5.3

CVSS4.0

CVE-2025-13347 - SourceCodester Train Station Ticketing System ajax.php sql injection

A flaw has been found in SourceCodester Train Station Ticketing System 1.0. This vulnerability affects unknown code of the file /ajax.php?action=save_user. Executing manipulation of the argument Username can lead to sql injection. The attack may be launched remotely. The exploit has been published …

📅 Published: Nov. 18, 2025, 1:02 p.m. 🔄 Last Modified: Nov. 19, 2025, 8:01 p.m.

5.3

CVSS4.0

CVE-2025-13346 - SourceCodester Train Station Ticketing System ajax.php sql injection

A vulnerability was detected in SourceCodester Train Station Ticketing System 1.0. This affects an unknown part of the file /ajax.php?action=save_station. Performing manipulation of the argument id/station results in sql injection. The attack may be initiated remotely. The exploit is now public and…

📅 Published: Nov. 18, 2025, 12:32 p.m. 🔄 Last Modified: Nov. 19, 2025, 8:01 p.m.

6.8

CVSS3.1

CVE-2025-8084 - AI Engine <= 3.1.8 - Authenticated (Editor+) Server-Side Request Forgery

The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.8 via the rest_helpers_create_images function. This makes it possible for authenticated attackers, with Editor-level access and above, to make web requests to arbitrary location…

📅 Published: Nov. 18, 2025, 12:29 p.m. 🔄 Last Modified: April 21, 2026, 1:45 a.m.

9.8

CVSS3.1

CVE-2025-9312 - Improper Certificate-Based Authentication Enforcement in Multiple WSO2 Products

A missing authentication enforcement vulnerability exists in the mutual TLS (mTLS) implementation used by System REST APIs and SOAP services in multiple WSO2 products. Due to improper validation of client certificate–based authentication in certain default configurations, the affected components ma…

📅 Published: Nov. 18, 2025, 12:05 p.m. 🔄 Last Modified: Dec. 8, 2025, 2:01 p.m.

5.3

CVSS4.0

CVE-2025-13345 - SourceCodester Train Station Ticketing System ajax.php sql injection

A security vulnerability has been detected in SourceCodester Train Station Ticketing System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=save_ticket. Such manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclos…

📅 Published: Nov. 18, 2025, 12:02 p.m. 🔄 Last Modified: Nov. 19, 2025, 1:02 p.m.

6.9

CVSS4.0

CVE-2025-13344 - SourceCodester Train Station Ticketing System ajax.php sql injection

A weakness has been identified in SourceCodester Train Station Ticketing System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=login. This manipulation of the argument Username causes sql injection. The attack can be initiated remotely. The exploit has …

📅 Published: Nov. 18, 2025, 12:02 p.m. 🔄 Last Modified: Nov. 19, 2025, 1:02 p.m.

5.1

CVSS4.0

CVE-2025-13343 - SourceCodester Interview Management System editQuestion.php cross site scripting

A security flaw has been discovered in SourceCodester Interview Management System 1.0. Affected is an unknown function of the file /editQuestion.php. The manipulation of the argument Question results in cross site scripting. It is possible to launch the attack remotely. The exploit has been release…

📅 Published: Nov. 18, 2025, 11:32 a.m. 🔄 Last Modified: Nov. 20, 2025, 3:54 p.m.

8.8

CVSS3.1

CVE-2025-6670 - Cross-Site Request Forgery (CSRF) in Multiple WSO2 Products via HTTP GET in Admin Services

A Cross-Site Request Forgery (CSRF) vulnerability exists in multiple WSO2 products due to the use of the HTTP GET method for state-changing operations within admin services, specifically in the event processor of the Carbon console. Although the SameSite=Lax cookie attribute is used as a mitigation…

📅 Published: Nov. 18, 2025, 11:28 a.m. 🔄 Last Modified: Dec. 8, 2025, 2 p.m.

5.1

CVSS4.0

CVE-2025-41350 - Stored Cross-Site Scripting (XSS) in WinPlus by Informática del Este

Stored Cross-site Scripting (XSS)vylnerability type in WinPlus v24.11.27 byInformática del Este that consist of an stored XSS of a stored XSS due to a lack of proper validation of user input by sending a POST request using the 'descripcion' parameter in '/WinplusPortal/ws/sWinplus.svc/json/savesold…

📅 Published: Nov. 18, 2025, 11:27 a.m. 🔄 Last Modified: Feb. 18, 2026, 12:17 p.m.

5.1

CVSS4.0

CVE-2025-41349 - Stored Cross-Site Scripting (XSS) in WinPlus by Informática del Este

Stored Cross-site Scripting (XSS)vylnerability type in WinPlus v24.11.27 byInformática del Este that consist of an stored XSS of a stored XSS due to a lack of proper validation of user input by sending a POST request using the 'descripcion' parameter in '/WinplusPortal/ws/sWinplus. svc/json/savesol…

📅 Published: Nov. 18, 2025, 11:26 a.m. 🔄 Last Modified: Feb. 18, 2026, 12:17 p.m.
Total resulsts: 349182
Page 2976 of 34,919
« previous page » next page
Filters