8.7

CVSS4.0

CVE-2025-6367 - D-Link DIR-619L formSetDomainFilter stack-based overflow

A vulnerability was found in D-Link DIR-619L 2.06B01. It has been declared as critical. This vulnerability affects unknown code of the file /goform/formSetDomainFilter. The manipulation of the argument curTime/sched_name_%d/url_%d leads to stack-based buffer overflow. The attack can be initiated re…

πŸ“… Published: June 20, 2025, 9 p.m. πŸ”„ Last Modified: June 25, 2025, 8:07 p.m.

6.9

CVSS4.0

CVE-2025-6365 - HobbesOSR Kitten pgtable.h set_pte_at resource consumption

A vulnerability was found in HobbesOSR Kitten up to c4f8b7c3158983d1020af432be1b417b28686736 and classified as critical. Affected by this issue is the function set_pte_at in the library /include/arch-arm64/pgtable.h. The manipulation leads to resource consumption. Continious delivery with rolling r…

πŸ“… Published: June 20, 2025, 8:31 p.m. πŸ”„ Last Modified: Sept. 30, 2025, 6:27 p.m.

6.9

CVSS4.0

CVE-2025-6364 - code-projects Simple Pizza Ordering System adduser-exec.php sql injection

A vulnerability has been found in code-projects Simple Pizza Ordering System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /adduser-exec.php. The manipulation of the argument Username leads to sql injection. The attack can be launched remotel…

πŸ“… Published: June 20, 2025, 8:31 p.m. πŸ”„ Last Modified: June 26, 2025, 3:28 p.m.

6.9

CVSS4.0

CVE-2025-6363 - code-projects Simple Pizza Ordering System adding-exec.php sql injection

A vulnerability, which was classified as critical, was found in code-projects Simple Pizza Ordering System 1.0. Affected is an unknown function of the file /adding-exec.php. The manipulation of the argument ingname leads to sql injection. It is possible to launch the attack remotely.

πŸ“… Published: June 20, 2025, 8 p.m. πŸ”„ Last Modified: July 2, 2025, 6:56 p.m.

3.1

CVSS3.1

CVE-2023-5600 - Missing Authorization in GitLab

An issue has been discovered in GitLab EE affecting all versions starting from 16.0 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. Arbitrary access to the titles of an private specific references could be leaked through the service-desk …

πŸ“… Published: June 20, 2025, 7:31 p.m. πŸ”„ Last Modified: Aug. 12, 2025, 2:52 p.m.

6.9

CVSS4.0

CVE-2025-6362 - code-projects Simple Pizza Ordering System editpro.php sql injection

A vulnerability, which was classified as critical, has been found in code-projects Simple Pizza Ordering System 1.0. This issue affects some unknown processing of the file /editpro.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely.

πŸ“… Published: June 20, 2025, 7:31 p.m. πŸ”„ Last Modified: June 26, 2025, 3:30 p.m.

6.9

CVSS4.0

CVE-2025-6361 - code-projects Simple Pizza Ordering System adds.php sql injection

A vulnerability classified as critical was found in code-projects Simple Pizza Ordering System 1.0. This vulnerability affects unknown code of the file /adds.php. The manipulation of the argument userid leads to sql injection. The attack can be initiated remotely.

πŸ“… Published: June 20, 2025, 7:31 p.m. πŸ”„ Last Modified: June 26, 2025, 3:33 p.m.

6.9

CVSS4.0

CVE-2025-6360 - code-projects Simple Pizza Ordering System portal.php sql injection

A vulnerability classified as critical has been found in code-projects Simple Pizza Ordering System 1.0. This affects an unknown part of the file /portal.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed t…

πŸ“… Published: June 20, 2025, 7 p.m. πŸ”„ Last Modified: June 26, 2025, 3:35 p.m.

10

CVSS4.0

CVE-2025-34030 - sar2html OS Command Injection

An OS command injection vulnerability exists in sar2html version 3.2.2 and prior via the plot parameter in index.php. The application fails to sanitize user-supplied input before using it in a system-level context. Remote, unauthenticated attackers can inject shell commands by appending them to the…

πŸ“… Published: June 20, 2025, 6:40 p.m. πŸ”„ Last Modified: April 7, 2026, 2:09 p.m.

9.4

CVSS4.0

CVE-2025-34029 - Edimax EW-7438RPn Mini OS Command Injection via syscmd.asp

An OS command injection vulnerability exists in the Edimax EW-7438RPn Mini firmware version 1.13 and prior via the syscmd.asp form handler. The /goform/formSysCmd endpoint exposes a system command interface through the sysCmd parameter. A remote authenticated attacker can submit arbitrary shell com…

πŸ“… Published: June 20, 2025, 6:38 p.m. πŸ”„ Last Modified: April 7, 2026, 2:09 p.m.
Total resulsts: 343942
Page 4406 of 34,395
Β« previous page Β» next page
Filters