Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In February 2025
A SQL Injection vulnerability was found in /shopping/track-orders.php in PHPGurukul Online Shopping Portal v2.1, which allows remote attackers to execute arbitrary code via orderid POST request parameter.
CVSS Score
8.8
EPSS Score
0.003
Published
2025-02-14
A SQL Injection vulnerability was found in /bpms/index.php in Source Code and Project Beauty Parlour Management System V1.1, which allows remote attackers to execute arbitrary code via the name POST request parameter.
CVSS Score
5.9
EPSS Score
0.001
Published
2025-02-14
A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the manage-employee.php page of Kashipara Online Attendance Management System V1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the department parameter.
CVSS Score
5.6
EPSS Score
0.001
Published
2025-02-14
Cross Site Scripting vulnerability in hooskcms v.1.8 allows a remote attacker to cause a denial of service via the custom Link title parameter and the Title parameter.
CVSS Score
4.8
EPSS Score
0.0
Published
2025-02-14
Cross Site Scripting vulnerability in hooskcms v.1.7.1 allows a remote attacker to obtain sensitive information via the /install/index.php component.
CVSS Score
6.1
EPSS Score
0.0
Published
2025-02-14
SQL Injection vulnerability in hooskcms v.1.7.1 allows a remote attacker to obtain sensitive information via the /install/index.php component.
CVSS Score
5.1
EPSS Score
0.0
Published
2025-02-14
SQL Injection vulnerability in FeMiner wms 1.0 allows a remote attacker to obtain sensitive information via the inquire_inout_item.php component.
CVSS Score
5.1
EPSS Score
0.001
Published
2025-02-14
SQL Injection vulnerability in FeMiner wms wms 1.0 allows a remote attacker to obtain sensitive information via the parameter "itemid."
CVSS Score
5.1
EPSS Score
0.001
Published
2025-02-14
SQL Injection vulnerability in FeMiner wms wms 1.0 allows a remote attacker to obtain sensitive information via the parameters date1, date2, id.
CVSS Score
7.5
EPSS Score
0.001
Published
2025-02-14
eLabFTW is an open source electronic lab notebook for research labs. Prior to version 5.1.15, an incorrect input validation could allow an authenticated user to read sensitive information, including login token or other content stored in the database. This could lead to privilege escalation if cookies are enabled (default setting). Users must upgrade to eLabFTW version 5.1.15 to receive a fix. No known workarounds are available.
CVSS Score
8.3
EPSS Score
0.001
Published
2025-02-14


Contact Us

Shodan ® - All rights reserved