9.8
CVE-2023-41527 -
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the password2 parameter in func.php.
9.8
CVE-2023-41530 -
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the app_contact parameter in appsearch.php.
6.1
CVE-2023-41529 -
Hospital Management System v4 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in func2.php via the fname and lname parameters.
6.4
CVE-2025-55134 -
In Agora Foundation Agora fall23-Alpha1 before b087490, there is XSS via tag in client/agora/public/js/editorManager.js.
5.6
CVE-2025-47806 - gstreamer1-plugins-base: GStreamer Subparse Stack Buffer Overflow
In GStreamer through 1.26.1, the subparse plugin's parse_subrip_time function may write data past the bounds of a stack buffer, leading to a crash.
8.1
CVE-2025-47219 - gstreamer1-plugins-good: GStreamer MP4 Parser Heap Overflow
In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_trak function may read past the end of a heap buffer while parsing an MP4 file, possibly leading to information disclosure.
9.8
CVE-2023-41528 -
Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in contact.php via the txtname, txtphone, and txtmail parameters.
5.3
CVE-2025-54394 -
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 has Insufficiently Protected Credentials for requests to remote Excel resources.
5.5
CVE-2025-47807 - gstreamer1-plugins-base: GStreamer Subparse NULL Pointer Dereference
In GStreamer through 1.26.1, the subparse plugin's subrip_unescape_formatting function may dereference a NULL pointer while parsing a subtitle file, leading to a crash.
6.6
CVE-2025-44779 -
An issue in Ollama v0.1.33 allows attackers to delete arbitrary files via sending a crafted packet to the endpoint /api/pull.