024-28386 | 2 Home-made, Home-made Io | 2 Fastmag Sync, Fastmagsync | 2025-09-18 | 9.8 Critical |
| An issue in Home-Made.io fastmagsync v.1.7.51 and before allows a remote attacker to execute arbitrary code via the getPhpBin() component. | ||||
| CVE-2024-28387 | 1 Axonaut | 1 Axonaut | 2025-09-18 | 7.5 High |
| An issue in axonaut v.3.1.23 and before allows a remote attacker to obtain sensitive information via the log.txt component. | ||||
| CVE-2024-28393 | 1 Scalapay | 1 Scalapay | 2025-09-18 | 9.8 Critical |
| SQL injection vulnerability in scalapay v.1.2.41 and before allows a remote attacker to escalate privileges via the ScalapayReturnModuleFrontController::postProcess() method. | ||||