4.8

CVSS3.1

CVE-2025-45007 -

A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the profile.php file of PHPGurukul Timetable Generator System v1.0. This vulnerability allows remote attackers to execute arbitrary JavaScript code via the adminname POST request parameter.

πŸ“… Published: April 30, 2025, midnight πŸ”„ Last Modified: April 30, 2025, 3:16 p.m.

0.0

CVE-2025-45019 -

A SQL injection vulnerability was discovered in /add-foreigners-ticket.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary code via the cprice POST request parameter.

πŸ“… Published: April 30, 2025, midnight πŸ”„ Last Modified: April 30, 2025, 2:15 p.m.

0.0

CVE-2025-45018 -

A SQL Injection vulnerability was discovered in the foreigner-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary SQL code via the todate parameter.

πŸ“… Published: April 30, 2025, midnight πŸ”„ Last Modified: April 30, 2025, 2:15 p.m.

0.0

CVE-2025-45017 -

A SQL injection vulnerability was discovered in edit-ticket.php of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary code via the tprice POST request parameter.

πŸ“… Published: April 30, 2025, midnight πŸ”„ Last Modified: April 30, 2025, 2:15 p.m.

0.0

CVE-2025-44193 -

SourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?page=view_complaint.

πŸ“… Published: April 30, 2025, midnight πŸ”„ Last Modified: April 30, 2025, 6:15 p.m.

0.0

CVE-2025-44192 -

SourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?page=view_clearance.

πŸ“… Published: April 30, 2025, midnight πŸ”„ Last Modified: April 30, 2025, 6:15 p.m.

8.6

CVSS3.1

CVE-2025-29906 - Finit bundled getty can bypass /bin/login

Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 and prior to version 4.11 bundle an implementation of getty for the `tty` configuration directive that can bypass `/bin/login`, i.e., a user can log in as any user without authentication. This issue has been patched in version 4…

πŸ“… Published: April 29, 2025, 10:17 p.m. πŸ”„ Last Modified: April 30, 2025, 5:33 p.m.

6.3

CVSS4.0

CVE-2025-46552 - KHC-INVITATION-AUTOMATION Sensitive User Information Leakage in Invitation Automation

KHC-INVITATION-AUTOMATION is a GitHub automation script that automatically invites followers of a bot account to join your organization. In some commits on version 1.2, a vulnerability was identified where user data, including email addresses and Discord usernames, were exposed in API responses wit…

πŸ“… Published: April 29, 2025, 10:13 p.m. πŸ”„ Last Modified: April 30, 2025, 5:40 p.m.

5.4

CVSS3.1

CVE-2025-3910 - Org.keycloak.authentication: two factor authentication bypass

A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.

πŸ“… Published: April 29, 2025, 8:46 p.m. πŸ”„ Last Modified: April 30, 2025, 3:53 p.m.

8.2

CVSS3.1

CVE-2025-3501 - Org.keycloak.protocol.services: keycloak hostname verification

A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.

πŸ“… Published: April 29, 2025, 8:45 p.m. πŸ”„ Last Modified: April 30, 2025, 3:54 p.m.
Total resulsts: 291908
Page 14 of 29,191
Β« previous page Β» next page
Filters