5.3

CVSS4.0

CVE-2025-6346 - SourceCodester Advance Charity Management System fundDetails.php sql injection

A vulnerability was found in SourceCodester Advance Charity Management System 1.0. It has been classified as critical. This affects an unknown part of the file /members/fundDetails.php. The manipulation of the argument m06 leads to sql injection. It is possible to initiate the attack remotely. The …

πŸ“… Published: June 20, 2025, 3 p.m. πŸ”„ Last Modified: June 26, 2025, 2:44 p.m.

8.1

CVSS3.1

CVE-2025-3319 - IBM Spectrum Protect Server authentication bypass

IBM Spectrum Protect Server 8.1 through 8.1.26 could allow attacker to bypass authentication due to improper session authentication which can result in access to unauthorized resources.

πŸ“… Published: June 20, 2025, 2:50 p.m. πŸ”„ Last Modified: Aug. 24, 2025, 11:45 a.m.

4.3

CVSS3.1

CVE-2025-3228 - Unauthorized Guest user access to Playbook

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly retrieve requestorInfo from playbooks handler for guest users which allows an attacker access to the playbook run.

πŸ“… Published: June 20, 2025, 2:31 p.m. πŸ”„ Last Modified: July 8, 2025, 2:30 p.m.

4.3

CVSS3.1

CVE-2025-3227 - Unauthorized channel member management through playbook runs

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly enforce channel member management permissions in playbook runs, allowing authenticated users without the 'Manage Channel Members' permission to add or remove users from pub…

πŸ“… Published: June 20, 2025, 2:31 p.m. πŸ”„ Last Modified: July 8, 2025, 2:31 p.m.

5.1

CVSS4.0

CVE-2025-6345 - SourceCodester My Food Recipe Add Recipe Page add-recipe.php addRecipeModal cross site scripting

A vulnerability was found in SourceCodester My Food Recipe 1.0 and classified as problematic. Affected by this issue is the function addRecipeModal of the file /endpoint/add-recipe.php of the component Add Recipe Page. The manipulation of the argument Name leads to cross site scripting. The attack …

πŸ“… Published: June 20, 2025, 2:31 p.m. πŸ”„ Last Modified: June 26, 2025, 2:46 p.m.

6.9

CVSS4.0

CVE-2025-6344 - code-projects Online Shoe Store contactus.php sql injection

A vulnerability has been found in code-projects Online Shoe Store 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /contactus.php. The manipulation of the argument email leads to sql injection. The attack can be launched remotely. The exploit ha…

πŸ“… Published: June 20, 2025, 2 p.m. πŸ”„ Last Modified: June 26, 2025, 3:38 p.m.

4.1

CVSS3.1

CVE-2024-7586 - Insertion of Sensitive Information into Log File in GitLab

An issue was discovered in GitLab EE affecting all versions starting from 17.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, where webhook deletion audit log preserved auth credentials.

πŸ“… Published: June 20, 2025, 1:58 p.m. πŸ”„ Last Modified: Aug. 12, 2025, 2:50 p.m.

9.8

CVSS3.1

CVE-2024-53298 -

Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.1, contains a missing authorization vulnerability in the NFS export. An unauthenticated attacker with remote access could potentially exploit this vulnerability leading to unauthorized filesystem access. The attacker may be able to read, modify…

πŸ“… Published: June 20, 2025, 1:51 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

5.3

CVSS3.1

CVE-2025-32753 -

Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.1, contains an improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service, informati…

πŸ“… Published: June 20, 2025, 1:46 p.m. πŸ”„ Last Modified: July 11, 2025, 12:34 p.m.

6.9

CVSS4.0

CVE-2025-6343 - code-projects Online Shoe Store admin_product.php sql injection

A vulnerability, which was classified as critical, was found in code-projects Online Shoe Store 1.0. Affected is an unknown function of the file /admin/admin_product.php. The manipulation of the argument pid leads to sql injection. It is possible to launch the attack remotely. The exploit has been …

πŸ“… Published: June 20, 2025, 1:31 p.m. πŸ”„ Last Modified: June 26, 2025, 3:41 p.m.
Total resulsts: 343921
Page 4417 of 34,393
Β« previous page Β» next page
Filters