Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2025-05-09 CVE-2025-4485 Injection vulnerability in Adrianmercurio GYM Management System 1.0
A vulnerability has been found in itsourcecode Gym Management System 1.0 and classified as critical.
network
low complexity
adrianmercurio CWE-74
critical
9.8
2025-05-09 CVE-2025-1993 IBM App Connect Enterprise Certified Container 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, 12.4, 12.5, 12.6, 12.7, 12.8, 12.9, and 12.10 DesignerAuthoring instances store their flows in a database that is protected by weaker than expected cryptographic algorithms that could be decrypted by a local user.
local
high complexity
CWE-521
5.1
2025-05-09 CVE-2025-4482 Injection vulnerability in Projectworlds Student Project Allocation System 1.0
A vulnerability classified as critical was found in Project Worlds Student Project Allocation System 1.0.
network
low complexity
projectworlds CWE-74
critical
9.8
2025-05-09 CVE-2025-4483 Injection vulnerability in Adrianmercurio GYM Management System 1.0
A vulnerability, which was classified as critical, has been found in itsourcecode Gym Management System 1.0.
network
low complexity
adrianmercurio CWE-74
critical
9.8
2025-05-09 CVE-2025-4480 Stack-based Buffer Overflow vulnerability in Fabianros Simple College Management System 1.0
A vulnerability was found in code-projects Simple College Management System 1.0.
local
low complexity
fabianros CWE-121
7.8
2025-05-09 CVE-2025-4481 Injection vulnerability in Oretnom23 Apartment Visitor Management System 1.0
A vulnerability was found in SourceCodester Apartment Visitor Management System 1.0.
network
low complexity
oretnom23 CWE-74
critical
9.8
2025-05-09 CVE-2025-4432 A flaw was found in Rust's Ring package.
network
low complexity
CWE-770
5.3
2025-05-09 CVE-2025-3528 A flaw was found in the Mirror Registry.
local
low complexity
CWE-276
8.2
2025-05-09 CVE-2025-3897 The EUCookieLaw plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.7.2 via the 'file_get_contents' function.
network
high complexity
CWE-22
5.9
2025-05-09 CVE-2025-4206 The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'process_export_delete' and 'process_import_delete' functions in all versions up to, and including, 4.1.1.2.
network
low complexity
CWE-22
7.2