9.8

CVSS3.1

CVE-2024-11739 - SQLi in Case Informatics' Case ERP

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Case Informatics Case ERP allows SQL Injection.This issue affects Case ERP: before V2.0.1.

πŸ“… Published: June 27, 2025, 3:41 p.m. πŸ”„ Last Modified: June 30, 2025, 6:38 p.m.

10

CVSS4.0

CVE-2025-53091 - WeGIA has Unauthenticated Time-Based Blind SQL Injection in almox Parameter

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Time-Based Blind SQL Injection vulnerability was discovered in version 3.3.3 the almox parameter of the `/controle/getProdutosPorAlmox.php` endpoint. This issue allows any unauthenticated atta…

πŸ“… Published: June 27, 2025, 3:08 p.m. πŸ”„ Last Modified: July 8, 2025, 2:48 p.m.

5.5

CVSS4.0

CVE-2025-52553 - authentik has Insufficient Session verification for Remote Access Control endpoint access

authentik is an open-source identity provider. After authorizing access to a RAC endpoint, authentik creates a token which is used for a single connection and is sent to the client in the URL. This token is intended to only be valid for the session of the user who authorized the connection, however…

πŸ“… Published: June 27, 2025, 3:03 p.m. πŸ”„ Last Modified: Aug. 21, 2025, 6:39 p.m.

7.6

CVSS4.0

CVE-2025-6705 -

A vulnerability in the Eclipse Open VSX Registry’s automated publishing system could have allowed unauthorized uploads of extensions. Specifically, the system’s build scripts were executed without proper isolation, potentially exposing a privileged token. This token enabled the publishing of new ex…

πŸ“… Published: June 27, 2025, 2:57 p.m. πŸ”„ Last Modified: July 31, 2025, 4:12 p.m.

5.4

CVSS3.1

CVE-2023-38007 - IBM Cloud Pak System HTML injection

IBM Cloud Pak System 2.3.5.0, 2.3.3.7, 2.3.3.7 iFix1 on Power and 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.4.0, 2.3.4.1 on Intel operating systems is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser …

πŸ“… Published: June 27, 2025, 2:48 p.m. πŸ”„ Last Modified: Aug. 17, 2025, 12:24 a.m.

7.2

CVSS3.1

CVE-2025-36595 -

Dell Unisphere for PowerMax vApp, version(s) 9.2.4.x, contain(s) an Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.

πŸ“… Published: June 27, 2025, 1:51 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

5.3

CVSS4.0

CVE-2025-6768 - sfturing hosp_order HospitalServiceImpl.java findAllHosByCondition sql injection

A vulnerability classified as critical has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. Affected is the function findAllHosByCondition of the file HospitalServiceImpl.java. The manipulation of the argument hospitalName leads to sql injection. It is possible to l…

πŸ“… Published: June 27, 2025, 1:31 p.m. πŸ”„ Last Modified: July 12, 2025, 4:01 p.m.

0.0

CVE-2025-53339 - WordPress Devnex Addons For Elementor plugin <= 1.0.9 - Local File Inclusion Vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in devnex Devnex Addons For Elementor devnex-addons-for-elementor allows PHP Local File Inclusion.This issue affects Devnex Addons For Elementor: from n/a through <= 1.0.9.

πŸ“… Published: June 27, 2025, 1:21 p.m. πŸ”„ Last Modified: April 1, 2026, 5:26 p.m.

0.0

CVE-2025-53338 - WordPress re.place plugin <= 0.2.1 - Cross Site Request Forgery (CSRF) Vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in dor re.place replace allows Stored XSS.This issue affects re.place: from n/a through <= 0.2.1.

πŸ“… Published: June 27, 2025, 1:21 p.m. πŸ”„ Last Modified: April 1, 2026, 5:26 p.m.

0.0

CVE-2025-53336 - WordPress My Resume Builder plugin <= 1.0.3 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in abditsori My Resume Builder my-resume-builder allows Stored XSS.This issue affects My Resume Builder: from n/a through <= 1.0.3.

πŸ“… Published: June 27, 2025, 1:21 p.m. πŸ”„ Last Modified: April 1, 2026, 5:26 p.m.
Total resulsts: 343928
Page 4328 of 34,393
Β« previous page Β» next page
Filters