6.9

CVSS4.0

CVE-2025-35432 - CISA Thorium does not rate limit account verification email messages

CISA Thorium does not rate limit requests to send account verification email messages. A remote unauthenticated attacker can send unlimited messages to a user who is pending verification. Fixed in 1.1.1 by adding a rate limit set by default to 10 minutes.

πŸ“… Published: Sept. 17, 2025, 4:52 p.m. πŸ”„ Last Modified: Sept. 30, 2025, 4:27 p.m.

5.3

CVSS4.0

CVE-2025-35431 - CISA Thorium LDAP injection

CISA Thorium does not escape user controlled strings used in LDAP queries. An authenticated remote attacker can modify LDAP authorization data such as group memberships. Fixed in 1.1.1.

πŸ“… Published: Sept. 17, 2025, 4:52 p.m. πŸ”„ Last Modified: Sept. 30, 2025, 3:27 p.m.

5.3

CVSS4.0

CVE-2025-35430 - CISA Thorium insecure downloaded file path validation

CISA Thorium does not adequately validate the paths of downloaded files via 'download_ephemeral' and 'download_children'. A remote, authenticated attacker could access arbitrary files subject to file system permissions. Fixed in 1.1.2.

πŸ“… Published: Sept. 17, 2025, 4:51 p.m. πŸ”„ Last Modified: Oct. 8, 2025, 7:01 p.m.

6.9

CVSS4.0

CVE-2025-10601 - SourceCodester Online Exam Form Submission index.php sql injection

A vulnerability has been found in SourceCodester Online Exam Form Submission 1.0. Affected is an unknown function of the file /admin/index.php. Such manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public …

πŸ“… Published: Sept. 17, 2025, 4:32 p.m. πŸ”„ Last Modified: Sept. 22, 2025, 2:57 p.m.

6.9

CVSS4.0

CVE-2025-10600 - SourceCodester Online Exam Form Submission register.php unrestricted upload

A flaw has been found in SourceCodester Online Exam Form Submission 1.0. This impacts an unknown function of the file /register.php. This manipulation of the argument img causes unrestricted upload. It is possible to initiate the attack remotely. The exploit has been published and may be used.

πŸ“… Published: Sept. 17, 2025, 4:32 p.m. πŸ”„ Last Modified: Sept. 22, 2025, 2:59 p.m.

6.9

CVSS4.0

CVE-2025-10599 - itsourcecode Web-Based Internet Laboratory Management System login.php AuthenticateUser sql injecti…

A security flaw has been discovered in itsourcecode Web-Based Internet Laboratory Management System 1.0. Impacted is the function User::AuthenticateUser of the file login.php. Performing manipulation of the argument user_email results in sql injection. Remote exploitation of the attack is possible.…

πŸ“… Published: Sept. 17, 2025, 4:02 p.m. πŸ”„ Last Modified: Sept. 22, 2025, 3:02 p.m.

6.9

CVSS4.0

CVE-2025-10598 - SourceCodester Pet Grooming Management Software search_product.php sql injection

A vulnerability was identified in SourceCodester Pet Grooming Management Software 1.0. This issue affects some unknown processing of the file /admin/search_product.php. Such manipulation of the argument group_id leads to sql injection. The attack may be launched remotely. The exploit is publicly av…

πŸ“… Published: Sept. 17, 2025, 4:02 p.m. πŸ”„ Last Modified: Sept. 22, 2025, 3:03 p.m.

6.9

CVSS4.0

CVE-2025-10597 - kidaze CourseSelectionSystem COUNT2.php sql injection

A vulnerability was determined in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. This vulnerability affects unknown code of the file /Profilers/PriProfile/COUNT2.php. This manipulation of the argument cname causes sql injection. The attack may be initiated remotely. Th…

πŸ“… Published: Sept. 17, 2025, 3:32 p.m. πŸ”„ Last Modified: Oct. 8, 2025, 7:07 p.m.

6.9

CVSS4.0

CVE-2025-10596 - SourceCodester Online Exam Form Submission index.php sql injection

A vulnerability was found in SourceCodester Online Exam Form Submission 1.0. This affects an unknown part of the file /index.php. The manipulation of the argument usn results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.

πŸ“… Published: Sept. 17, 2025, 3:02 p.m. πŸ”„ Last Modified: Sept. 22, 2025, 3:09 p.m.

6.1

CVSS4.0

CVE-2025-9862 - Ghost 6.0.6 - SSRF via oEmbed Bookmark

Server-Side Request Forgery (SSRF) vulnerability in Ghost allows an attacker to access internal resources.This issue affects Ghost: from 6.0.0 through 6.0.8, from 5.99.0 through 5.130.3.

πŸ“… Published: Sept. 17, 2025, 3:02 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:36 p.m.
Total resulsts: 349182
Page 3806 of 34,919
Β« previous page Β» next page
Filters