6.9

CVSS4.0

CVE-2025-8972 - itsourcecode Online Tour and Travel Management System page-login.php sql injection

A vulnerability was identified in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown processing of the file /admin/page-login.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been discloโ€ฆ

๐Ÿ“… Published: Aug. 14, 2025, 5:32 p.m. ๐Ÿ”„ Last Modified: Aug. 18, 2025, 3 p.m.

6.5

CVSS3.1

CVE-2024-37945 - WordPress WPBITS Addons For Elementor plugin <= 1.5 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpbits WPBITS Addons For Elementor Page Builder wpbits-addons-for-elementor allows Stored XSS.This issue affects WPBITS Addons For Elementor Page Builder: from n/a through <= 1.5.

๐Ÿ“… Published: Aug. 14, 2025, 5:15 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:18 p.m.

6.9

CVSS4.0

CVE-2025-8971 - itsourcecode Online Tour and Travel Management System travellers.php sql injection

A vulnerability was determined in itsourcecode Online Tour and Travel Management System 1.0. This vulnerability affects unknown code of the file /admin/operations/travellers.php. The manipulation of the argument val-username leads to sql injection. The attack can be initiated remotely. The exploit โ€ฆ

๐Ÿ“… Published: Aug. 14, 2025, 5:02 p.m. ๐Ÿ”„ Last Modified: Aug. 18, 2025, 2:54 p.m.

6.9

CVSS4.0

CVE-2025-8970 - itsourcecode Online Tour and Travel Management System booking.php sql injection

A vulnerability was found in itsourcecode Online Tour and Travel Management System 1.0. This affects an unknown part of the file /admin/operations/booking.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed โ€ฆ

๐Ÿ“… Published: Aug. 14, 2025, 5:02 p.m. ๐Ÿ”„ Last Modified: Aug. 18, 2025, 2:54 p.m.

8.6

CVSS4.0

CVE-2025-55192 - HomeAssistant-Tapo-Control Code Injection Vulnerability in issues.yml Workflow

HomeAssistant-Tapo-Control offers Control for Tapo cameras as a Home Assistant component. Prior to commit 2a3b80f, there is a code injection vulnerability in the GitHub Actions workflow .github/workflows/issues.yml. It does not affect users of the Home Assistant integration itself โ€” it only impactsโ€ฆ

๐Ÿ“… Published: Aug. 14, 2025, 4:40 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6

CVSS3.1

CVE-2025-20220 -

A vulnerability in the CLI of Cisco Secure Firewall Management Center (FMC) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as root. This vulnerability is due to impropeโ€ฆ

๐Ÿ“… Published: Aug. 14, 2025, 4:40 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS3.1

CVE-2025-55195 - @std/toml Prototype Pollution in Node.js and Browser

@std/toml is the Deno Standard Library. Prior to version 1.0.9, an attacker can pollute the prototype chain in Node.js runtime and Browser when parsing untrusted TOML data, thus achieving Prototype Pollution (PP) vulnerability. This is because the library is merging an untrusted object with an emptโ€ฆ

๐Ÿ“… Published: Aug. 14, 2025, 4:39 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-8969 - itsourcecode Online Tour and Travel Management System approve_user.php sql injection

A vulnerability has been found in itsourcecode Online Tour and Travel Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/approve_user.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has beeโ€ฆ

๐Ÿ“… Published: Aug. 14, 2025, 4:32 p.m. ๐Ÿ”„ Last Modified: Aug. 18, 2025, 2:53 p.m.

6.9

CVSS4.0

CVE-2025-8968 - itsourcecode Online Tour and Travel Management System disapprove_user.php sql injection

A vulnerability was identified in itsourcecode Online Tour and Travel Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/disapprove_user.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploiโ€ฆ

๐Ÿ“… Published: Aug. 14, 2025, 4:32 p.m. ๐Ÿ”„ Last Modified: Aug. 18, 2025, 2:53 p.m.

4.9

CVSS3.1

CVE-2025-20306 - Cisco Secure Firewall Management Center Software Command Injection Vulnerability

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker with Administrator-level privileges to execute arbitrary commands on the underlying operating system. This vulnerability is due to insuffiโ€ฆ

๐Ÿ“… Published: Aug. 14, 2025, 4:31 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 5:48 p.m.
Total resulsts: 349182
Page 4271 of 34,919
ยซ previous page ยป next page
Filters