High · CVSS 7.5
JATOS 3.9.4 contains a denial-of-service (DoS) vulnerability in the authentication system, where an attacker can prevent legitimate users from accessing their accounts by repeatedly sending multiple failed login attempts. Specifically, by submitting 3 incorrect login attempts every minute, the attacker can trigger the account lockout mechanism on the account level, effectively locking the user out indefinitely. Since the lockout is applied to the user account and not based on the IP address, any attacker can trigger the lockout on any user account, regardless of their privileges.
Published Jan 7, 2025 · Updated Jul 5, 2026
Medium · CVSS 5.4
MonicaHQ v4.1.2 was discovered to contain an authenticated Client-Side Injection vulnerability via the Reason parameter at /people/h:[id]/debts/create.
Published Jan 10, 2025 · Updated Jul 5, 2026
Medium · CVSS 5.4
MonicaHQ v4.1.1 was discovered to contain an authenticated Client-Side Injection vulnerability via the entry text field at /journal/entries/ID/edit.
Published Jan 10, 2025 · Updated Jul 5, 2026
High · CVSS 8.8
MonicaHQ v4.1.2 was discovered to contain multiple authenticated Client-Side Injection vulnerabilities via the title and description parameters at /people/ID/reminders/create.
Published Jan 10, 2025 · Updated Jul 5, 2026
Medium · CVSS 6.5
MonicaHQ v4.1.2 was discovered to contain multiple Client-Side Injection vulnerabilities via the first_name and last_name parameters in the Add a new relationship feature.
Published Jan 10, 2025 · Updated Jul 5, 2026
High · CVSS 8
TP-Link TL-WR940N V3 and V4 with firmware 3.16.9 and earlier contain a buffer overflow via the dnsserver1 and dnsserver2 parameters at /userRpm/Wan6to4TunnelCfgRpm.htm. This vulnerability allows an authenticated attacker to execute arbitrary code on the remote device in the context of the root user.
Published Jan 9, 2025 · Updated Jul 5, 2026
Critical · CVSS 9.1
SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to recharge members indefinitely.
Published Jan 6, 2025 · Updated Jul 5, 2026
Critical · CVSS 9.8
PHPYun before 7.0.2 is vulnerable to code execution through backdoor-restricted arbitrary file writing and file inclusion.
Published Jan 9, 2025 · Updated Jul 5, 2026
High · CVSS 8.8
An authenticated arbitrary file upload vulnerability in Car Rental Management System v1.0 to v1.3 allows attackers to execute arbitrary code via uploading a crafted file.
Published Jan 7, 2025 · Updated Jul 5, 2026
High · CVSS 7.2
Vehicle Management System 1.0 is vulnerable to SQL Injection. A guest user can exploit vulnerable POST parameters in various administrative actions, such as booking a vehicle or confirming a booking. The affected parameters include "Booking ID", "Action Name", and "Payment Confirmation ID", which are present in /newvehicle.php and /newdriver.php.
Published Jan 7, 2025 · Updated Jul 5, 2026
High · CVSS 7.5
An issue in the validate_email function in CTFd/utils/validators/__init__.py of CTFd 3.7.3 allows attackers to cause a Regular expression Denial of Service (ReDoS) via supplying a crafted string as e-mail address during registration.
Published Jan 7, 2025 · Updated Jul 5, 2026
Medium · CVSS 4.8
A cross-site scripting (XSS) vulnerability in Sunbird DCIM dcTrack v9.1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in some admin screens.
Published Dec 16, 2024 · Updated Jul 5, 2026
High · CVSS 7.5
Incorrect access control in Sunbird DCIM dcTrack v9.1.2 allows attackers to create or update a ticket with a location which bypasses an RBAC check.
Published Dec 16, 2024 · Updated Jul 5, 2026
High · CVSS 8
A Cross-Site Request Forgery (CSRF) in Sunbird DCIM dcTrack v9.1.2 allows authenticated attackers to escalate their privileges by forcing an Administrator user to perform sensitive requests in some admin screens.
