8.1
CVE-2025-64685 -
In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure
4.5
CVE-2025-64684 -
In JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form
5.3
CVE-2025-64683 -
In JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API
2.7
CVE-2025-64682 -
In JetBrains Hub before 2025.3.104432 a race condition allowed bypass of the Agent-user limit
2.7
CVE-2025-64681 -
In JetBrains Hub before 2025.3.104992 a race condition allowed bypass of the user limit via invitations
5.3
CVE-2025-12939 - SourceCodester Interview Management System addCandidate.php sql injection
A security flaw has been discovered in SourceCodester Interview Management System up to 1.0. Affected by this issue is some unknown functionality of the file /addCandidate.php. The manipulation of the argument candName results in sql injection. The attack can be launched remotely. The exploit has bβ¦
6.9
CVE-2025-12938 - projectworlds Online Admission System process_login.php sql injection
A vulnerability was identified in projectworlds Online Admission System 1.0. Affected by this vulnerability is an unknown functionality of the file /process_login.php. The manipulation of the argument keywords leads to sql injection. The attack can be initiated remotely. The exploit is publicly avaβ¦
5.1
CVE-2025-41001 - Cross-Site Scripting (XSS) in SOPlanning
Cross Site Scripting (XSS) vulnerability stored in SOPlanning v1.53.02, which consist of a stored XSS due to a lack of proper validation of user input by sending a POST request using the 'LOGOUT_REDIRECT' parameter in '/soplanning/www/process/options.php'. This vulnerability could allow a remote usβ¦
7.7
CVE-2025-12405 - Unauthorized access through stored credentials in Looker Studio
An improper privilege management vulnerability was found in Looker Studio.Β It impacted all JDBC-based connectors. A Looker Studio user with report view access could make a copy of the report and execute arbitrary SQL that would run on the data source database due to the stored credentials attachedβ¦
5.1
CVE-2025-41107 - Stored XSS in Smart School
Stored Cross Site Scripting (XSS) vulnerability in Smart School 7.0 due to lack of proper validation of user input when sending a POST request to '/online_admission', wich affects the parameters 'firstname', 'lastname', 'guardian_name' and others. This vulnerability could allow a remote user to senβ¦