5.3

CVSS4.0

CVE-2025-6604 - SourceCodester Best Salon Management System add-staff.php sql injection

A vulnerability classified as critical has been found in SourceCodester Best Salon Management System 1.0. This affects an unknown part of the file /panel/add-staff.php. The manipulation of the argument Name leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…

πŸ“… Published: June 25, 2025, 1 p.m. πŸ”„ Last Modified: July 2, 2025, 4:36 p.m.

9.2

CVSS4.0

CVE-2025-6543 - Memory overflow vulnerability leading to unintended control flow and Denial of Service

Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway whenΒ configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

πŸ“… Published: June 25, 2025, 12:49 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

4.3

CVSS3.1

CVE-2025-25012 - Kibana Open Redirect

URL redirection to an untrusted site ('Open Redirect') in Kibana can lead to sending a user to an arbitrary site and server-side request forgery via a specially crafted URL.

πŸ“… Published: June 25, 2025, 11:52 a.m. πŸ”„ Last Modified: Sept. 30, 2025, 8:27 p.m.

4.8

CVSS4.0

CVE-2025-6603 - coldfunction qCUDA qcow.c qcow_make_empty integer overflow

A vulnerability was found in coldfunction qCUDA up to db0085400c2f2011eed46fbc04fdc0873141688e. It has been rated as problematic. Affected by this issue is the function qcow_make_empty of the file qCUDA/qcu-device/block/qcow.c. The manipulation of the argument s->l1_size leads to integer overflow. …

πŸ“… Published: June 25, 2025, 10:31 a.m. πŸ”„ Last Modified: June 26, 2025, 6:57 p.m.

5.5

CVSS3.1

CVE-2025-41647 - Lenze: Plaintext Password Disclosure in PLC Designer V4 Interface

A local, low-privileged attacker can learn the password of the connected controller in PLC Designer V4 due to an incorrect implementation that results in the password being displayed in plain text under special conditions.

πŸ“… Published: June 25, 2025, 9:40 a.m. πŸ”„ Last Modified: June 26, 2025, 6:57 p.m.

8.5

CVSS4.0

CVE-2025-49797 -

Multiple Brother driver installers for Windows contain a privilege escalation vulnerability. If exploited, an arbitrary program may be executed with the administrative privilege. As for the details of affected product names, model numbers, and versions, refer to the information provided by the resp…

πŸ“… Published: June 25, 2025, 9:25 a.m. πŸ”„ Last Modified: Aug. 19, 2025, 7:15 a.m.

5.1

CVSS4.0

CVE-2025-6613 - PHPGurukul Hospital Management System manage-patient.php cross site scripting

A vulnerability classified as problematic was found in PHPGurukul Hospital Management System 4.0. Affected by this vulnerability is an unknown functionality of the file /doctor/manage-patient.php. The manipulation of the argument Name leads to cross site scripting. The attack can be launched remote…

πŸ“… Published: June 25, 2025, 9:25 a.m. πŸ”„ Last Modified: July 6, 2025, 10:16 p.m.

7.5

CVSS3.1

CVE-2025-5927 - Everest Forms (Pro) <= 1.9.4 - Unauthenticated Path Traversal to Arbitrary File Deletion

The Everest Forms (Pro) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_entry_files() function in all versions up to, and including, 1.9.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the serv…

πŸ“… Published: June 25, 2025, 9:21 a.m. πŸ”„ Last Modified: April 8, 2026, 5:11 p.m.

8

CVSS3.1

CVE-2025-41255 - Cyberduck and Mountain Duck - Improper Certificate Store Handling

Cyberduck and Mountain Duck improperly handle TLS certificate pinning for untrusted certificates (e.g., self-signed), unnecessarily installing it to the Windows Certificate Store of the current user without any restrictions. This issue affects Cyberduck through 9.1.6 and Mountain Duck th…

πŸ“… Published: June 25, 2025, 9:21 a.m. πŸ”„ Last Modified: June 26, 2025, 6:58 p.m.

7.4

CVSS3.1

CVE-2025-41256 - Cyberduck and Mountain Duck - Weak Hash Algorithm for Certificate Fingerprint

Cyberduck and Mountain Duck improper handle TLS certificate pinning for untrusted certificates (e.g., self-signed), since the certificate fingerprint is stored as SHA-1, although SHA-1 is considered weak. This issue affects Cyberduck: through 9.1.6; Mountain Duck: through 4.17.5.

πŸ“… Published: June 25, 2025, 9:16 a.m. πŸ”„ Last Modified: June 26, 2025, 6:57 p.m.
Total resulsts: 343887
Page 4366 of 34,389
Β« previous page Β» next page
Filters