6.9

CVSS4.0

CVE-2025-7750 - code-projects Online Appointment Booking System adddoctorclinic.php sql injection

A vulnerability, which was classified as critical, was found in code-projects Online Appointment Booking System 1.0. Affected is an unknown function of the file /admin/adddoctorclinic.php. The manipulation of the argument clinic leads to sql injection. It is possible to launch the attack remotely. …

πŸ“… Published: July 17, 2025, 7:02 p.m. πŸ”„ Last Modified: July 18, 2025, 6:16 p.m.

7.5

CVSS3.1

CVE-2025-7472 -

A local privilege escalation vulnerability in the Intercept X for Windows installer prior version 1.22 can lead to a local user gaining system level privileges, if the installer is run as SYSTEM.

πŸ“… Published: July 17, 2025, 6:53 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-54070 - OpenZeppelin Contracts's Bytes's lastIndexOf function with position argument performs out-of-bound …

OpenZeppelin Contracts is a library for secure smart contract development. Starting in version 5.2.0 and prior to version 5.4.0, the `lastIndexOf(bytes,byte,uint256)` function of the `Bytes.sol` library may access uninitialized memory when the following two conditions hold: 1) the provided buffer l…

πŸ“… Published: July 17, 2025, 6:25 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.2

CVSS4.0

CVE-2025-54068 - Livewire vulnerable to remote command execution during property update hydration

Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers to achieve remote command execution in specific scenarios. The issue stems from how certain component property updates are hydrated. This vulnerability is uniq…

πŸ“… Published: July 17, 2025, 6:16 p.m. πŸ”„ Last Modified: March 23, 2026, 1:04 p.m.

5.5

CVSS4.0

CVE-2025-53817 - GHSL-2025-059 - 7-Zip - Null pointer array write attempt in NArchive::NCom::CHandler::GetStream

7-Zip is a file archiver with a high compression ratio. 7-Zip supports extracting from Compound Documents. Prior to version 25.0.0, a null pointer dereference in the Compound handler may lead to denial of service. Version 25.0.0 contains a fix cor the issue.

πŸ“… Published: July 17, 2025, 6:12 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

5.5

CVSS4.0

CVE-2025-53816 - GHSL-2025-058 - 7-Zip Multi-byte write heap buffer overflow in NCompress::NRar5::CDecoder

7-Zip is a file archiver with a high compression ratio. Zeroes written outside heap buffer in RAR5 handler may lead to memory corruption and denial of service in versions of 7-Zip prior to 25.0.0. Version 25.0.0 contains a fix for the issue.

πŸ“… Published: July 17, 2025, 6:09 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

6.9

CVSS4.0

CVE-2025-7749 - code-projects Online Appointment Booking System getmanagerregion.php sql injection

A vulnerability, which was classified as critical, has been found in code-projects Online Appointment Booking System 1.0. This issue affects some unknown processing of the file /admin/getmanagerregion.php. The manipulation of the argument city leads to sql injection. The attack may be initiated rem…

πŸ“… Published: July 17, 2025, 6:02 p.m. πŸ”„ Last Modified: July 18, 2025, 4:47 p.m.

6.6

CVSS4.0

CVE-2025-53644 - OpenCV contains a use after free buffer write due to an uninitialized pointer

OpenCV is an Open Source Computer Vision Library. Versions 4.10.0 and 4.11.0 have an uninitialized pointer variable on stack that may lead to arbitrary heap buffer write when reading crafted JPEG images. Version 4.12.0 fixes the vulnerability.

πŸ“… Published: July 17, 2025, 5:58 p.m. πŸ”„ Last Modified: Oct. 17, 2025, 7:18 p.m.

6.9

CVSS4.0

CVE-2025-53638 - Solady lacks extcodesize validation on implementation in ERC4337Factory

Solady is software that provides Solidity snippets with APIs. Starting in version 0.0.125 and prior to version 0.1.24, when an account is deployed via a proxy, using regular Solidity to call its initialization function may result in a silent failure, if the initialization function does not return a…

πŸ“… Published: July 17, 2025, 5:54 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-7748 - ZCMS Create Article Page cross site scripting

A vulnerability classified as problematic was found in ZCMS 3.6.0. This vulnerability affects unknown code of the component Create Article Page. The manipulation of the argument Title leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public a…

πŸ“… Published: July 17, 2025, 5:32 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346528
Page 4342 of 34,653
Β« previous page Β» next page
Filters