Published Dec 16, 2024 · Updated Jul 5, 2026
Medium · CVSS 4.8
An HTML injection vulnerability in Sunbird DCIM dcTrack 9.1.2 allows attackers authenticated as administrators to inject arbitrary HTML code in an admin screen.
Published Dec 16, 2024 · Updated Jul 5, 2026
Medium · CVSS 6.1
A Cross Site Scripting (XSS) vulnerability in the profile.php of PHPGurukul Beauty Parlour Management System v1.1 allows remote attackers to execute arbitrary code by injecting arbitrary HTML into the "Firstname" and "Last name" parameters.
Published Dec 10, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.8
Phpgurukul's Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in `login.php` via the `emailcont` parameter.
Published Dec 10, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.8
An issue in the BYD Dilink Headunit System v3.0 to v4.0 allows attackers to bypass authentication via a bruteforce attack.
Published Dec 10, 2024 · Updated Jul 5, 2026
Medium · CVSS 6.5
A hardcoded decryption key in Thinkware Cloud APK v4.3.46 allows attackers to access sensitive data and execute arbitrary commands with elevated privileges.
Published Dec 4, 2024 · Updated Jul 5, 2026
Medium · CVSS 5.4
A SQL injection vulnerability was found in PHPGURUKUL Vehicle Parking Management System v1.13 in /users/view-detail.php. This vulnerability affects the viewid parameter, where improper input sanitization allows attackers to inject malicious SQL queries.
Published Dec 2, 2024 · Updated Jul 5, 2026
Medium · CVSS 6.1
A stored cross-site scripting (XSS) vulnerability was identified in PHPGURUKUL Vehicle Parking Management System v1.13 in /users/profile.php. This vulnerability allows authenticated users to inject malicious XSS scripts into the profile name field.
Published Nov 26, 2024 · Updated Jul 5, 2026
Medium · CVSS 4.9
SemCms v4.8 was discovered to contain a SQL injection vulnerability. This allows an attacker to execute arbitrary code via the ldgid parameter in the SEMCMS_SeoAndTag.php component.
Published Nov 20, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.8
In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter filtering. An attacker can achieve arbitrary command execution by constructing the payload.
Published Nov 22, 2024 · Updated Jul 5, 2026
High · CVSS 8.1
Tenda AC6 v2.0 v15.03.06.50 was discovered to contain a buffer overflow in the function 'fromSetSysTime.
Published Nov 19, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.8
An arbitrary file upload vulnerability in the component \Users\username.BlackBoard of BlackBoard v2.0.0.2 allows attackers to execute arbitrary code via uploading a crafted .xml file.
Published Nov 21, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.8
An arbitrary file upload vulnerability in the component \Roaming\Omega of OmegaT v6.0.1 allows attackers to execute arbitrary code via uploading a crafted .conf file.
Published Nov 21, 2024 · Updated Jul 5, 2026
High · CVSS 8.8
An arbitrary file upload vulnerability in ModbusMechanic v3.0 allows attackers to execute arbitrary code via uploading a crafted .xml file.
Published Nov 21, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.8
qiwen-file v1.4.0 was discovered to contain a SQL injection vulnerability via the component /mapper/NoticeMapper.xml.
Published Nov 26, 2024 · Updated Jul 5, 2026
Medium · CVSS 4.2
Quectel EC25-EUX EC25EUXGAR08A05M1G was discovered to contain a stack overflow.
Published Nov 27, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.1
An issue in the createTempFile method of hornetq v2.4.9 allows attackers to arbitrarily overwrite files or access sensitive information.
Published Nov 4, 2024 · Updated Jul 5, 2026
Medium · CVSS 5.3
An issue in kodbox v.1.52.04 and before allows a remote attacker to obtain sensitive information via the captcha feature in the password reset function.
