U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.


The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.

For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2024-47120 - IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 could allow a privileged user to escalate their privileges and attack surface on the host due to the containers running with unnecessary privileges.
    Published: September 10, 2025; 4:15:32 PM -0400

    V3.1: 6.8 MEDIUM

  • CVE-2025-52074 - PHPGURUKUL Online Shopping Portal 2.1 is vulnerable to Cross Site Scripting (XSS) due to lack of input sanitization in the quantity parameter when adding a product to the cart.
    Published: September 12, 2025; 1:15:47 PM -0400

  • CVE-2025-10372 - A weakness has been identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /intranet/educar_modulo_cad.php. This manipulation of the argument nm_tipo/descricao causes cross site scripting. It is possible to initi... read CVE-2025-10372
    Published: September 13, 2025; 2:15:31 PM -0400

    V3.1: 5.4 MEDIUM

  • CVE-2025-10373 - A security vulnerability has been detected in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the file /intranet/educar_turma_tipo_cad.php. Such manipulation of the argument nm_tipo leads to cross site scripting. It ... read CVE-2025-10373
    Published: September 13, 2025; 3:15:31 PM -0400

    V3.1: 6.1 MEDIUM

  • CVE-2025-10396 - A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. Affected by this issue is some unknown functionality of the file /admin/edit_role.php. Executing manipulation of the argument ID can lead to sql injection. It i... read CVE-2025-10396
    Published: September 14, 2025; 5:15:31 AM -0400

    V3.1: 9.8 CRITICAL

  • CVE-2025-44593 - Halo prior to 2.20.13 allows bypassing file type detection and uploading malicious files such as .exe and .html files. Specifically, .html files can trigger stored XSS vulnerabilities. This vulnerability is fixed in 2.20.13
    Published: September 09, 2025; 5:15:36 PM -0400

  • CVE-2025-44595 - Halo v2.20.17 and before is vulnerable to Cross Site Scripting (XSS) in /halo_host/archives/{name}.
    Published: September 09, 2025; 5:15:36 PM -0400

  • CVE-2025-58763 - Tautulli is a Python based monitoring and tracking tool for Plex Media Server. A command injection vulnerability in Tautulli v2.15.3 and prior allows attackers with administrative privileges to obtain remote code execution on the application serve... read CVE-2025-58763
    Published: September 09, 2025; 5:15:38 PM -0400

    V3.1: 7.2 HIGH

  • CVE-2025-10407 - A vulnerability was identified in SourceCodester Student Grading System 1.0. Affected by this vulnerability is an unknown functionality of the file /view_user.php. Such manipulation of the argument ID leads to sql injection. It is possible to laun... read CVE-2025-10407
    Published: September 14, 2025; 4:15:32 PM -0400

    V3.1: 8.8 HIGH

  • CVE-2025-58768 - DeepChat is a smart assistant uses artificial intelligence. Prior to version 0.3.5, in the Mermaid chart rendering component, there is a risky operation of directly using `innerHTML` to set user content. Therefore, any malicious content rendered v... read CVE-2025-58768
    Published: September 09, 2025; 5:15:38 PM -0400

  • CVE-2025-10408 - A security flaw has been discovered in SourceCodester Student Grading System 1.0. Affected by this issue is some unknown functionality of the file /edit_user.php. Performing manipulation of the argument ID results in sql injection. The attack can ... read CVE-2025-10408
    Published: September 14, 2025; 4:15:32 PM -0400

    V3.1: 8.8 HIGH

  • CVE-2025-23344 - The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to run code on the platform host as a non-privileged user. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges,... read CVE-2025-23344
    Published: September 09, 2025; 5:15:35 PM -0400

    V3.1: 9.8 CRITICAL

  • CVE-2025-10590 - A security flaw has been discovered in Portabilis i-Educar up to 2.10. The impacted element is an unknown function of the file /intranet/educar_usuario_det.php. The manipulation of the argument ref_pessoa results in cross site scripting. The attac... read CVE-2025-10590
    Published: September 17, 2025; 7:15:32 AM -0400

    V3.1: 6.1 MEDIUM

  • CVE-2025-10591 - A weakness has been identified in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/educar_funcao_cad.php of the component Editar Função Page. This manipulation of the argument abreviatura/tipoacao causes cross... read CVE-2025-10591
    Published: September 17, 2025; 7:15:32 AM -0400

    V3.1: 5.4 MEDIUM

  • CVE-2025-10593 - A vulnerability was detected in SourceCodester Online Student File Management System 1.0. Affected is an unknown function of the file /admin/update_student.php. Performing manipulation of the argument stud_id results in sql injection. It is possib... read CVE-2025-10593
    Published: September 17, 2025; 10:15:36 AM -0400

    V3.1: 8.8 HIGH

  • CVE-2025-10594 - A flaw has been found in SourceCodester Online Student File Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/delete_student.php. Executing manipulation of the argument stud_id can lead to sql inj... read CVE-2025-10594
    Published: September 17, 2025; 10:15:36 AM -0400

    V3.1: 8.8 HIGH

  • CVE-2025-10604 - A vulnerability was identified in PHPGurukul Online Discussion Forum 1.0. This affects an unknown part of the file /admin/edit_member.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploi... read CVE-2025-10604
    Published: September 17, 2025; 2:15:42 PM -0400

    V3.1: 9.8 CRITICAL

  • CVE-2025-10605 - A security flaw has been discovered in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /agenda_preferencias.php. The manipulation of the argument tipoacao results in cross site scripting. The attack may be launc... read CVE-2025-10605
    Published: September 17, 2025; 2:15:42 PM -0400

    V3.1: 6.1 MEDIUM

  • CVE-2025-10606 - A weakness has been identified in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /module/Configuracao/ConfiguracaoMovimentoGeral. This manipulation of the argument tipoacao causes cross site scripting. Remot... read CVE-2025-10606
    Published: September 17, 2025; 2:15:42 PM -0400

    V3.1: 6.1 MEDIUM

  • CVE-2025-10607 - A security vulnerability has been detected in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/Avaliacao/diarioApi. Such manipulation leads to information disclosure. The attack can be executed remotely. The expl... read CVE-2025-10607
    Published: September 17, 2025; 2:15:42 PM -0400

    V3.1: 6.5 MEDIUM

Created September 20, 2022 , Updated August 27, 2024