8.6
CVE-2025-8083 - Vuetify Prototype Pollution via Preset options
The Preset configuration https://v2.vuetifyjs.com/en/features/presets ย feature of Vuetify is vulnerable to Prototype Pollution https://cheatsheetseries.owasp.org/cheatsheets/Prototype_Pollution_Prevention_Cheat_Sheet.html ย due to the internal 'mergeDeep' utility function used to merge options witโฆ
4.3
CVE-2025-14373 -
Inappropriate implementation in Toolbar in Google Chrome on Android prior to 143.0.7499.110 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)
6.1
CVE-2025-14372 -
Use after free in Password Manager in Google Chrome prior to 143.0.7499.110 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
8.8
CVE-2025-14174 - Google Chrome: chromium: Out of bounds memory access via crafted HTML page
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
6.3
CVE-2025-8082 - Vuetify XSS via unsanitized 'titleDateFormat' in 'VDatePicker'
Improper neutralization of the title date in the 'VDatePicker' component in Vuetify, allows unsanitized HTML to be inserted into the page.ย This can lead to a Cross-Site Scripting (XSS) https://owasp.org/www-community/attacks/xss ย attack. The vulnerability occurs because theย 'title-date-format' proโฆ
6.9
CVE-2025-14571 - projectworlds Advanced Library Management System borrow_book.php sql injection
A vulnerability has been found in projectworlds Advanced Library Management System 1.0. Affected by this issue is some unknown functionality of the file /borrow_book.php. Such manipulation of the argument roll_number leads to sql injection. The attack may be launched remotely. The exploit has been โฆ
6.9
CVE-2025-14570 - projectworlds Advanced Library Management System view_admin.php sql injection
A flaw has been found in projectworlds Advanced Library Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /view_admin.php. This manipulation of the argument admin_id causes sql injection. The attack may be initiated remotely. The exploit has been publisheโฆ
4.8
CVE-2025-14569 - ggml-org whisper.cpp common-whisper.cpp read_audio_data use after free
A vulnerability was detected in ggml-org whisper.cpp up to 1.8.2. Affected is the function read_audio_data of the file /whisper.cpp/examples/common-whisper.cpp. The manipulation results in use after free. The attack requires a local approach. The exploit is now public and may be used. The project wโฆ
5.3
CVE-2025-14568 - haxxorsid Stock-Management-System User.php sql injection
A security vulnerability has been detected in haxxorsid Stock-Management-System up to fbbbf213e9c93b87183a3891f77e3cc7095f22b0. This impacts an unknown function of the file model/User.php. The manipulation of the argument employee_id/id/admin leads to sql injection. The attack can be initiated remoโฆ
0.0
CVE-2025-14597 -
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.