Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2025-01-03 CVE-2025-0197 SQL Injection vulnerability in Code-Projects Point of Sales and Inventory Management System 1.0
A vulnerability classified as critical was found in code-projects Point of Sales and Inventory Management System 1.0.
network
low complexity
code-projects CWE-89
6.5
2025-01-03 CVE-2025-0196 SQL Injection vulnerability in Code-Projects Point of Sales and Inventory Management System 1.0
A vulnerability classified as critical has been found in code-projects Point of Sales and Inventory Management System 1.0.
network
low complexity
code-projects CWE-89
6.5
2025-01-03 CVE-2024-56411 Cross-site Scripting vulnerability in PHPoffice PHPspreadsheet
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files.
network
low complexity
phpoffice CWE-79
5.4
2025-01-03 CVE-2024-56412 Cross-site Scripting vulnerability in PHPoffice PHPspreadsheet
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files.
network
low complexity
phpoffice CWE-79
5.4
2025-01-03 CVE-2025-0195 SQL Injection vulnerability in Code-Projects Point of Sales and Inventory Management System 1.0
A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0.
network
low complexity
code-projects CWE-89
6.5
2025-01-03 CVE-2024-41780 IBM Jazz Foundation 7.0.2, 7.0.3, and 7.1.0 could could allow a physical user to obtain sensitive information due to not masking passwords during entry.
high complexity
CWE-359
4.2
2025-01-03 CVE-2024-5591 IBM Jazz Foundation 7.0.2, 7.0.3, and 7.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.
network
low complexity
CWE-209
4.3
2025-01-03 CVE-2024-12132 Authorization Bypass Through User-Controlled Key vulnerability in Wpjobportal WP JOB Portal
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.4 due to missing validation on a user controlled key.
network
low complexity
wpjobportal CWE-639
4.3
2025-01-03 CVE-2025-0174 SQL Injection vulnerability in Code-Projects Point of Sales and Inventory Management System 1.0
A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0.
network
low complexity
code-projects CWE-89
6.5
2025-01-03 CVE-2025-0175 Cross-site Scripting vulnerability in Anisha Online Shop 1.0
A vulnerability was found in code-projects Online Shop 1.0.
network
low complexity
anisha CWE-79
6.1