4.9

CVSS4.0

CVE-2025-58053 - Galette has a privilege escalation vulnerability

Galette is a membership management web application for non profit organizations. Prior to version 1.2.0, while updating any existing account with a self forged POST request, one can gain higher privileges. Version 1.2.0 fixes the issue.

πŸ“… Published: Dec. 19, 2025, 4:26 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 6 p.m.

2.1

CVSS4.0

CVE-2025-58052 - Galette has groups managers access control bypass on Members

Galette is a membership management web application for non profit organizations. Starting in version 0.9.6 and prior to version 1.2.0, attackers with group manager role can bypass intended restrictions allowing unauthorized access and changes despite role-based controls. Since it requires privilege…

πŸ“… Published: Dec. 19, 2025, 4:24 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 6 p.m.

6.3

CVSS4.0

CVE-2025-14954 - Open5GS QER/FAR/URR/PDR context.c ogs_pfcp_qer_find_or_add assertion

A vulnerability has been found in Open5GS up to 2.7.5. Affected is the function ogs_pfcp_pdr_find_or_add/ogs_pfcp_far_find_or_add/ogs_pfcp_urr_find_or_add/ogs_pfcp_qer_find_or_add in the library lib/pfcp/context.c of the component QER/FAR/URR/PDR. The manipulation leads to reachable assertion. It i…

πŸ“… Published: Dec. 19, 2025, 4:02 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 6 p.m.

2.3

CVSS4.0

CVE-2025-14953 - Open5GS FAR-ID handler.c ogs_pfcp_handle_create_pdr null pointer dereference

A flaw has been found in Open5GS up to 2.7.5. This impacts the function ogs_pfcp_handle_create_pdr in the library lib/pfcp/handler.c of the component FAR-ID Handler. Executing manipulation can lead to null pointer dereference. The attack may be performed from remote. The attack requires a high leve…

πŸ“… Published: Dec. 19, 2025, 4:02 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 6 p.m.

9.3

CVSS4.0

CVE-2025-34433 - AVideo < 20.1 Unauthenticated RCE via Predictable Installation Salt

AVideo versions 14.3.1 prior to 20.1 contain an unauthenticated remote code execution vulnerability caused by predictable generation of an installation salt using PHP uniqid(). The installation timestamp is exposed via a public endpoint, and a derived hash identifier is accessible through unauthent…

πŸ“… Published: Dec. 19, 2025, 3:37 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 7:59 p.m.

1.3

CVSS4.0

CVE-2025-53922 - Galette has access control bypass

Galette is a membership management web application for non profit organizations. Starting in version 1.1.4 and prior to version 1.2.0, a user who is logged in as group manager may bypass intended restrictions on Contributions and Transactions. Version 1.2.0 fixes the issue.

πŸ“… Published: Dec. 19, 2025, 3:10 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 6 p.m.

6.9

CVSS4.0

CVE-2025-14952 - Campcodes Supplier Management System add_category.php sql injection

A vulnerability was detected in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /admin/add_category.php. Performing manipulation of the argument txtCategoryName results in sql injection. The attack is possible to be carried out remotely. The exploit is now pub…

πŸ“… Published: Dec. 19, 2025, 2:32 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 6 p.m.

6.9

CVSS4.0

CVE-2025-14951 - code-projects Scholars Tracking System home.php sql injection

A security vulnerability has been detected in code-projects Scholars Tracking System 1.0. The impacted element is an unknown function of the file /home.php. Such manipulation of the argument post_content leads to sql injection. The attack can be executed remotely. The exploit has been disclosed pub…

πŸ“… Published: Dec. 19, 2025, 2:32 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 6 p.m.

6.9

CVSS4.0

CVE-2025-14950 - code-projects Scholars Tracking System delete_post.php sql injection

A weakness has been identified in code-projects Scholars Tracking System 1.0. The affected element is an unknown function of the file /delete_post.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to th…

πŸ“… Published: Dec. 19, 2025, 1:32 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 6 p.m.

3.8

CVSS4.0

CVE-2025-14881 - Insecure direct object reference

Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only.

πŸ“… Published: Dec. 19, 2025, 12:24 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 6 p.m.
Total resulsts: 323547
Page 10 of 32,355
Β« previous page Β» next page
Filters