Common Vulnerabilities and Exposures (CVE)

CVE-2024-4944

Jul 29, 2026 22:15:07 UTC

A local privilege escalation vlnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user to execute arbitrary commands with elevated privileged.

CVE-2025-67408

Jul 29, 2026 22:04:12 UTC

Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.php via the parameter status.

CVE-2025-67407

Jul 29, 2026 22:03:08 UTC

Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_student.php via parameters fname and student_class.

CVE-2025-67406

Jul 29, 2026 22:01:38 UTC

https://www.sourcecodester.com Advocate office management system 1.0 is affected by: SQL Injection. The impact is: execute arbitrary code (remote). The component is: control/activate_case.php,?id=1. The attack vector is: A SQL Injection vul...

CVE-2025-67405

Jul 29, 2026 21:56:09 UTC

Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_password.php via the parameter new_password.

CVE-2025-67404

Jul 29, 2026 21:54:04 UTC

Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters fname, lname, and student_class.

CVE-2025-67403

Jul 29, 2026 21:52:53 UTC

Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the parameter class_name.

CVE-2025-69949

Jul 29, 2026 21:51:22 UTC

kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in check_availability.php via the parameters emailid and email.

CVE-2025-69945

Jul 29, 2026 21:48:59 UTC

kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /doctor/edit-patient.php?editid=1.

CVE-2025-69944

Jul 29, 2026 21:47:20 UTC

kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in the view-medhistory.php endpoint via the viewid parameter.

CVE-2025-69943

Jul 29, 2026 21:45:35 UTC

kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and specilizationid.

CVE-2026-67595

Jul 29, 2026 21:33:25 UTC

VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers to execute unauthorized code in any browser that ...

CVE-2026-15157

Jul 29, 2026 21:17:44 UTC

undici does not validate the type property of a duck-typed blob-like request body before using it as the Content-Type header on the HTTP/1.1 dispatcher. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before 8....

CVE-2026-14643

Jul 29, 2026 21:08:33 UTC

undici's cache interceptor mishandles optional whitespace placed around the equals sign of a qualified no-cache or private Cache-Control directive. In undici from 7.0.0 up to before 7.29.0 and from 8.0.0 up to before 8.9.0, the parser eithe...

CVE-2025-69942

Jul 29, 2026 21:02:52 UTC

kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1.