8.7

CVSS4.0

CVE-2025-41373 - SQL injection vulnerability in Gandia Integra Total

A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /encuestas/integraweb[_v4]/integra/html/view/…

πŸ“… Published: Aug. 1, 2025, 12:29 p.m. πŸ”„ Last Modified: Aug. 1, 2025, 1:25 p.m.

8.7

CVSS4.0

CVE-2025-41372 - SQL injection vulnerability in Gandia Integra Total

A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /encuestas/integraweb[_v4]/integra/html/view/…

πŸ“… Published: Aug. 1, 2025, 12:29 p.m. πŸ”„ Last Modified: Aug. 1, 2025, 1:36 p.m.

9.3

CVSS4.0

CVE-2025-41371 - SQL injection vulnerability in Gandia Integra Total

A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /encuestas/integraweb_v4/integra/html/view/ac…

πŸ“… Published: Aug. 1, 2025, 12:28 p.m. πŸ”„ Last Modified: Aug. 1, 2025, 1:39 p.m.

9.3

CVSS4.0

CVE-2025-41370 - SQL injection vulnerability in Gandia Integra Total

A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /encuestas/integraweb/html/view/acceso.php.

πŸ“… Published: Aug. 1, 2025, 12:28 p.m. πŸ”„ Last Modified: Aug. 1, 2025, 1:43 p.m.

6.4

CVSS3.1

CVE-2025-6228 - Sina Extension for Elementor <= 3.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting vi…

The Sina Extension for Elementor (Header Builder, Footer Builter, Theme Builder, Slider, Gallery, Form, Modal, Data Table Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `Sina Posts`, `Sina Blog Post` and `Sina Table` widgets i…

πŸ“… Published: Aug. 1, 2025, 11:18 a.m. πŸ”„ Last Modified: Aug. 1, 2025, 1:43 p.m.

6.4

CVSS3.1

CVE-2025-4684 - BlockSpare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites <= 3.2.13.1 - Authenti…

The BlockSpare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites – Post Grids, Sliders, Carousels, Counters, Page Builder & Starter Site Imports, No Coding Needed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTML attributes of Image Carousel and Image Sl…

πŸ“… Published: Aug. 1, 2025, 11:18 a.m. πŸ”„ Last Modified: Aug. 1, 2025, 1:44 p.m.

6.7

CVSS4.0

CVE-2025-6398 -

A null pointer dereference vulnerability exists in the IOMap64.sys driver of ASUS AI Suite 3. The vulnerability can be triggered by a specially crafted input, which may lead to a system crash (BSOD). Refer to the ' Security Update for for AI Suite 3 ' section on the ASUS Security Advisory for mor…

πŸ“… Published: Aug. 1, 2025, 8:49 a.m. πŸ”„ Last Modified: Aug. 1, 2025, 12:03 p.m.

6.9

CVSS4.0

CVE-2025-8443 - code-projects Online Medicine Guide login.php sql injection

A vulnerability was found in code-projects Online Medicine Guide 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument uname leads to sql injection. The attack may be launched remotely. The exploit has been disc…

πŸ“… Published: Aug. 1, 2025, 8:32 a.m. πŸ”„ Last Modified: Aug. 1, 2025, 12:23 p.m.

6.9

CVSS4.0

CVE-2025-8442 - code-projects Online Medicine Guide cussignup.php sql injection

A vulnerability has been found in code-projects Online Medicine Guide 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /cussignup.php. The manipulation of the argument uname leads to sql injection. The attack can be launched remotely. The exploi…

πŸ“… Published: Aug. 1, 2025, 8:02 a.m. πŸ”„ Last Modified: Aug. 1, 2025, 12:32 p.m.

6.9

CVSS4.0

CVE-2025-8441 - code-projects Online Medicine Guide pharsignup.php sql injection

A vulnerability, which was classified as critical, was found in code-projects Online Medicine Guide 1.0. Affected is an unknown function of the file /pharsignup.php. The manipulation of the argument phuname leads to sql injection. It is possible to launch the attack remotely. The exploit has been d…

πŸ“… Published: Aug. 1, 2025, 7:32 a.m. πŸ”„ Last Modified: Aug. 1, 2025, 12:54 p.m.
Total resulsts: 303963
Page 4 of 30,397
Β« previous page Β» next page
Filters