6.9

CVSS4.0

CVE-2025-9305 - SourceCodester Online Bank Management System mnotice.php sql injection

A security vulnerability has been detected in SourceCodester Online Bank Management System 1.0. The affected element is an unknown function of the file /bank/mnotice.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…

πŸ“… Published: Aug. 21, 2025, 3:02 p.m. πŸ”„ Last Modified: Aug. 23, 2025, 10:55 a.m.

6.9

CVSS4.0

CVE-2025-9304 - SourceCodester Online Bank Management System show.php sql injection

A weakness has been identified in SourceCodester Online Bank Management System 1.0. Impacted is an unknown function of the file /bank/show.php. Executing manipulation of the argument ID can lead to sql injection. The attack may be performed from a remote location. The exploit has been made availabl…

πŸ“… Published: Aug. 21, 2025, 3:02 p.m. πŸ”„ Last Modified: Aug. 23, 2025, 10:55 a.m.

9.9

CVSS3.1

CVE-2025-53251 - WordPress Pin WP theme < 7.2 - Arbitrary File Upload Vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in An-Themes Pin WP pin-wp allows Upload a Web Shell to a Web Server.This issue affects Pin WP: from n/a through < 7.2.

πŸ“… Published: Aug. 21, 2025, 2:43 p.m. πŸ”„ Last Modified: April 23, 2026, 3:32 p.m.

7.5

CVSS3.1

CVE-2025-48956 - vLLM API endpoints vulnerable to Denial of Service Attacks

vLLM is an inference and serving engine for large language models (LLMs). From 0.1.0 to before 0.10.1.1, a Denial of Service (DoS) vulnerability can be triggered by sending a single HTTP GET request with an extremely large header to an HTTP endpoint. This results in server memory exhaustion, potent…

πŸ“… Published: Aug. 21, 2025, 2:41 p.m. πŸ”„ Last Modified: Oct. 9, 2025, 6:04 p.m.

8.7

CVSS4.0

CVE-2025-9303 - TOTOLINK A720R cstecgi.cgi setParentalRules buffer overflow

A security flaw has been discovered in TOTOLINK A720R 4.1.5cu.630_B20250509. This issue affects the function setParentalRules of the file /cgi-bin/cstecgi.cgi. Performing manipulation of the argument desc results in buffer overflow. The attack is possible to be carried out remotely. The exploit has…

πŸ“… Published: Aug. 21, 2025, 2:32 p.m. πŸ”„ Last Modified: Oct. 6, 2025, 6:48 p.m.

6.9

CVSS4.0

CVE-2025-9302 - PHPGurukul User Management System signup.php sql injection

A vulnerability was identified in PHPGurukul User Management System 1.0. This vulnerability affects unknown code of the file /signup.php. Such manipulation of the argument emailid leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.

πŸ“… Published: Aug. 21, 2025, 2:02 p.m. πŸ”„ Last Modified: Aug. 23, 2025, 10:55 a.m.

8.5

CVSS3.1

CVE-2025-34158 -

Plex Media Server (PMS) 1.41.7.x through 1.42.0.x before 1.42.1 is affected by incorrect resource transfer between spheres because /myplex/account provides the credentials of the server owner (and a /api/resources call reveals other servers accessible by that server owner).

πŸ“… Published: Aug. 21, 2025, 1:43 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-9301 - cmake cmForEachCommand.cxx ReplayItems assertion

A vulnerability was determined in cmake 4.1.20250725-gb5cce23. This affects the function cmForEachFunctionBlocker::ReplayItems of the file cmForEachCommand.cxx. This manipulation causes reachable assertion. The attack needs to be launched locally. The exploit has been publicly disclosed and may be …

πŸ“… Published: Aug. 21, 2025, 1:32 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-9300 - saitoha libsixel img2sixel encoder.c sixel_debug_print_palette stack-based overflow

A vulnerability was found in saitoha libsixel up to 1.10.3. Affected by this issue is the function sixel_debug_print_palette of the file src/encoder.c of the component img2sixel. The manipulation results in stack-based buffer overflow. The attack must be initiated from a local position. The exploit…

πŸ“… Published: Aug. 21, 2025, 1:02 p.m. πŸ”„ Last Modified: April 24, 2026, 1:44 p.m.

8.7

CVSS4.0

CVE-2025-9299 - Tenda M3 getMasterPassengerAnalyseData formGetMasterPassengerAnalyseData stack-based overflow

A vulnerability has been found in Tenda M3 1.0.0.12. Affected by this vulnerability is the function formGetMasterPassengerAnalyseData of the file /goform/getMasterPassengerAnalyseData. The manipulation of the argument Time leads to stack-based buffer overflow. The attack may be initiated remotely. …

πŸ“… Published: Aug. 21, 2025, 12:32 p.m. πŸ”„ Last Modified: Aug. 25, 2025, 2 a.m.
Total resulsts: 349182
Page 4184 of 34,919
Β« previous page Β» next page
Filters