Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2025-05-10 CVE-2025-4505 SQL Injection vulnerability in PHPgurukul Apartment Visitors Management System 1.0
A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0.
network
low complexity
phpgurukul CWE-89
critical
9.8
2025-05-10 CVE-2025-4506 Unspecified vulnerability in Campcodes Online Food Ordering System 1.0
A vulnerability was found in Campcodes Online Food Ordering System 1.0.
network
low complexity
campcodes
critical
9.8
2025-05-10 CVE-2025-4504 SQL Injection vulnerability in Donbermoy Online College Library System 1.0
A vulnerability was found in SourceCodester Online College Library System 1.0.
network
low complexity
donbermoy CWE-89
critical
9.8
2025-05-10 CVE-2025-4502 Injection vulnerability in Campcodes Sales and Inventory System 1.0
A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical.
network
low complexity
campcodes CWE-74
critical
9.8
2025-05-10 CVE-2025-4503 Injection vulnerability in Campcodes Sales and Inventory System 1.0
A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical.
network
low complexity
campcodes CWE-74
critical
9.8
2025-05-10 CVE-2025-4500 Out-of-bounds Write vulnerability in Code-Projects Hotel Management System 1.0
A vulnerability, which was classified as critical, has been found in code-projects Hotel Management System 1.0.
local
low complexity
code-projects CWE-787
7.8
2025-05-10 CVE-2025-4501 Out-of-bounds Write vulnerability in Fabianros Album Management System 1.0
A vulnerability, which was classified as critical, was found in code-projects Album Management System 1.0.
local
low complexity
fabianros CWE-787
7.8
2025-05-10 CVE-2025-3876 Missing Authorization vulnerability in Cozyvision SMS Alert Order Notifications
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to insufficient user OTP validation in the handleWpLoginCreateUserAction() function in all versions up to, and including, 3.8.1.
network
low complexity
cozyvision CWE-862
8.8
2025-05-10 CVE-2025-3878 Cross-site Scripting vulnerability in Cozyvision SMS Alert Order Notifications
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sa_verify shortcode in all versions up to, and including, 3.8.1 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
cozyvision CWE-79
5.4
2025-05-10 CVE-2025-4499 Out-of-bounds Write vulnerability in Fabianros Simple Hospital Management System 1.0
A vulnerability classified as critical was found in code-projects Simple Hospital Management System 1.0.
local
low complexity
fabianros CWE-787
7.8