7.8

CVSS3.1

CVE-2025-5047 - DGN File Parsing Uninitialized Variable Vulnerability

A maliciously crafted DGN file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

📅 Published: Aug. 15, 2025, 2:37 p.m. 🔄 Last Modified: Aug. 15, 2025, 2:37 p.m.

7.8

CVSS3.1

CVE-2025-5046 - DGN File Parsing Out-of-Bounds Read Vulnerability

A maliciously crafted DGN file, when linked or imported into Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

📅 Published: Aug. 15, 2025, 2:37 p.m. 🔄 Last Modified: Aug. 15, 2025, 2:37 p.m.

0.0

CVE-2025-54466 - Apache OFBiz: RCE Vulnerability in scrum plugin

Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects Apache OFBiz: before 24.09.02 only when the scrum plugin is used. Even unauthenticated attackers can exploit this vulnerability. Users are recommend…

📅 Published: Aug. 15, 2025, 2:13 p.m. 🔄 Last Modified: Aug. 15, 2025, 2:13 p.m.

6.9

CVSS4.0

CVE-2025-9053 - projectworlds Travel Management System updatesubcategory.php sql injection

A vulnerability has been found in projectworlds Travel Management System 1.0. This vulnerability affects unknown code of the file /updatesubcategory.php. The manipulation of the argument t1/s1 leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public…

📅 Published: Aug. 15, 2025, 1:02 p.m. 🔄 Last Modified: Aug. 15, 2025, 1:02 p.m.

6.9

CVSS4.0

CVE-2025-9052 - projectworlds Travel Management System updatepackage.php sql injection

A vulnerability was identified in projectworlds Travel Management System 1.0. This affects an unknown part of the file /updatepackage.php. The manipulation of the argument s1 leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may…

📅 Published: Aug. 15, 2025, 12:32 p.m. 🔄 Last Modified: Aug. 15, 2025, 12:32 p.m.

7.2

CVSS3.1

CVE-2025-1929 - SQLi in RiskTurk's Treasury Management Software

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Risk Yazılım Teknolojileri Ltd. Şti. Reel Sektör Hazine ve Risk Yönetimi Yazılımı allows SQL Injection, CAPEC - 7 - Blind SQL Injection.This issue affects Reel Sektör Hazine ve Risk Yönetimi Yazılı…

📅 Published: Aug. 15, 2025, 12:06 p.m. 🔄 Last Modified: Aug. 15, 2025, 12:06 p.m.

6.9

CVSS4.0

CVE-2025-9051 - projectworlds Travel Management System updatecategory.php sql injection

A vulnerability was determined in projectworlds Travel Management System 1.0. Affected by this issue is some unknown functionality of the file /updatecategory.php. The manipulation of the argument t1 leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the …

📅 Published: Aug. 15, 2025, 12:02 p.m. 🔄 Last Modified: Aug. 18, 2025, 3:08 p.m.

8.7

CVSS4.0

CVE-2025-54475 - Extension - joomsky.com - SQL injection in JS jobs component version 1.3.2 - 1.4.4 for Joomla

A SQL injection vulnerability in the JS Jobs plugin versions 1.3.2-1.4.4 for Joomla allows low-privilege users to execute arbitrary SQL commands.

📅 Published: Aug. 15, 2025, 11:54 a.m. 🔄 Last Modified: Aug. 15, 2025, 11:54 a.m.

8.5

CVSS4.0

CVE-2025-54474 - Extension - dj-extensions.com - SQLi vulnerability in DJ-Classifieds component 3.9.2-3.10.1 for Joo…

A SQLi vulnerability in DJ-Classifieds component 3.9.2-3.10.1 for Joomla was discovered. The issue allows privileged users to execute arbitrary SQL commands.

📅 Published: Aug. 15, 2025, 11:54 a.m. 🔄 Last Modified: Aug. 15, 2025, 11:54 a.m.

9.2

CVSS4.0

CVE-2025-54473 - Extension - phoca.cz - Authenticated RCE vulnerability in Phoca Commander component 1.0.0-4.0.0 and…

An authenticated RCE vulnerability in Phoca Commander component 1.0.0-4.0.0 and 5.0.0-5.0.1 for Joomla was discovered. The issue allows code execution via the unzip feature.

📅 Published: Aug. 15, 2025, 11:54 a.m. 🔄 Last Modified: Aug. 15, 2025, 11:54 a.m.
Total resulsts: 305916
Page 19 of 30,592
« previous page » next page
Filters