6.9

CVSS4.0

CVE-2025-9155 - itsourcecode Online Tour and Travel Management System forget_password.php sql injection

A vulnerability has been found in itsourcecode Online Tour and Travel Management System 1.0. Impacted is an unknown function of the file /user/forget_password.php. Such manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to …

πŸ“… Published: Aug. 19, 2025, 7:32 p.m. πŸ”„ Last Modified: Aug. 21, 2025, 6:40 p.m.

2.7

CVSS3.1

CVE-2025-2988 - IBM Sterling B2B Integrator and IBM Sterling File Gateway information disclosure

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7, 6.2.0.0 through 6.2.0.4, and 6.2.1.0 could disclose sensitive server information to an unauthorized user that could aid in further attacks against the system.

πŸ“… Published: Aug. 19, 2025, 7:15 p.m. πŸ”„ Last Modified: Aug. 19, 2025, 7:15 p.m.

5.3

CVSS4.0

CVE-2025-43743 -

Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.5, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.15 and 7.4 GA through update 92 allows any authenticated remote user to view other calendars by all…

πŸ“… Published: Aug. 19, 2025, 7:13 p.m. πŸ”„ Last Modified: Aug. 19, 2025, 7:13 p.m.

6.9

CVSS4.0

CVE-2025-55737 - flaskBlog arbitrary comment delete

flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when deleting a comment, there's no validation of the ownership of the comment. Every user can delete an arbitrary comment of another user on every post, by simply intercepting the delete request and changing the commentID. The code th…

πŸ“… Published: Aug. 19, 2025, 7:06 p.m. πŸ”„ Last Modified: Aug. 21, 2025, 6:40 p.m.

9.3

CVSS4.0

CVE-2025-55736 - flaskBlog allows arbitrary privilege escalation

flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, an arbitrary user can change his role to "admin", giving its relative privileges (e.g. delete users, posts, comments etc.). The problem is in the routes/adminPanelUsers file.

πŸ“… Published: Aug. 19, 2025, 7:04 p.m. πŸ”„ Last Modified: Aug. 19, 2025, 7:04 p.m.

5.4

CVSS3.1

CVE-2025-33008 - IBM Sterling B2B Integrator and IBM Sterling File Gateway cross-site scripting

IBM Sterling B2B Integrator 6.2.1.0 and IBM Sterling File GatewayΒ 6.2.1.0Β is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure wi…

πŸ“… Published: Aug. 19, 2025, 7:03 p.m. πŸ”„ Last Modified: Aug. 19, 2025, 7:03 p.m.

6.9

CVSS4.0

CVE-2025-9154 - itsourcecode Online Tour and Travel Management System page-login.php sql injection

A flaw has been found in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown processing of the file /user/page-login.php. This manipulation of the argument email causes sql injection. The attack may be initiated remotely. The exploit has been published and may…

πŸ“… Published: Aug. 19, 2025, 7:02 p.m. πŸ”„ Last Modified: Aug. 21, 2025, 6:40 p.m.

5.3

CVSS4.0

CVE-2025-55735 - flaskBlog Stored XSS Vulnerability

flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when creating a post, there's no validation of the content of the post stored in the variable "postContent". The vulnerability arises when displaying the content of the post using the | safe filter, that tells the engine to not escape …

πŸ“… Published: Aug. 19, 2025, 6:56 p.m. πŸ”„ Last Modified: Aug. 19, 2025, 6:56 p.m.

6.9

CVSS4.0

CVE-2025-43745 -

A CSRF vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.7, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.19 and 7.4 GA through update 92 allows remote…

πŸ“… Published: Aug. 19, 2025, 6:39 p.m. πŸ”„ Last Modified: Aug. 19, 2025, 6:39 p.m.

6.9

CVSS4.0

CVE-2025-55734 - flaskBlo Authorization Bypass

flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, the code checks if the userRole is "admin" only when visiting the /admin page, but not when visiting its subroutes. Specifically, only the file routes/adminPanel.py checks the user role when a user is trying to access the admin page, b…

πŸ“… Published: Aug. 19, 2025, 6:38 p.m. πŸ”„ Last Modified: Aug. 19, 2025, 6:38 p.m.
Total resulsts: 306500
Page 41 of 30,650
Β« previous page Β» next page
Filters