5.4
CVE-2025-64687 -
In JetBrains YouTrack before 2025.3.104432 improper access control allowed modify MCP tool logic
3.1
CVE-2025-64686 -
In JetBrains YouTrack before 2025.3.104432 missing user principal cleanup led to reuse of incorrect authorization context
8.1
CVE-2025-64685 -
In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure
4.5
CVE-2025-64684 -
In JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form
5.3
CVE-2025-64683 -
In JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API
2.7
CVE-2025-64682 -
In JetBrains Hub before 2025.3.104432 a race condition allowed bypass of the Agent-user limit
2.7
CVE-2025-64681 -
In JetBrains Hub before 2025.3.104992 a race condition allowed bypass of the user limit via invitations
5.3
CVE-2025-12939 - SourceCodester Interview Management System addCandidate.php sql injection
A security flaw has been discovered in SourceCodester Interview Management System up to 1.0. Affected by this issue is some unknown functionality of the file /addCandidate.php. The manipulation of the argument candName results in sql injection. The attack can be launched remotely. The exploit has bโฆ
6.9
CVE-2025-12938 - projectworlds Online Admission System process_login.php sql injection
A vulnerability was identified in projectworlds Online Admission System 1.0. Affected by this vulnerability is an unknown functionality of the file /process_login.php. The manipulation of the argument keywords leads to sql injection. The attack can be initiated remotely. The exploit is publicly avaโฆ
5.1
CVE-2025-41001 - Cross-Site Scripting (XSS) in SOPlanning
Cross Site Scripting (XSS) vulnerability stored in SOPlanning v1.53.02, which consist of a stored XSS due to a lack of proper validation of user input by sending a POST request using the 'LOGOUT_REDIRECT' parameter in '/soplanning/www/process/options.php'. This vulnerability could allow a remote usโฆ