4.1

CVSS4.0

CVE-2025-0495 - Secrets leakage to telemetry endpoint via cache backend configuration via buildx

Buildx is a Docker CLI plugin that extends build capabilities using BuildKit. Cache backends support credentials by setting secrets directly as attribute values in cache-to/cache-from configuration. When supplied as user input, these secure values may be inadvertently captured in OpenTelemetry tra…

📅 Published: March 17, 2025, 7:21 p.m. 🔄 Last Modified: March 18, 2025, 4:25 p.m.

5.3

CVSS3.1

CVE-2024-8510 - N-central Path Traversal

N-central is vulnerable to a path traversal that allows unintended access to the Apache Tomcat WEB-INF directory. Customer data is not exposed. This vulnerability is present in all deployments of N-central prior to N-central 2024.6.

📅 Published: March 17, 2025, 7:01 p.m. 🔄 Last Modified: March 18, 2025, 2:41 p.m.

5.3

CVSS4.0

CVE-2025-2390 - code-projects Blood Bank Management System add_donor.php sql injection

A vulnerability classified as critical has been found in code-projects Blood Bank Management System 1.0. This affects an unknown part of the file /user_dashboard/add_donor.php. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to…

📅 Published: March 17, 2025, 7 p.m. 🔄 Last Modified: March 18, 2025, 3:16 p.m.

5.1

CVSS4.0

CVE-2025-2389 - code-projects Blood Bank Management System add_city.php sql injection

A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/add_city.php. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclo…

📅 Published: March 17, 2025, 6:31 p.m. 🔄 Last Modified: March 18, 2025, 1:36 p.m.

8.4

CVSS3.1

CVE-2024-48831 -

Dell SmartFabric OS10 Software, version(s) 10.5.6.x, contain(s) a Use of Hard-coded Password vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.

📅 Published: March 17, 2025, 6 p.m. 🔄 Last Modified: March 17, 2025, 6:26 p.m.

6.9

CVSS4.0

CVE-2025-2388 - Keytop 路内停车收费系统 API getParks improper authentication

A vulnerability was found in Keytop 路内停车收费系统 2.7.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /saas/commonApi/park/getParks of the component API. The manipulation leads to improper authentication. The attack can be launched remotely. Th…

📅 Published: March 17, 2025, 6 p.m. 🔄 Last Modified: March 17, 2025, 6:34 p.m.

7.8

CVSS3.1

CVE-2025-22472 -

Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to ex…

📅 Published: March 17, 2025, 5:47 p.m. 🔄 Last Modified: March 18, 2025, 3:55 a.m.

7.8

CVSS3.1

CVE-2025-22473 -

Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Co…

📅 Published: March 17, 2025, 5:42 p.m. 🔄 Last Modified: March 18, 2025, 3:55 a.m.

7.8

CVSS3.1

CVE-2024-49561 -

Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

📅 Published: March 17, 2025, 5:35 p.m. 🔄 Last Modified: March 18, 2025, 3:55 a.m.

6.9

CVSS4.0

CVE-2025-2387 - SourceCodester Online Food Ordering System ajax.php sql injection

A vulnerability was found in SourceCodester Online Food Ordering System 2.0. It has been classified as critical. Affected is an unknown function of the file /admin/ajax.php?action=add_to_cart. The manipulation of the argument pid leads to sql injection. It is possible to launch the attack remotely.…

📅 Published: March 17, 2025, 5:31 p.m. 🔄 Last Modified: March 17, 2025, 6:23 p.m.
Total resulsts: 285686
Page 13 of 28,569
« previous page » next page
Filters