7.6
CVE-2025-46349 - YesWiki Vulnerable to Unauthenticated Reflected Cross-site Scripting
YesWiki is a wiki system written in PHP. Prior to version 4.5.4, YesWiki is vulnerable to reflected XSS in the file upload form. This vulnerability allows any malicious unauthenticated user to create a link that can be clicked on by the victim to perform arbitrary actions. This issue has been patchβ¦
5.8
CVE-2025-46347 - YesWiki Remote Code Execution via Arbitrary PHP File Write and Execution
YesWiki is a wiki system written in PHP. Prior to version 4.5.4, YesWiki vulnerable to remote code execution. An arbitrary file write can be used to write a file with a PHP extension, which then can be browsed to in order to execute arbitrary code on the server, resulting in a full compromise of thβ¦
6.9
CVE-2025-4073 - PHPGurukul Student Record System change-password.php sql injection
A vulnerability was found in PHPGurukul Student Record System 3.20. It has been classified as critical. Affected is an unknown function of the file /change-password.php. The manipulation of the argument currentpassword leads to sql injection. It is possible to launch the attack remotely. The exploiβ¦
5.3
CVE-2025-4072 - PHPGurukul Online Nurse Hiring System edit-nurse.php sql injection
A vulnerability was found in PHPGurukul Online Nurse Hiring System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/edit-nurse.php. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the publiβ¦
4.8
CVE-2025-0716 - AngularJS improper sanitization in SVG '<image>' element
Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '<image>' SVG elements in AngularJS allows attackers to bypass common image source restrictions. This can lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing Β and also negativelyβ¦
8
CVE-2025-23181 - Ribbon Communications - CWE-250: Execution with Unnecessary Privileges
CWE-250: Execution with Unnecessary Privileges
8
CVE-2025-23180 - Ribbon Communications - CWE-250: Execution with Unnecessary Privileges
CWE-250: Execution with Unnecessary Privileges
5.5
CVE-2025-23179 - Ribbon Communications - CWE-798: Use of Hard-coded Credentials
CWE-798: Use of Hard-coded Credentials
7.6
CVE-2025-23178 - Ribbon Communications - CWE-923: Improper Restriction of Communication Channel to Intended Endpoints
CWE-923: Improper Restriction of Communication Channel to Intended Endpoints
7.6
CVE-2025-23177 - Ribbon Communications - CWE-427: Uncontrolled Search Path Element
CWE-427: Uncontrolled Search Path Element