4.8

CVSS4.0

CVE-2025-4499 - code-projects Simple Hospital Management System Add Information add stack-based overflow

A vulnerability classified as critical was found in code-projects Simple Hospital Management System 1.0. Affected by this vulnerability is the function Add of the component Add Information. The manipulation of the argument x[i].name/x[i].disease leads to stack-based buffer overflow. The attack need…

📅 Published: May 10, 2025, 11:31 a.m. 🔄 Last Modified: Oct. 23, 2025, 8:06 p.m.

6.4

CVSS3.1

CVE-2025-3878 - SMS Alert Order Notifications – WooCommerce <= 3.8.1 - Authenticated (Contributor+) Stored Cross-Si…

The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sa_verify shortcode in all versions up to, and including, 3.8.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it po…

📅 Published: May 10, 2025, 11:22 a.m. 🔄 Last Modified: April 20, 2026, 11 p.m.

8.8

CVSS3.1

CVE-2025-3876 - SMS Alert Order Notifications – WooCommerce <= 3.8.1 - Authenticated (Subscriber+) Privilege Escala…

The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to insufficient user OTP validation in the handleWpLoginCreateUserAction() function in all versions up to, and including, 3.8.1. This makes it possible for authenticated attackers, with Su…

📅 Published: May 10, 2025, 11:22 a.m. 🔄 Last Modified: April 22, 2026, 5:30 p.m.

4.8

CVSS4.0

CVE-2025-4498 - code-projects Simple Bus Reservation System Install Bus install stack-based overflow

A vulnerability classified as critical has been found in code-projects Simple Bus Reservation System 1.0. Affected is the function a::install of the component Install Bus. The manipulation of the argument bus leads to stack-based buffer overflow. It is possible to launch the attack on the local hos…

📅 Published: May 10, 2025, 10 a.m. 🔄 Last Modified: Oct. 23, 2025, 8:06 p.m.

8.8

CVSS3.1

CVE-2025-2158 - WordPress Review Plugin: The Ultimate Solution for Building a Review Website <= 5.3.5 - Authenticat…

The WordPress Review Plugin: The Ultimate Solution for Building a Review Website plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.3.5 via the Post custom fields. This makes it possible for authenticated attackers, with Contributor-level access and a…

📅 Published: May 10, 2025, 9:23 a.m. 🔄 Last Modified: April 22, 2026, 1:45 a.m.

4.8

CVSS4.0

CVE-2025-4497 - code-projects Simple Banking System Sign In buffer overflow

A vulnerability was found in code-projects Simple Banking System up to 1.0. It has been rated as critical. This issue affects some unknown processing of the component Sign In. The manipulation of the argument password2 leads to buffer overflow. Attacking locally is a requirement. The exploit has be…

📅 Published: May 10, 2025, 7 a.m. 🔄 Last Modified: May 16, 2025, 2:51 p.m.

6.4

CVSS3.1

CVE-2025-2944 - Jeg Elementor Kit <= 2.6.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via Video Bu…

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video Button and Countdown Widgets in all versions up to, and including, 2.6.12 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…

📅 Published: May 10, 2025, 5:32 a.m. 🔄 Last Modified: April 22, 2026, 1:45 a.m.

8.7

CVSS4.0

CVE-2025-4496 - TOTOLINK T10/A3100R/A950RG/A800R/N600R/A3000RU/A810R cstecgi.cgi CloudACMunualUpdate buffer overflow

A vulnerability was found in TOTOLINK T10, A3100R, A950RG, A800R, N600R, A3000RU and A810R 4.1.8cu.5241_B20210927. It has been declared as critical. This vulnerability affects the function CloudACMunualUpdate of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName leads to buffe…

📅 Published: May 10, 2025, 5 a.m. 🔄 Last Modified: July 29, 2025, 2:42 p.m.

7.5

CVSS3.1

CVE-2025-1137 - IBM Storage Scale command injection

IBM Storage Scale 5.2.2.0 and 5.2.2.1, under certain configurations, could allow an authenticated user to execute privileged commands due to improper input neutralization.

📅 Published: May 10, 2025, 1:56 a.m. 🔄 Last Modified: Feb. 26, 2026, 6:28 p.m.

5.1

CVSS4.0

CVE-2025-4495 - JAdmin-JAVA JAdmin save cross site scripting

A vulnerability has been found in JAdmin-JAVA JAdmin 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /memoAjax/save. The manipulation of the argument ID leads to cross site scripting. The attack can be launched remotely. The exploit has been…

📅 Published: May 10, 2025, 1 a.m. 🔄 Last Modified: Oct. 10, 2025, 6 p.m.
Total resulsts: 349182
Page 5470 of 34,919
« previous page » next page
Filters