8.1

CVSS4.0

CVE-2025-54082 - nova-tiptap has an Unauthenticated Arbitrary File Upload Vulnerability

marshmallow-packages/nova-tiptap is a rich text editor for Laravel Nova based on tiptap. Prior to 5.7.0, a vulnerability was discovered in the marshmallow-packages/nova-tiptap Laravel Nova package that allows unauthenticated users to upload arbitrary files to any Laravel disk configured in the appl…

πŸ“… Published: July 21, 2025, 4:25 p.m. πŸ”„ Last Modified: July 22, 2025, 1:05 p.m.

4.2

CVSS3.1

CVE-2025-36603 -

Dell AppSync, version(s) 4.6.0.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering.

πŸ“… Published: July 21, 2025, 4:20 p.m. πŸ”„ Last Modified: July 22, 2025, 1:05 p.m.

6.9

CVSS4.0

CVE-2025-7930 - code-projects Church Donation System add_members.php sql injection

A vulnerability was found in code-projects Church Donation System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /members/add_members.php. The manipulation of the argument mobile leads to sql injection. The attack can be launched remote…

πŸ“… Published: July 21, 2025, 4:02 p.m. πŸ”„ Last Modified: July 22, 2025, 1:05 p.m.

6.9

CVSS4.0

CVE-2025-7929 - code-projects Church Donation System edit_Members.php sql injection

A vulnerability was found in code-projects Church Donation System 1.0. It has been classified as critical. Affected is an unknown function of the file /members/edit_Members.php. The manipulation of the argument fname leads to sql injection. It is possible to launch the attack remotely. The exploit …

πŸ“… Published: July 21, 2025, 3:32 p.m. πŸ”„ Last Modified: July 22, 2025, 1:05 p.m.

6.9

CVSS4.0

CVE-2025-7928 - code-projects Church Donation System edit_user.php sql injection

A vulnerability was found in code-projects Church Donation System 1.0 and classified as critical. This issue affects some unknown processing of the file /members/edit_user.php. The manipulation of the argument firstname leads to sql injection. The attack may be initiated remotely. The exploit has b…

πŸ“… Published: July 21, 2025, 3:02 p.m. πŸ”„ Last Modified: July 22, 2025, 1:06 p.m.

5.3

CVSS4.0

CVE-2025-7927 - PHPGurukul Online Banquet Booking System view-user-queries.php sql injection

A vulnerability has been found in PHPGurukul Online Banquet Booking System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/view-user-queries.php. The manipulation of the argument viewid leads to sql injection. The attack can be initiated remotely. The expl…

πŸ“… Published: July 21, 2025, 2:32 p.m. πŸ”„ Last Modified: July 22, 2025, 1:06 p.m.

5.3

CVSS4.0

CVE-2025-6235 - ExtremeControl (NAC) 'onmouseover' XSS

In ExtremeControl before 25.5.12, a cross-site scripting (XSS) vulnerability was discovered in a login interface of the affected application. The issue stems from improper handling of user-supplied input within HTML attributes, allowing an attacker to inject script code that may execute in a user's…

πŸ“… Published: July 21, 2025, 2:07 p.m. πŸ”„ Last Modified: July 22, 2025, 1:06 p.m.

7.5

CVSS3.1

CVE-2025-4130 - Hardcoded Credentials in PAVO Inc.'s PAVO Pay

Use of Hard-coded Credentials vulnerability in PAVO Inc. PAVO Pay allows Read Sensitive Constants Within an Executable.This issue affects PAVO Pay: before 13.05.2025.

πŸ“… Published: July 21, 2025, 2:01 p.m. πŸ”„ Last Modified: July 22, 2025, 1:06 p.m.

7.5

CVSS3.1

CVE-2025-4129 - IDOR in PAVO Inc.'s PAVO Pay

Authorization Bypass Through User-Controlled Key vulnerability in PAVO Inc. PAVO Pay allows Exploitation of Trusted Identifiers.This issue affects PAVO Pay: before 13.05.2025.

πŸ“… Published: July 21, 2025, 1:59 p.m. πŸ”„ Last Modified: July 22, 2025, 1:06 p.m.

6.8

CVSS3.1

CVE-2024-13973 -

A post-auth SQL injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR1 (21.0.1) can potentially lead to administrators achieving arbitrary code execution.

πŸ“… Published: July 21, 2025, 1:38 p.m. πŸ”„ Last Modified: July 22, 2025, 1:06 p.m.
Total resulsts: 302890
Page 28 of 30,289
Β« previous page Β» next page
Filters