6.3

CVSS3.1

CVE-2025-24344 -

A vulnerability in the error notification messages of the web application of ctrlX OS allows a remote unauthenticated attacker to inject arbitrary HTML tags and, possibly, execute arbitrary client-side code in the context of another user's browser via a crafted HTTP request.

πŸ“… Published: April 30, 2025, 11:33 a.m. πŸ”„ Last Modified: April 30, 2025, 2:52 p.m.

5.4

CVSS3.1

CVE-2025-24343 -

A vulnerability in the β€œManages app data” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to write arbitrary files in arbitrary file system paths via a crafted HTTP request.

πŸ“… Published: April 30, 2025, 11:26 a.m. πŸ”„ Last Modified: April 30, 2025, 3:07 p.m.

5.3

CVSS3.1

CVE-2025-24342 -

A vulnerability in the login functionality of the web application of ctrlX OS allows a remote unauthenticated attacker to guess valid usernames via multiple crafted HTTP requests.

πŸ“… Published: April 30, 2025, 11:25 a.m. πŸ”„ Last Modified: April 30, 2025, 3:08 p.m.

6.5

CVSS3.1

CVE-2025-24341 -

A vulnerability in the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to induce a Denial-of-Service (DoS) condition on the device via multiple crafted HTTP requests. In the worst case, a full power cycle is needed to regain control of the device.

πŸ“… Published: April 30, 2025, 11:14 a.m. πŸ”„ Last Modified: April 30, 2025, 3:11 p.m.

5.3

CVSS4.0

CVE-2025-4113 - PHPGurukul Curfew e-Pass Management System edit-pass-detail.php sql injection

A vulnerability was found in PHPGurukul Curfew e-Pass Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/edit-pass-detail.php. The manipulation of the argument editid leads to sql injection. The attack may be initiated remotely. The e…

πŸ“… Published: April 30, 2025, 11 a.m. πŸ”„ Last Modified: April 30, 2025, 3:24 p.m.

6.9

CVSS4.0

CVE-2025-4112 - PHPGurukul Student Record System add-course.php sql injection

A vulnerability was found in PHPGurukul Student Record System 3.20. It has been declared as critical. This vulnerability affects unknown code of the file /add-course.php. The manipulation of the argument course-short leads to sql injection. The attack can be initiated remotely. The exploit has been…

πŸ“… Published: April 30, 2025, 11 a.m. πŸ”„ Last Modified: April 30, 2025, 3:32 p.m.

6.5

CVSS3.1

CVE-2025-24340 -

A vulnerability in the users configuration file of ctrlX OS may allow a remote authenticated (low-privileged) attacker to recover the plaintext passwords of other users.

πŸ“… Published: April 30, 2025, 10:59 a.m. πŸ”„ Last Modified: April 30, 2025, 3:44 p.m.

5

CVSS3.1

CVE-2025-24339 -

A vulnerability in the web application of ctrlX OS allows a remote unauthenticated attacker to conduct various attacks against users of the vulnerable system, including web cache poisoning or Man-in-the-Middle (MitM), via a crafted HTTP request.

πŸ“… Published: April 30, 2025, 10:54 a.m. πŸ”„ Last Modified: April 30, 2025, 3:46 p.m.

7.1

CVSS3.1

CVE-2025-24338 -

A vulnerability in the β€œManages app data” functionality of the web application of ctrlX OS allows a remote authenticated (lowprivileged) attacker to execute arbitrary client-side code in the context of another user's browser via multiple crafted HTTP requests.

πŸ“… Published: April 30, 2025, 10:51 a.m. πŸ”„ Last Modified: April 30, 2025, 3:48 p.m.

5.3

CVSS4.0

CVE-2025-4111 - PHPGurukul Pre-School Enrollment System visitor-details.php sql injection

A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/visitor-details.php. The manipulation of the argument Status leads to sql injection. It is possible to initiate the attack remotely. The expl…

πŸ“… Published: April 30, 2025, 10:31 a.m. πŸ”„ Last Modified: April 30, 2025, 3:51 p.m.
Total resulsts: 291833
Page 4 of 29,184
Β« previous page Β» next page
Filters