5.6
CVE-2025-47808 - gstreamer1-plugins-base: GStreamer Subparse NULL Pointer Dereference
In GStreamer through 1.26.1, the subparse plugin's tmplayer_parse_line function may dereference a NULL pointer while parsing a subtitle file, leading to a crash.
6.6
CVE-2025-47183 - gstreamer1-plugins-good: GStreamer MP4 Parser Heap Overflow
In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_tree function may read past the end of a heap buffer while parsing an MP4 file, leading to information disclosure.
9.1
CVE-2025-45765 - ruby-jwt: Ruby-JWT Weak Encryption
ruby-jwt v3.0.0.beta1 was discovered to contain weak encryption. NOTE: the Supplier's perspective is "keysize is not something that is enforced by this library. Currently more recent versions of OpenSSL are enforcing some key sizes and those restrictions apply to the users of this gem also."
8.8
CVE-2023-41532 -
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the doctor_contact parameter in doctorsearch.php.
9.8
CVE-2025-50692 -
FoxCMS <=v1.2.5 is vulnerable to Code Execution in admin/template_file/editFile.html.
8.8
CVE-2023-41523 -
Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the emailAddress parameter at createClassTeacher.php.
7.4
CVE-2025-55137 -
LinkJoin through 882f196 mishandles lacks type checking in password reset.
8.8
CVE-2025-54788 - SuiteCRM: Authenticated Blind SQL Injection in InboundEmail module
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions and below, the InboundEmail module allows the arbitrary execution of queries in the backend database, leading to SQL injection. This can have wide-reaching implications on confidentβ¦
5.3
CVE-2025-54786 - SuiteCRM: Legacy iCal service allows unauthenticated access to meeting data
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, the broken authentication in the legacy iCal service allows unauthenticated access to meeting data. An unauthenticated actor can view any user's meeting (calendar β¦
8.8
CVE-2025-54785 - SuiteCRM is Vulnerable to PHP Object Injection in Reports
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, user-supplied input is not validated/sanitized before it is passed to the unserialize function, which could lead to penetration, privilege escalation, sensitive dβ¦