9.8
CVE-2025-9312 - Improper Certificate-Based Authentication Enforcement in Multiple WSO2 Products
A missing authentication enforcement vulnerability exists in the mutual TLS (mTLS) implementation used by System REST APIs and SOAP services in multiple WSO2 products. Due to improper validation of client certificate–based authentication in certain default configurations, the affected components ma…
5.3
CVE-2025-13345 - SourceCodester Train Station Ticketing System ajax.php sql injection
A security vulnerability has been detected in SourceCodester Train Station Ticketing System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=save_ticket. Such manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclos…
6.9
CVE-2025-13344 - SourceCodester Train Station Ticketing System ajax.php sql injection
A weakness has been identified in SourceCodester Train Station Ticketing System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=login. This manipulation of the argument Username causes sql injection. The attack can be initiated remotely. The exploit has …
5.1
CVE-2025-13343 - SourceCodester Interview Management System editQuestion.php cross site scripting
A security flaw has been discovered in SourceCodester Interview Management System 1.0. Affected is an unknown function of the file /editQuestion.php. The manipulation of the argument Question results in cross site scripting. It is possible to launch the attack remotely. The exploit has been release…
8.8
CVE-2025-6670 - Cross-Site Request Forgery (CSRF) in Multiple WSO2 Products via HTTP GET in Admin Services
A Cross-Site Request Forgery (CSRF) vulnerability exists in multiple WSO2 products due to the use of the HTTP GET method for state-changing operations within admin services, specifically in the event processor of the Carbon console. Although the SameSite=Lax cookie attribute is used as a mitigation…
5.1
CVE-2025-41350 - Stored Cross-Site Scripting (XSS) in WinPlus by Informática del Este
Stored Cross-site Scripting (XSS)vylnerability type in WinPlus v24.11.27 byInformática del Este that consist of an stored XSS of a stored XSS due to a lack of proper validation of user input by sending a POST request using the 'descripcion' parameter in '/WinplusPortal/ws/sWinplus.svc/json/savesold…
5.1
CVE-2025-41349 - Stored Cross-Site Scripting (XSS) in WinPlus by Informática del Este
Stored Cross-site Scripting (XSS)vylnerability type in WinPlus v24.11.27 byInformática del Este that consist of an stored XSS of a stored XSS due to a lack of proper validation of user input by sending a POST request using the 'descripcion' parameter in '/WinplusPortal/ws/sWinplus. svc/json/savesol…
8.7
CVE-2025-41348 - Stored Cross-Site Scripting (XSS) in WinPlus by Informática del Este
SQL injection vulnerability in WinPlus v24.11.27 by Informática del Este. This vulnerability allows an attacker recover, create, update an delete databases by sendng a POST request using the parameters 'val1' and 'cont in '/WinplusPortal/ws/sWinplus.svc/json/getacumper_post'.
8.7
CVE-2025-41347 - Stored Cross-Site Scripting (XSS) in WinPlus by Informática del Este
Unlimited upload vulnerability for dangerous file types in WinPlus v24.11.27 from Informática del Este. This vulnerability allows an attacker to upload a 'webshell' by sending a POST request to '/WinplusPortal/ws/sWinplus.svc/json/uploadfile'.
5.8
CVE-2025-11427 - WP Migrate Lite <= 2.7.6 - Unauthenticated Blind Server-Side Request Forgery
The WP Migrate Lite – WordPress Migration Made Easy plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.7.6 via the wpmdb_flush AJAX action. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations o…