6.9
CVE-2025-9662 - code-projects Simple Grading System Admin Panel login.php sql injection
A vulnerability was determined in code-projects Simple Grading System 1.0. This affects an unknown function of the file /login.php of the component Admin Panel. Executing manipulation can lead to sql injection. The attack may be performed from a remote location. The exploit has been publicly discloโฆ
6.9
CVE-2025-9660 - SourceCodester Bakeshop Online Ordering System passwordrecover.php sql injection
A vulnerability was found in SourceCodester Bakeshop Online Ordering System 1.0. The impacted element is an unknown function of the file /passwordrecover.php. Performing manipulation of the argument phonenumber results in sql injection. The attack is possible to be carried out remotely. The exploitโฆ
0.0
CVE-2025-58375 -
This CVE is a duplicate of another CVE.
5.1
CVE-2025-9659 - O2OA Personal Profile widget cross site scripting
A vulnerability has been found in O2OA up to 10.0-410. The affected element is an unknown function of the file /x_portal_assemble_designer/jaxrs/widget of the component Personal Profile Page. Such manipulation leads to cross site scripting. The attack can be executed remotely. The exploit has been โฆ
5.1
CVE-2025-9658 - O2OA Personal Profile dict cross site scripting
A flaw has been found in O2OA up to 10.0-410. Impacted is an unknown function of the file /x_portal_assemble_designer/jaxrs/dict/ of the component Personal Profile Page. This manipulation of the argument name/alias/description causes cross site scripting. Remote exploitation of the attack is possibโฆ
7.3
CVE-2025-47909 - Improper validation of TrustedOrigins allows CSRF attacks in github.com/gorilla/csrf
Hosts listed in TrustedOrigins implicitly allow requests from the corresponding HTTP origins, allowing network MitMs to perform CSRF attacks. After the CVE-2025-24358 fix, a network attacker that places a form at http://example.com can't get it to submit to https://example.com because the Origin heโฆ
6.5
CVE-2025-55750 - Gitpod Classic Affected by Bitbucket OAuth Token Exposure via Redirect Fragment
Gitpod is a developer platform for cloud development environments. In versions before main-gha.33628 for both Gitpod Classic and Gitpod Classic Enterprise, OAuth integration with Bitbucket in certain conditions allowed a crafted link to expose a valid Bitbucket access token via the URL fragment wheโฆ
5.4
CVE-2025-55177 -
Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a targetโs device. We aโฆ
7.3
CVE-2025-5808 - Authentication Bypass vulnerability discovered in the OpenTextโข Self-Service Password Reset
Improper Input Validation vulnerability in OpenText Self Service Password Reset allows Authentication Bypass.This issue affects Self Service Password Reset from before 4.8 patch 3.
2.7
CVE-2025-55202 - Opencast has a partial path traversal vulnerability in UI config
Opencast is a free, open-source platform to support the management of educational audio and video content. In version 18.0 and versions before 17.7, the protections against path traversal attacks in the UI config module are insufficient, still partially allowing for attacks in very specific cases. โฆ