0.0

CVE-2025-6297 - dpkg-deb: Fix cleanup for control member with restricted directories

It was discovered that dpkg does not properly sanitize directory permissions when extracting a control member into a temporary directory, which is documented as being a safe operation even on untrusted data, which may lead to leave temporary files behind on cleanup. Given automated and repeated exe…

📅 Published: July 1, 2025, 4:16 p.m. 🔄 Last Modified: July 1, 2025, 4:16 p.m.

6.9

CVSS4.0

CVE-2025-6963 - Campcodes Employee Management System myprofile.php sql injection

A vulnerability has been found in Campcodes Employee Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /myprofile.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed…

📅 Published: July 1, 2025, 4:02 p.m. 🔄 Last Modified: July 1, 2025, 4:15 p.m.

6.9

CVSS4.0

CVE-2025-6962 - Campcodes Employee Management System myprofileup.php sql injection

A vulnerability, which was classified as critical, was found in Campcodes Employee Management System 1.0. This affects an unknown part of the file /myprofileup.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been discl…

📅 Published: July 1, 2025, 3:32 p.m. 🔄 Last Modified: July 1, 2025, 4:15 p.m.

6.9

CVSS4.0

CVE-2025-6961 - Campcodes Employee Management System mark.php sql injection

A vulnerability, which was classified as critical, has been found in Campcodes Employee Management System 1.0. Affected by this issue is some unknown functionality of the file /mark.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has…

📅 Published: July 1, 2025, 3:32 p.m. 🔄 Last Modified: July 1, 2025, 4:15 p.m.

6.9

CVSS4.0

CVE-2025-6960 - Campcodes Employee Management System empproject.php sql injection

A vulnerability classified as critical was found in Campcodes Employee Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /empproject.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been…

📅 Published: July 1, 2025, 3:02 p.m. 🔄 Last Modified: July 1, 2025, 3:29 p.m.

6.9

CVSS4.0

CVE-2025-6959 - Campcodes Employee Management System eloginwel.php sql injection

A vulnerability classified as critical has been found in Campcodes Employee Management System 1.0. Affected is an unknown function of the file /eloginwel.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to …

📅 Published: July 1, 2025, 3:02 p.m. 🔄 Last Modified: July 1, 2025, 3:32 p.m.

5.5

CVSS4.0

CVE-2025-53099 - Sentry Missing Invalidation of Authorization Codes During OAuth Exchange and Revocation

Sentry is a developer-first error tracking and performance monitoring tool. Prior to version 25.5.0, an attacker with a malicious OAuth application registered with Sentry can take advantage of a race condition and improper handling of authorization code within Sentry to maintain persistence to a us…

📅 Published: July 1, 2025, 2:53 p.m. 🔄 Last Modified: July 1, 2025, 3:15 p.m.

9

CVSS4.0

CVE-2025-34064 - OneLogin AD Connector Log S3 Bucket Hijack Leading to Cross-Tenant Data Leakage

A cloud infrastructure misconfiguration in OneLogin AD Connector results in log data being sent to a hardcoded S3 bucket (onelogin-adc-logs-production) without validating bucket ownership. An attacker who registers this unclaimed bucket can begin receiving log files from other OneLogin tenants. The…

📅 Published: July 1, 2025, 2:49 p.m. 🔄 Last Modified: July 1, 2025, 3:15 p.m.

10

CVSS4.0

CVE-2025-34063 - OneLogin AD Connector JWT Authentication Bypass via Exposed Signing Key

A cryptographic authentication bypass vulnerability exists in OneLogin AD Connector prior to 6.1.5 due to the exposure of a tenant’s SSO JWT signing key via the /api/adc/v4/configuration endpoint. An attacker in possession of the signing key can craft valid JWT tokens impersonating arbitrary users …

📅 Published: July 1, 2025, 2:49 p.m. 🔄 Last Modified: July 1, 2025, 3:17 p.m.

5.7

CVSS4.0

CVE-2025-34062 - OneLogin AD Connector API Credential and Signing Key Exposure

An information disclosure vulnerability exists in OneLogin AD Connector versions prior to 6.1.5 via the /api/adc/v4/configuration endpoint. An attacker with access to a valid directory_token—which may be retrievable from host registry keys or improperly secured logs—can retrieve a plaintext respons…

📅 Published: July 1, 2025, 2:49 p.m. 🔄 Last Modified: July 1, 2025, 3:35 p.m.
Total resulsts: 300013
Page 1 of 30,002
» next page
Filters