2.1

CVSS4.0

CVE-2025-53535 - Better Auth has an Open Redirect Vulnerability in originCheck Middleware Affecting Multiple Routes

Better Auth is an authentication and authorization library for TypeScript. An open redirect has been found in the originCheck middleware function, which affects the following routes: /verify-email, /reset-password/:token, /delete-user/callback, /magic-link/verify, /oauth-proxy-callback. This vulner…

πŸ“… Published: July 7, 2025, 5:15 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-53532 - giscus allows unauthorized discussion creation

giscus is a commenting system powered by GitHub Discussions. A bug in giscus' discussions creation API allowed an unauthorized user to create discussions on any repository where giscus is installed. This affects the server-side part of giscus, which is provided via http://giscus.app or your own sel…

πŸ“… Published: July 7, 2025, 5:06 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-53531 - WeGIA allows Uncontrolled Resource Consumption via the fid parameter

WeGIA is a web manager for charitable institutions. The Wegia server has a vulnerability that allows excessively long HTTP GET requests to a specific URL. This issue arises from the lack of validation for the length of the fid parameter. Tests confirmed that the server processes URLs up to 8,142 ch…

πŸ“… Published: July 7, 2025, 5:02 p.m. πŸ”„ Last Modified: July 10, 2025, 8:49 p.m.

5.3

CVSS4.0

CVE-2025-7137 - SourceCodester Best Salon Management System schedule-staff.php sql injection

A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been classified as critical. This affects an unknown part of the file /panel/schedule-staff.php. The manipulation of the argument staff_id leads to sql injection. It is possible to initiate the attack remotely. The…

πŸ“… Published: July 7, 2025, 5:02 p.m. πŸ”„ Last Modified: July 9, 2025, 3:27 p.m.

8.7

CVSS4.0

CVE-2025-53530 - WeGIA allows Uncontrolled Resource Consumption via the errorstr parameter

WeGIA is a web manager for charitable institutions. The Wegia server has a vulnerability that allows excessively long HTTP GET requests to a specific URL. This issue arises from the lack of validation for the length of the errorstr parameter. Tests confirmed that the server processes URLs up to 8,1…

πŸ“… Published: July 7, 2025, 5 p.m. πŸ”„ Last Modified: July 10, 2025, 9:16 p.m.

9.8

CVSS3.1

CVE-2025-53529 - WeGIA allows SQL Injection in html/funcionario/profile_funcionario.php (id_funcionario parameter)

WeGIA is a web manager for charitable institutions. An SQL Injection vulnerability was identified in the /html/funcionario/profile_funcionario.php endpoint. The id_funcionario parameter is not properly sanitized or validated before being used in a SQL query, allowing an unauthenticated attacker to …

πŸ“… Published: July 7, 2025, 4:51 p.m. πŸ”„ Last Modified: July 10, 2025, 9:16 p.m.

8.3

CVSS4.0

CVE-2025-53527 - WeGIA allows Time-Based Blind SQL Injection in the relatorio_geracao.php endpoint

WeGIA is a web manager for charitable institutions. A Time-Based Blind SQL Injection vulnerability was discovered in the almox parameter of the /controle/relatorio_geracao.php endpoint. This issue allows attacker to inject arbitrary SQL queries, potentially leading to unauthorized data access or fu…

πŸ“… Published: July 7, 2025, 4:47 p.m. πŸ”„ Last Modified: July 10, 2025, 9:16 p.m.

6.7

CVSS3.1

CVE-2025-1351 - IBM Storage Virtualize privilege escalation

IBM Storage Virtualize 8.5, 8.6, and 8.7 products could allow a user to escalate their privileges to that of another user logging in at the same time due to a race condition in the login function.

πŸ“… Published: July 7, 2025, 4:41 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:27 p.m.

2

CVSS4.0

CVE-2025-53526 - WeGIA allows Stored XSS attacks in novo_memorando.php

WeGIA is a web manager for charitable institutions. An XSS Injection vulnerability was identified in novo_memorando.php. After the memo was submitted, the vulnerability was confirmed by accessing listar_memorandos_antigos.php. Upon loading this page, the injected script was executed in the browser.…

πŸ“… Published: July 7, 2025, 4:36 p.m. πŸ”„ Last Modified: July 10, 2025, 9:17 p.m.

6.9

CVSS4.0

CVE-2025-7136 - Campcodes Online Recruitment Management System view_vacancy.php sql injection

A vulnerability, which was classified as critical, was found in Campcodes Online Recruitment Management System 1.0. Affected is an unknown function of the file /admin/view_vacancy.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The expl…

πŸ“… Published: July 7, 2025, 4:32 p.m. πŸ”„ Last Modified: July 13, 2025, 9:47 p.m.
Total resulsts: 345202
Page 4364 of 34,521
Β« previous page Β» next page
Filters