9.3
CVE-2025-3096 - Clinics Patient Management System SQL Injection
Clinicβs Patient Management System versions 2.0 suffers from a SQL injection vulnerability in the login page.
7.5
CVE-2025-31137 - Remix and React Router allow URL manipulation via Host / X-Forwarded-Host headers
React Router is a multi-strategy router for React bridging the gap from React 18 to React 19. There is a vulnerability in Remix/React Router that affects all Remix 2 and React Router 7 consumers using the Express adapter. Basically, this vulnerability allows anyone to spoof the URL used in an incomβ¦
0.0
CVE-2023-6800 - keycloak-core: Session Fixation
No description is available for this CVE.
5.5
CVE-2025-25041 - Arbitrary File Overwrite in HPE Aruba Networking Virtual Intranet Access (VIA) Microsoft Windows Clβ¦
A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could allow malicious users to overwrite arbitrary files as NT AUTHORITY\SYSTEM (root). A successful exploit could allow the creation of a Denial-of-Service (DoS) condition affecting the Microsoft Windows Operating Sysβ¦
8.1
CVE-2025-31132 - Raven allows Remote Code Execution due to improper validation
Raven is an open-source messaging platform. A vulnerability allowed any logged in user to execute code via an API endpoint. This vulnerability is fixed in 2.1.10.
8.6
CVE-2025-31131 - Path Traversal allowing arbitrary read of files in Yeswiki
YesWiki is a wiki system written in PHP. The squelette parameter is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server. This vulnerability is fixed in 4.5.2.
7
CVE-2025-31121 - OpenEMR allows XSS in Patient Image feature
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 7.0.3.1, the Patient Image feature in OpenEMR is vulnerable to cross-site scripting attacks via the EXIF title in an image. This vulnerability is fixed in 7.0.3.1.
7.6
CVE-2025-31910 - WordPress BookingPress Plugin <= 1.1.28 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in reputeinfosystems BookingPress allows SQL Injection. This issue affects BookingPress: from n/a through 1.1.28.
7.1
CVE-2025-31908 - WordPress JSON Structuring Markup plugin <= 0.1 - CSRF to Stored XSS vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Sami Ahmed Siddiqui JSON Structuring Markup allows Stored XSS. This issue affects JSON Structuring Markup: from n/a through 0.1.
7.1
CVE-2025-31906 - WordPress WP Profitshare Plugin <= 1.4.9 - CSRF to Stored XSS vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in ProfitShare.ro WP Profitshare allows Stored XSS. This issue affects WP Profitshare: from n/a through 1.4.9.