7.8

CVSS3.1

CVE-2024-49720 -

In multiple functions of Permissions.java, there is a possible way to override the state of the user's location permissions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitatโ€ฆ

๐Ÿ“… Published: Sept. 2, 2025, 10:11 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 5:49 p.m.

7.3

CVSS3.1

CVE-2024-40653 -

In multiple functions of ConnectionServiceWrapper.java, there is a possible way to retain a permission forever in the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitaโ€ฆ

๐Ÿ“… Published: Sept. 2, 2025, 10:11 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 5:49 p.m.

6.9

CVSS4.0

CVE-2025-9837 - itsourcecode Student Information Management System index.php sql injection

A vulnerability was determined in itsourcecode Student Information Management System 1.0. This issue affects some unknown processing of the file /admin/modules/student/index.php. This manipulation of the argument studentId causes sql injection. The attack may be initiated remotely. The exploit has โ€ฆ

๐Ÿ“… Published: Sept. 2, 2025, 10:02 p.m. ๐Ÿ”„ Last Modified: Sept. 5, 2025, 5:40 p.m.

5.3

CVSS4.0

CVE-2025-9836 - macrozheng mall paySuccess authorization

A vulnerability was found in macrozheng mall up to 1.0.3. This vulnerability affects the function paySuccess of the file /order/paySuccess. The manipulation of the argument orderId results in authorization bypass. The attack can be launched remotely. The exploit has been made public and could be usโ€ฆ

๐Ÿ“… Published: Sept. 2, 2025, 10:02 p.m. ๐Ÿ”„ Last Modified: Nov. 26, 2025, 4:29 p.m.

5.3

CVSS4.0

CVE-2025-9835 - macrozheng mall cancelUserOrder cancelOrder authorization

A vulnerability has been found in macrozheng mall up to 1.0.3. This affects the function cancelOrder of the file /order/cancelUserOrder. The manipulation of the argument orderId leads to authorization bypass. The attack can be initiated remotely. The exploit has been disclosed to the public and mayโ€ฆ

๐Ÿ“… Published: Sept. 2, 2025, 9:32 p.m. ๐Ÿ”„ Last Modified: Sept. 5, 2025, 5:44 p.m.

5.1

CVSS4.0

CVE-2025-9834 - PHPGurukul Small CRM registration.php cross site scripting

A flaw has been found in PHPGurukul Small CRM 4.0. Affected by this issue is some unknown functionality of the file /registration.php. Executing manipulation of the argument Username can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and mโ€ฆ

๐Ÿ“… Published: Sept. 2, 2025, 9:02 p.m. ๐Ÿ”„ Last Modified: Sept. 5, 2025, 5:46 p.m.

6.9

CVSS4.0

CVE-2025-9833 - SourceCodester Online Farm Management System login.php sql injection

A vulnerability was detected in SourceCodester Online Farm Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /Login/login.php. Performing manipulation of the argument uname results in sql injection. It is possible to initiate the attack remotely. The explโ€ฆ

๐Ÿ“… Published: Sept. 2, 2025, 9:02 p.m. ๐Ÿ”„ Last Modified: Sept. 5, 2025, 5:47 p.m.

6.9

CVSS4.0

CVE-2025-9832 - SourceCodester Food Ordering Management System register-router.php sql injection

A security vulnerability has been detected in SourceCodester Food Ordering Management System 1.0. Affected is an unknown function of the file /routers/register-router.php. Such manipulation of the argument phone leads to sql injection. The attack may be performed from remote. The exploit has been dโ€ฆ

๐Ÿ“… Published: Sept. 2, 2025, 8:32 p.m. ๐Ÿ”„ Last Modified: Sept. 5, 2025, 5:50 p.m.

6.9

CVSS4.0

CVE-2025-9831 - PHPGurukul Beauty Parlour Management System edit-services.php sql injection

A weakness has been identified in PHPGurukul Beauty Parlour Management System 1.1. This impacts an unknown function of the file /admin/edit-services.php. This manipulation of the argument sername causes sql injection. The attack is possible to be carried out remotely. The exploit has been made avaiโ€ฆ

๐Ÿ“… Published: Sept. 2, 2025, 8:32 p.m. ๐Ÿ”„ Last Modified: Sept. 5, 2025, 5:54 p.m.

7.8

CVSS3.0

CVE-2025-9330 - Foxit PDF Reader Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulneraโ€ฆ

Foxit PDF Reader Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker must first obtain the ability to execute low-privileged code on the โ€ฆ

๐Ÿ“… Published: Sept. 2, 2025, 8:09 p.m. ๐Ÿ”„ Last Modified: Sept. 8, 2025, 1:52 p.m.
Total resulsts: 349182
Page 4050 of 34,919
ยซ previous page ยป next page
Filters