Published Nov 15, 2024 · Updated Jul 5, 2026
High · CVSS 8.8
SeaCms 13.1 is vulnerable to code injection in the notification module of the member message notification module in the backend user module, due to unsafe handling of the "notify" variable in admin_notify.php.
Published Nov 8, 2024 · Updated Jul 5, 2026
Medium · CVSS 4.3
An issue in the Bluetooth Low Energy implementation of Realtek RTL8762E BLE SDK v1.4.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted ll_terminate_ind packet.
Published Nov 7, 2024 · Updated Jul 5, 2026
Low · CVSS 2.4
Hathway Skyworth Router CM5100-511 v4.1.1.24 was discovered to store sensitive information about USB and Wifi connected devices in plaintext.
Published Nov 15, 2024 · Updated Jul 5, 2026
Medium · CVSS 6.5
An Improper Authorization (Access Control Misconfiguration) vulnerability in MGT-COMMERCE GmbH CloudPanel v2.0.0 to v2.4.2 allows low-privilege users to bypass access controls and gain unauthorized access to sensitive configuration files and administrative functionality.
Published Nov 8, 2024 · Updated Jul 5, 2026
Medium · CVSS 6.1
An incorrect access control issue in HomeServe Home Repair' android app - 3.3.4 allows a physically proximate attacker to escalate privileges via the fingerprint authentication function.
Published Nov 8, 2024 · Updated Jul 5, 2026
Medium · CVSS 6.8
Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read Exchange account passwords via HTTP GET request.
Published Nov 4, 2024 · Updated Jul 5, 2026
Medium · CVSS 6.8
Insufficiently protected credentials in AD/LDAP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send AD/LDAP administrators account passwords to an arbitrary server via HTTP POST request.
Published Nov 4, 2024 · Updated Jul 5, 2026
Medium · CVSS 6.8
Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read SMTP accounts passwords via HTTP GET request.
Published Nov 4, 2024 · Updated Jul 5, 2026
Medium · CVSS 6.8
Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allow remote administrators to read proxy-server accounts passwords via HTTP GET request.
Published Nov 4, 2024 · Updated Jul 5, 2026
Medium · CVSS 6.8
Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send SMTP account passwords to an arbitrary server via HTTP POST request.
Published Nov 4, 2024 · Updated Jul 5, 2026
High · CVSS 7.5
Yealink Meeting Server before V26.0.0.67 is vulnerable to sensitive data exposure in the server response via sending HTTP request with enterprise ID.
Published Nov 1, 2024 · Updated Jul 5, 2026
High · CVSS 7.5
An Insecure Direct Object Reference (IDOR) vulnerability in appointment-detail.php in Phpgurukul's Beauty Parlour Management System v1.1 allows unauthorized access to the Personally Identifiable Information (PII) of other customers.
Published Oct 31, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.8
Phpgurukul Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in admin/index.php via the the username parameter.
Published Oct 31, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.8
Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection via the tid parameter to admin/queries.php.
Published Oct 31, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.1
Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection in add-teacher.php via the mobile number or email parameter.
Published Oct 31, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.1
Projectworlds Online Admission System v1 is vulnerable to SQL Injection in index.php via the 'a_id' parameter.
Published Oct 31, 2024 · Updated Jul 5, 2026
High · CVSS 8.4
Incorrect access control in the firmware update and download processes of Sylvania Smart Home v3.0.3 allows attackers to access sensitive information by analyzing the code and data within the APK file.
Published Oct 24, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.8
Neye3C v4.5.2.0 was discovered to contain a hardcoded encryption key in the firmware update mechanism.
Published Oct 24, 2024 · Updated Jul 5, 2026
Critical · CVSS 9.8
Incorrect access control in the firmware update and download processes of Neye3C v4.5.2.0 allows attackers to access sensitive information by analyzing the code and data within the APK file.
Published Oct 24, 2024 · Updated Jul 5, 2026