Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2025-04-28 CVE-2025-4025 Injection vulnerability in Angeljudesuarez Placement Management System 1.0
A vulnerability classified as critical was found in itsourcecode Placement Management System 1.0.
network
low complexity
angeljudesuarez CWE-74
critical
9.8
2025-04-28 CVE-2025-4022 Injection vulnerability in Webarena
A vulnerability was found in web-arena-x webarena up to 0.2.0.
network
low complexity
webarena CWE-74
8.8
2025-04-28 CVE-2025-4023 Injection vulnerability in Angeljudesuarez Placement Management System 1.0
A vulnerability was found in itsourcecode Placement Management System 1.0.
network
low complexity
angeljudesuarez CWE-74
critical
9.8
2025-04-28 CVE-2025-46661 Code Injection vulnerability in Ipwsystems Metazo
IPW Systems Metazo through 8.1.3 allows unauthenticated Remote Code Execution because smartyValidator.php enables the attacker to provide template expressions, aka Server-Side Template-Injection.
network
low complexity
ipwsystems CWE-94
critical
9.8
2025-04-28 CVE-2025-4020 SQL Injection vulnerability in PHPgurukul OLD AGE Home Management System 1.0
A vulnerability was found in PHPGurukul Old Age Home Management System 1.0 and classified as critical.
network
low complexity
phpgurukul CWE-89
critical
9.8
2025-04-28 CVE-2025-4021 SQL Injection vulnerability in Code-Projects Patient Record Management System 1.0
A vulnerability was found in code-projects Patient Record Management System 1.0.
network
low complexity
code-projects CWE-89
7.5
2025-04-28 CVE-2025-4018 A vulnerability, which was classified as critical, has been found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160.
network
low complexity
CWE-306
5.3
2025-04-28 CVE-2025-4016 A vulnerability classified as critical has been found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160.
network
low complexity
CWE-266
5.4
2025-04-28 CVE-2025-4017 A vulnerability classified as problematic was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160.
network
low complexity
CWE-266
4.3
2025-04-28 CVE-2025-3200 An unauthenticated remote attacker could exploit the used, insecure TLS 1.0 and TLS 1.1 protocols to intercept and manipulate encrypted communications between the Com-Server and connected systems.
network
low complexity
CWE-327
critical
9.1