5.3

CVSS4.0

CVE-2025-8340 - code-projects Intern Membership Management System Error Message fill_details.php cross site scripti…

A vulnerability was found in code-projects Intern Membership Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file fill_details.php of the component Error Message Handler. The manipulation of the argument email leads to cross site scripting.…

📅 Published: July 31, 2025, 12:32 a.m. 🔄 Last Modified: July 31, 2025, 1:15 a.m.

6.9

CVSS4.0

CVE-2025-8339 - code-projects Intern Membership Management System student_login.php sql injection

A vulnerability was found in code-projects Intern Membership Management System 1.0. It has been classified as critical. This affects an unknown part of the file /student_login.php. The manipulation of the argument user_name/password leads to sql injection. It is possible to initiate the attack remo…

📅 Published: July 31, 2025, 12:02 a.m. 🔄 Last Modified: July 31, 2025, 1:15 a.m.

6.5

CVSS3.1

CVE-2025-36040 - IBM Aspera Faspex session fixation

IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms.

📅 Published: July 30, 2025, 11:48 p.m. 🔄 Last Modified: July 31, 2025, 12:15 a.m.

6.5

CVSS3.1

CVE-2025-36039 - IBM Aspera Faspex bypass security

IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms,

📅 Published: July 30, 2025, 11:47 p.m. 🔄 Last Modified: July 31, 2025, 12:15 a.m.

5.1

CVSS4.0

CVE-2025-49082 - Permissions bypass vulnerability in the Secure Access administrative console of Absolute Secure Acc…

CVE-2025-49082 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access to the console and who have been assigned a certain set of permissions can bypass those permissions to improperly read other settings. The attack comple…

📅 Published: July 30, 2025, 11:45 p.m. 🔄 Last Modified: July 31, 2025, 12:15 a.m.

5.1

CVSS4.0

CVE-2025-54085 - Elevation of privilege vulnerability in the Secure Access administrative console of Absolute Secure…

CVE-2025-54085 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access to the console and who have been assigned a certain set of permissions can bypass those permissions to improperly read or change other settings. The att…

📅 Published: July 30, 2025, 11:40 p.m. 🔄 Last Modified: July 31, 2025, 12:15 a.m.

5.3

CVSS4.0

CVE-2025-49084 - Elevation of privilege vulnerability in the Secure Access administrative console of Absolute Secure…

CVE-2025-49084 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access can overwrite policy rules without the requisite permissions. The attack complexity is low, attack requirements are present, privileges required are hig…

📅 Published: July 30, 2025, 11:36 p.m. 🔄 Last Modified: July 31, 2025, 12:15 a.m.

6.9

CVSS4.0

CVE-2025-8338 - projectworlds Online Admission System adminac.php sql injection

A vulnerability was found in projectworlds Online Admission System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /adminac.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been dis…

📅 Published: July 30, 2025, 11:32 p.m. 🔄 Last Modified: July 31, 2025, 12:15 a.m.

7

CVSS4.0

CVE-2025-49083 - Data deserialization vulnerability in the Secure Access administrative console of Absolute Secure A…

CVE-2025-49083 is a vulnerability in the management console of Absolute Secure Access after version 12.00 and prior to version 13.56. Attackers with administrative access to the console can cause unsafe content to be deserialized and executed in the security context of the console. The attack compl…

📅 Published: July 30, 2025, 11:30 p.m. 🔄 Last Modified: July 31, 2025, 12:15 a.m.

4.8

CVSS4.0

CVE-2025-8337 - code-projects Simple Car Rental System add_vehicles.php cross site scripting

A vulnerability, which was classified as problematic, has been found in code-projects Simple Car Rental System 1.0. This issue affects some unknown processing of the file /admin/add_vehicles.php. The manipulation of the argument car_name leads to cross site scripting. The attack may be initiated re…

📅 Published: July 30, 2025, 11:02 p.m. 🔄 Last Modified: July 30, 2025, 11:15 p.m.
Total resulsts: 303775
Page 2 of 30,378
« previous page » next page
Filters