Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2025-01-02 CVE-2025-0171 SQL Injection vulnerability in Code-Projects Chat System 1.0
A vulnerability, which was classified as critical, was found in code-projects Chat System 1.0.
network
low complexity
code-projects CWE-89
7.5
2025-01-02 CVE-2024-39623 Cross-Site Request Forgery (CSRF) vulnerability in Cridio Listingpro
Cross-Site Request Forgery (CSRF) vulnerability in CridioStudio ListingPro allows Authentication Bypass.This issue affects ListingPro: from n/a through 2.9.4.
network
low complexity
cridio CWE-352
8.8
2025-01-02 CVE-2024-37093 Cross-Site Request Forgery (CSRF) vulnerability in Stylemixthemes Masterstudy LMS
Cross-Site Request Forgery (CSRF) vulnerability in StylemixThemes MasterStudy LMS allows Cross Site Request Forgery.This issue affects MasterStudy LMS: from n/a through 3.2.1.
network
low complexity
stylemixthemes CWE-352
8.8
2025-01-02 CVE-2024-37469 Cross-Site Request Forgery (CSRF) vulnerability in Creativethemes Blocksy
Cross-Site Request Forgery (CSRF) vulnerability in CreativeThemes Blocksy allows Cross Site Request Forgery.This issue affects Blocksy: from n/a through 2.0.22.
network
low complexity
creativethemes CWE-352
8.8
2025-01-02 CVE-2024-56247 SQL Injection vulnerability in Afthemes WP Post Author
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AF themes WP Post Author allows SQL Injection.This issue affects WP Post Author: from n/a through 3.8.2.
network
low complexity
afthemes CWE-89
7.2
2025-01-02 CVE-2024-56266 Missing Authorization vulnerability in Sonaar MP3 Audio Player for Music, Radio & Podcast
Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.8.
network
low complexity
sonaar CWE-862
8.8
2025-01-02 CVE-2024-13092 SQL Injection vulnerability in Code-Projects JOB Recruitment 1.0
A vulnerability classified as critical was found in code-projects Job Recruitment 1.0.
network
low complexity
code-projects CWE-89
7.5
2025-01-02 CVE-2024-13093 SQL Injection vulnerability in Code-Projects JOB Recruitment 1.0
A vulnerability, which was classified as critical, has been found in code-projects Job Recruitment 1.0.
network
low complexity
code-projects CWE-89
7.5
2025-01-01 CVE-2025-0168 SQL Injection vulnerability in Anisha JOB Recruitment 1.0
A vulnerability classified as critical has been found in code-projects Job Recruitment 1.0.
network
low complexity
anisha CWE-89
7.5
2024-12-31 CVE-2024-13079 SQL Injection vulnerability in PHPgurukul Land Record System 1.0
A vulnerability was found in PHPGurukul Land Record System 1.0 and classified as critical.
network
low complexity
phpgurukul CWE-89
8.8