7.1

CVSS3.1

CVE-2023-44915 -

A cross-site scripting (XSS) vulnerability in the component /Login.php of c3crm up to v3.0.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the login_error parameter.

πŸ“… Published: June 25, 2025, midnight πŸ”„ Last Modified: June 26, 2025, 6:57 p.m.

5.7

CVSS3.1

CVE-2024-57708 -

An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __proto__, and Object.assign components. NOTE: this is disputed by the Supplier who does not agree it is a prototype pollution vulnerability.

πŸ“… Published: June 25, 2025, midnight πŸ”„ Last Modified: July 25, 2025, 9:15 p.m.

7.1

CVSS3.1

CVE-2025-25905 -

Cross-Site Scripting (XSS) vulnerability in CADClick v1.13.0 and before allows remote attackers to inject arbitrary web script or HTML via the "tree" parameter.

πŸ“… Published: June 25, 2025, midnight πŸ”„ Last Modified: July 13, 2025, 9:48 p.m.

7.5

CVSS3.1

CVE-2025-45332 -

vkoskiv c-ray 1.1 contains a Null Pointer Dereference (NPD) vulnerability in the parse_mtllib function of its data processing module, leading to unpredictable program behavior, causing segmentation faults, and program crashes.

πŸ“… Published: June 25, 2025, midnight πŸ”„ Last Modified: July 9, 2025, 7:07 p.m.

5.3

CVSS4.0

CVE-2025-6582 - SourceCodester Best Salon Management System edit-customer-detailed.php sql injection

A vulnerability, which was classified as critical, has been found in SourceCodester Best Salon Management System 1.0. Affected by this issue is some unknown functionality of the file /edit-customer-detailed.php. The manipulation of the argument editid leads to sql injection. The attack may be launc…

πŸ“… Published: June 24, 2025, 11:31 p.m. πŸ”„ Last Modified: July 2, 2025, 5:04 p.m.

5.3

CVSS4.0

CVE-2025-6581 - SourceCodester Best Salon Management System add-customer.php sql injection

A vulnerability classified as critical was found in SourceCodester Best Salon Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /add-customer.php. The manipulation of the argument name/email/mobilenum/gender/details/dob/marriage_date leads to sql injectio…

πŸ“… Published: June 24, 2025, 10:31 p.m. πŸ”„ Last Modified: July 2, 2025, 5:11 p.m.

6.9

CVSS4.0

CVE-2025-6580 - SourceCodester Best Salon Management System Login sql injection

A vulnerability classified as critical has been found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the component Login. The manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disc…

πŸ“… Published: June 24, 2025, 9:31 p.m. πŸ”„ Last Modified: July 2, 2025, 5:13 p.m.

1.7

CVSS4.0

CVE-2025-52884 - risc0-ethereum-contracts allows invalid commitment with digest value of zero to be accepted by Stee…

RISC Zero is a zero-knowledge verifiable general computing platform, with Ethereum integration. The risc0-ethereum repository contains Solidity verifier contracts, Steel EVM view call library, and supporting code. Prior to versions 2.1.1 and 2.2.0, the `Steel.validateCommitment` Solidity library fu…

πŸ“… Published: June 24, 2025, 8:20 p.m. πŸ”„ Last Modified: Oct. 2, 2025, 8:48 a.m.

5.3

CVSS3.1

CVE-2025-52883 - Meshtastic-Android vulnerable to forged DMs with no PKC showing up as encrypted

Meshtastic-Android is an Android application for the mesh radio software Meshtastic. Prior to version 2.5.21, an attacker is able to send an unencrypted direct message to a victim impersonating any other node of the mesh. This message will be displayed in the same chat that the victim normally comm…

πŸ“… Published: June 24, 2025, 8:12 p.m. πŸ”„ Last Modified: June 26, 2025, 6:58 p.m.

10

CVSS3.1

CVE-2025-52572 - Hikka vulnerable to RCE through dangling web interface

Hikka, a Telegram userbot, has vulnerability affects all users on all versions of Hikka. Two scenarios are possible. 1. Web interface does not have an authenticated session: attacker can use his own Telegram account to gain RCE to the server by authorizing in the dangling web interface. 2. Web inte…

πŸ“… Published: June 24, 2025, 8:10 p.m. πŸ”„ Last Modified: Dec. 8, 2025, 5:22 p.m.
Total resulsts: 343921
Page 4372 of 34,393
Β« previous page Β» next page
Filters