6.9

CVSS4.0

CVE-2025-6359 - code-projects Simple Pizza Ordering System cashconfirm.php sql injection

A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /cashconfirm.php. The manipulation of the argument transactioncode leads to sql injection. The attack may be launched remotely…

πŸ“… Published: June 20, 2025, 6:31 p.m. πŸ”„ Last Modified: June 26, 2025, 12:59 p.m.

8.1

CVSS3.1

CVE-2024-4994 - Cross-Site Request Forgery (CSRF) in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1.0 before 16.11.5, all versions starting from 17.0 before 17.0.3, all versions starting from 17.1.0 before 17.1.1 which allowed for a CSRF attack on GitLab's GraphQL API leading to the execution of arbitrary GraphQL mutati…

πŸ“… Published: June 20, 2025, 6:14 p.m. πŸ”„ Last Modified: Aug. 12, 2025, 2:52 p.m.

6.5

CVSS3.1

CVE-2024-4025 - Inefficient Regular Expression Complexity in GitLab

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions from 7.10 prior before 16.11.5, version 17.0 before 17.0.3, and 17.1 before 17.1.1. It is possible for an attacker to cause a denial of service using a crafted markdown page.

πŸ“… Published: June 20, 2025, 6:14 p.m. πŸ”„ Last Modified: Aug. 12, 2025, 2:51 p.m.

6.9

CVSS4.0

CVE-2025-6358 - code-projects Simple Pizza Ordering System saveorder.php sql injection

A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /saveorder.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The …

πŸ“… Published: June 20, 2025, 6 p.m. πŸ”„ Last Modified: June 26, 2025, 1:04 p.m.

6.9

CVSS4.0

CVE-2025-6357 - code-projects Simple Pizza Ordering System paymentportal.php sql injection

A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been classified as critical. Affected is an unknown function of the file /paymentportal.php. The manipulation of the argument person leads to sql injection. It is possible to launch the attack remotely. The exploit …

πŸ“… Published: June 20, 2025, 5:31 p.m. πŸ”„ Last Modified: June 26, 2025, 1:10 p.m.

6.9

CVSS4.0

CVE-2025-6356 - code-projects Simple Pizza Ordering System addmem.php sql injection

A vulnerability was found in code-projects Simple Pizza Ordering System 1.0 and classified as critical. This issue affects some unknown processing of the file /addmem.php. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and…

πŸ“… Published: June 20, 2025, 5:31 p.m. πŸ”„ Last Modified: June 26, 2025, 1:17 p.m.

2.7

CVSS4.0

CVE-2025-52484 - RISC Zero zkVM Underconstrained Vulnerability

RISC Zero is a general computing platform based on zk-STARKs and the RISC-V microarchitecture. Due to a missing constraint in the rv32im circuit, any 3-register RISC-V instruction (including remu and divu) in risc0-zkvm 2.0.0, 2.0.1, and 2.0.2 are vulnerable to an attack by a malicious prover. The …

πŸ“… Published: June 20, 2025, 5:21 p.m. πŸ”„ Last Modified: Oct. 2, 2025, 8:48 a.m.

8.7

CVSS3.1

CVE-2025-2443 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab

An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass in a user's browser under specific conditions, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

πŸ“… Published: June 20, 2025, 5:12 p.m. πŸ”„ Last Modified: Aug. 12, 2025, 2:50 p.m.

8.5

CVSS3.1

CVE-2025-5121 - Missing Authorization in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.4 and 18.0 before 18.0.2. A missing authorization check may have allowed compliance frameworks to be applied to projects outside the compliance framework's group.

πŸ“… Published: June 20, 2025, 5:12 p.m. πŸ”„ Last Modified: Aug. 12, 2025, 2:51 p.m.

6.9

CVSS4.0

CVE-2025-6355 - SourceCodester Online Hotel Reservation System execeditroom.php sql injection

A vulnerability has been found in SourceCodester Online Hotel Reservation System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/execeditroom.php. The manipulation of the argument userid leads to sql injection. The attack can be initiated remotely. The exp…

πŸ“… Published: June 20, 2025, 5 p.m. πŸ”„ Last Modified: Nov. 13, 2025, 3:19 p.m.
Total resulsts: 343935
Page 4407 of 34,394
Β« previous page Β» next page
Filters