6.9

CVSS4.0

CVE-2025-15408 - code-projects Online Guitar Store Create_product.php sql injection

A vulnerability was found in code-projects Online Guitar Store 1.0. Affected is an unknown function of the file /admin/Create_product.php. Performing a manipulation of the argument dre_title results in sql injection. The attack is possible to be carried out remotely. The exploit has been made publi…

📅 Published: Jan. 1, 2026, 6:02 p.m. 🔄 Last Modified: Feb. 23, 2026, 9:16 a.m.

9.7

CVSS3.1

CVE-2025-66398 - Signal K Server has Unauthenticated State Pollution leading to Remote Code Execution (RCE)

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticated attacker can pollute the internal state (`restoreFilePath`) of the server via the `/skServer/validateBackup` endpoint. This allows the attacker to hijack the administrator's "Re…

📅 Published: Jan. 1, 2026, 6 p.m. 🔄 Last Modified: Jan. 6, 2026, 6:34 p.m.

7.7

CVSS4.0

CVE-2026-21428 - cpp-httplib has CRLF injection in http headers

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.30.0, the ``write_headers`` function does not check for CR & LF characters in user supplied headers, allowing untrusted header value to escape header lines. This vulnerability allows attackers to ad…

📅 Published: Jan. 1, 2026, 5:54 p.m. 🔄 Last Modified: Jan. 6, 2026, 6:20 p.m.

6.9

CVSS4.0

CVE-2025-15407 - code-projects Online Guitar Store Create_category.php sql injection

A vulnerability has been found in code-projects Online Guitar Store 1.0. This impacts an unknown function of the file /admin/Create_category.php. Such manipulation of the argument dre_Ctitle leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public an…

📅 Published: Jan. 1, 2026, 5:32 p.m. 🔄 Last Modified: Feb. 23, 2026, 8:02 a.m.

5.3

CVSS4.0

CVE-2025-15406 - PHPGurukul Online Course Registration authorization

A flaw has been found in PHPGurukul Online Course Registration up to 3.1. This affects an unknown function. This manipulation causes missing authorization. Remote exploitation of the attack is possible. The exploit has been published and may be used.

📅 Published: Jan. 1, 2026, 5:02 p.m. 🔄 Last Modified: Feb. 23, 2026, 8:02 a.m.

8.1

CVSS3.1

CVE-2025-47411 - Apache StreamPipes: Leverage of User ID for Privilege Escalation

A user with a legitimate non-administrator account can exploit a vulnerability in the user ID creation mechanism in Apache StreamPipes that allows them to swap the username of an existing user with that of an administrator.  This vulnerability allows an attacker to gain administrative control over…

📅 Published: Jan. 1, 2026, 4:41 p.m. 🔄 Last Modified: Jan. 6, 2026, 2:40 p.m.

6.4

CVSS3.1

CVE-2025-14627 - WP Import – Ultimate CSV XML Importer for WordPress <= 7.35 - Authenticated (Contributor+) Server-S…

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.35. This is due to inadequate validation of the resolved URL after following Bitly shortlink redirects in the `upload_function()` method.…

📅 Published: Jan. 1, 2026, 4:19 p.m. 🔄 Last Modified: April 8, 2026, 5:04 p.m.

4.3

CVSS3.1

CVE-2025-14428 - My Sticky Elements <= 2.3.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Bulk L…

The All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs - My Sticky Elements plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the 'my_sticky_elements_bulks' function in all versions up to, and including, 2.3.3. This…

📅 Published: Jan. 1, 2026, 4:19 p.m. 🔄 Last Modified: April 8, 2026, 4:38 p.m.

5.3

CVSS3.1

CVE-2025-48769 - Apache NuttX RTOS: fs/vfs/fs_rename: use after free

Use After Free vulnerability was discovered in fs/vfs/fs_rename code of the Apache NuttX RTOS, that due recursive implementation and single buffer use by two different pointer variables allowed arbitrary user provided size buffer reallocation and write to the previously freed heap chunk, that in sp…

📅 Published: Jan. 1, 2026, 4:14 p.m. 🔄 Last Modified: Jan. 6, 2026, 2:35 p.m.

5.3

CVSS3.1

CVE-2025-48768 - Apache NuttX RTOS: fs/inode: fs_inoderemove root inode removal

Release of Invalid Pointer or Reference vulnerability was discovered in fs/inode/fs_inoderemove code of the Apache NuttX RTOS that allowed root filesystem inode removal leading to a debug assert trigger (that is disabled by default), NULL pointer dereference (handled differently depending on the ta…

📅 Published: Jan. 1, 2026, 4:14 p.m. 🔄 Last Modified: Jan. 6, 2026, 2:39 p.m.
Total resulsts: 343975
Page 1794 of 34,398
« previous page » next page
Filters