9.8

CVSS3.1

CVE-2023-43958 -

An arbitrary file upload vulnerability in the component /jquery-file-upload/server/php/index.php of Hospital Management System v4.0 allows an unauthenticated attacker to upload any file to the server and execute arbitrary code.

๐Ÿ“… Published: April 22, 2025, midnight ๐Ÿ”„ Last Modified: May 14, 2025, 1:14 p.m.

6.5

CVSS3.1

CVE-2025-29743 -

D-Link DIR-816 A2V1.1.0B05 was found to contain a command injection in /goform/delRouting.

๐Ÿ“… Published: April 22, 2025, midnight ๐Ÿ”„ Last Modified: April 30, 2025, 1:54 p.m.

9.8

CVSS3.1

CVE-2025-43949 -

MuM (aka Mensch und Maschine) MapEdit (aka mapedit-web) 24.2.3 is vulnerable to SQL Injection that allows an attacker to execute malicious SQL statements that control a web application's database server.

๐Ÿ“… Published: April 22, 2025, midnight ๐Ÿ”„ Last Modified: April 23, 2025, 2:15 p.m.

7.3

CVSS3.1

CVE-2024-40445 -

A directory traversal vulnerability in forkosh Mime TeX before version 1.77 allows attackers on Windows systems to read or append arbitrary files by manipulating crafted input paths.

๐Ÿ“… Published: April 22, 2025, midnight ๐Ÿ”„ Last Modified: June 23, 2025, 6:33 p.m.

6.1

CVSS3.1

CVE-2023-44753 -

A stored cross-site scripting (XSS) vulnerability fin Student Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email parameter on the profile.php page.

๐Ÿ“… Published: April 22, 2025, midnight ๐Ÿ”„ Last Modified: April 24, 2025, 2:56 p.m.

0.0

CVE-2025-45959 -

DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

๐Ÿ“… Published: April 22, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 3, 2025, 5:14 p.m.

7.3

CVSS3.1

CVE-2025-29621 -

Francois Jacquet RosarioSIS v12.0.0 was discovered to contain a content spoofing vulnerability in the Theme configuration under the My Preferences module. This vulnerability allows attackers to manipulate application settings.

๐Ÿ“… Published: April 22, 2025, midnight ๐Ÿ”„ Last Modified: April 23, 2025, 2:08 p.m.

9.8

CVSS3.1

CVE-2023-44752 -

An issue in Student Study Center Desk Management System v1.0 allows attackers to bypass authentication via a crafted GET request to /php-sscdms/admin/login.php.

๐Ÿ“… Published: April 22, 2025, midnight ๐Ÿ”„ Last Modified: April 24, 2025, 2:56 p.m.

6.1

CVSS3.1

CVE-2023-43378 -

A cross-site scripting (XSS) vulnerability in Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the commento1_1 parameter.

๐Ÿ“… Published: April 22, 2025, midnight ๐Ÿ”„ Last Modified: June 23, 2025, 6:15 p.m.

5.3

CVSS4.0

CVE-2025-3849 - YXJ2018 SpringBoot-Vue-OnlineExam studentPWD unverified password change

A vulnerability classified as problematic was found in YXJ2018 SpringBoot-Vue-OnlineExam 1.0. This vulnerability affects unknown code of the file /api/studentPWD. The manipulation of the argument studentId leads to unverified password change. The attack can be initiated remotely. The exploit has beโ€ฆ

๐Ÿ“… Published: April 21, 2025, 11:31 p.m. ๐Ÿ”„ Last Modified: Oct. 15, 2025, 6:57 p.m.
Total resulsts: 343980
Page 5185 of 34,398
ยซ previous page ยป next page
Filters