4.8

CVSS4.0

CVE-2025-4029 - code-projects Personal Diary Management System New Record addrecord stack-based overflow

A vulnerability was found in code-projects Personal Diary Management System 1.0 and classified as critical. Affected by this issue is the function addrecord of the component New Record Handler. The manipulation of the argument filename leads to stack-based buffer overflow. Local access is required …

πŸ“… Published: April 28, 2025, 5 p.m. πŸ”„ Last Modified: April 28, 2025, 5 p.m.

6.9

CVSS4.0

CVE-2025-4028 - PHPGurukul COVID19 Testing Management System profile.php sql injection

A vulnerability has been found in PHPGurukul COVID19 Testing Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /profile.php. The manipulation of the argument mobilenumber leads to sql injection. The attack can be launched remote…

πŸ“… Published: April 28, 2025, 4:31 p.m. πŸ”„ Last Modified: April 28, 2025, 4:31 p.m.

6

CVSS4.0

CVE-2025-43857 - net-imap rubygem vulnerable to possible DoS by memory exhaustion

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.5.7, 0.4.20, 0.3.9, and 0.2.5, there is a possibility for denial of service by memory exhaustion when net-imap reads server responses. At any time while the client is connected, a maliciou…

πŸ“… Published: April 28, 2025, 4:02 p.m. πŸ”„ Last Modified: April 28, 2025, 4:15 p.m.

6.9

CVSS4.0

CVE-2025-4027 - PHPGurukul Old Age Home Management System rules.php sql injection

A vulnerability, which was classified as critical, was found in PHPGurukul Old Age Home Management System 1.0. Affected is an unknown function of the file /admin/rules.php. The manipulation of the argument pagetitle leads to sql injection. It is possible to launch the attack remotely. The exploit h…

πŸ“… Published: April 28, 2025, 4 p.m. πŸ”„ Last Modified: April 28, 2025, 4:15 p.m.

2.3

CVSS4.0

CVE-2025-43854 - DIFY vulnerable to Clickjacking Attack

DIFY is an open-source LLM app development platform. Prior to version 1.3.0, a clickjacking vulnerability was found in the default setup of the DIFY application, allowing malicious actors to trick users into clicking on elements of the web page without their knowledge or consent. This can lead to u…

πŸ“… Published: April 28, 2025, 3:58 p.m. πŸ”„ Last Modified: April 28, 2025, 4:15 p.m.

6.9

CVSS4.0

CVE-2025-4026 - PHPGurukul Nipah Virus Testing Management System profile.php sql injection

A vulnerability, which was classified as critical, has been found in PHPGurukul Nipah Virus Testing Management System 1.0. This issue affects some unknown processing of the file /profile.php. The manipulation of the argument adminname leads to sql injection. The attack may be initiated remotely. Th…

πŸ“… Published: April 28, 2025, 3:31 p.m. πŸ”„ Last Modified: April 28, 2025, 4:15 p.m.

6.9

CVSS4.0

CVE-2025-4025 - itsourcecode Placement Management System registration.php sql injection

A vulnerability classified as critical was found in itsourcecode Placement Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /registration.php. The manipulation of the argument Name leads to sql injection. The attack can be launched remotely. The exploit …

πŸ“… Published: April 28, 2025, 3 p.m. πŸ”„ Last Modified: April 28, 2025, 3:15 p.m.

4.2

CVSS3.1

CVE-2025-23377 -

Dell PowerProtect Data Manager Reporting, version(s) 19.17, 19.18 contain(s) an Improper Encoding or Escaping of Output vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to inject arbitrary web script or html in reporting outputs.

πŸ“… Published: April 28, 2025, 2:38 p.m. πŸ”„ Last Modified: April 28, 2025, 3:15 p.m.

2.3

CVSS3.1

CVE-2025-23376 -

Dell PowerProtect Data Manager Reporting, version(s) 19.16, 19.17, 19.18, contain(s) an Improper Neutralization of Special Elements Used in a Template Engine vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.

πŸ“… Published: April 28, 2025, 2:34 p.m. πŸ”„ Last Modified: April 28, 2025, 3:15 p.m.

6.9

CVSS4.0

CVE-2025-4024 - itsourcecode Placement Management System add_drive.php sql injection

A vulnerability classified as critical has been found in itsourcecode Placement Management System 1.0. Affected is an unknown function of the file /add_drive.php. The manipulation of the argument drive_title leads to sql injection. It is possible to launch the attack remotely. The exploit has been …

πŸ“… Published: April 28, 2025, 2:31 p.m. πŸ”„ Last Modified: April 28, 2025, 3:15 p.m.
Total resulsts: 291634
Page 1 of 29,164
Β» next page
Filters