5.4
CVE-2025-63449 -
Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /orders.php.
6.1
CVE-2025-63447 -
Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /add_customer.php.
7.5
CVE-2025-50735 -
Directory traversal vulnerability in NextChat thru 2.16.0 due to the WebDAV proxy failing to canonicalize or reject dot path segments in its catch-all route, allowing attackers to gain sensitive information via authenticated or anonymous WebDAV endpoints.
7.5
CVE-2024-12125 - 3scale-porta: readonly fields not validated server-side
A flaw was found in the 3scale Developer Portal. When creating or updating an account in the Developer Portal UI it is possible to modify fields explicitly configured as read-only or hidden, allowing an attacker to modify restricted information.
6.1
CVE-2025-63448 -
Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /edit_product.php?id=1.
6.5
CVE-2025-45663 -
An issue in NetSurf v3.11 causes the application to read uninitialized heap memory when creating a dom_event structure.
9.4
CVE-2025-63452 -
Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/forgot-pass.php.
5.4
CVE-2025-50363 -
Phpgurukul Maid Hiring Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in /maid-hiring.php va the name field.
5.4
CVE-2025-63450 -
Car-Booking-System-PHP v.1.0 is vulnerable to Cross Site Scripting (XSS) in /carlux/booking.php.
6.5
CVE-2024-51317 -
An issue in NetSurf v.3.11 allows a remote attacker to execute arbitrary code via the dom_node_normalize function