NA - CVE-2025-50695 - PHPGurukul Online DJ Booking Management System...
PHPGurukul Online DJ Booking Management System 2.0 is vulnerable to Cross Site Scripting (XSS) in /admin/view-booking-detail.php and /admin/invoice-generating.php.
Medium - CVE-2025-6570 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, has been found in PHPGurukul Hospital Management System 4.0. Affected by this issue is some unknown functionality of the file /doctor/search.php....
NA - CVE-2024-56918 - In Netbox Community 4.1.7, the login page is...
In Netbox Community 4.1.7, the login page is vulnerable to cross-site scripting (XSS), which allows a privileged, authenticated attacker to exfiltrate user input from the login form.
Critical - CVE-2025-4378 - Cleartext Transmission of Sensitive...
Cleartext Transmission of Sensitive Information, Use of Hard-coded Credentials vulnerability in Ataturk University ATA-AOF Mobile Application allows Authentication Abuse, Authentication Bypass.This...
NA - CVE-2024-56916 - In Netbox Community 4.1.7, once authenticated,...
In Netbox Community 4.1.7, once authenticated, Configuration History > Add`is vulnerable to cross-site scripting (XSS) due to the `current value` field rendering user supplied html. An...
NA - CVE-2025-23260 - NVIDIA AIStore contains a vulnerability in the...
NVIDIA AIStore contains a vulnerability in the AIS Operator where a user may gain elevated k8s cluster access by using the ServiceAccount attached to the ClusterRole. A successful exploit of this...
NA - CVE-2025-49147 - Umbraco, a free and open source .NET content...
Umbraco, a free and open source .NET content management system, has a vulnerability in versions 10.0.0 through 10.8.10 and 13.0.0 through 13.9.1. Via a request to an anonymously authenticated...
NA - CVE-2025-53073 - In Sentry 25.1.0 through 25.5.1, an...
In Sentry 25.1.0 through 25.5.1, an authenticated attacker can access a project's issue endpoint and perform unauthorized actions (such as adding a comment) without being a member of the...
NA - CVE-2025-2566 - Kaleris NAVIS N4 ULC (Ultra Light Client)...
Kaleris NAVIS N4 ULC (Ultra Light Client) contains an unsafe Java deserialization vulnerability. An unauthenticated attacker can make specially crafted requests to execute arbitrary code on the...