9.3

CVSS4.0

CVE-2025-41371 - SQL injection vulnerability in Gandia Integra Total

A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /encuestas/integraweb_v4/integra/html/view/ac…

πŸ“… Published: Aug. 1, 2025, 12:28 p.m. πŸ”„ Last Modified: Oct. 8, 2025, 6:41 p.m.

9.3

CVSS4.0

CVE-2025-41370 - SQL injection vulnerability in Gandia Integra Total

A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /encuestas/integraweb/html/view/acceso.php.

πŸ“… Published: Aug. 1, 2025, 12:28 p.m. πŸ”„ Last Modified: Oct. 8, 2025, 6:33 p.m.

6.4

CVSS3.1

CVE-2025-6228 - Sina Extension for Elementor <= 3.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting vi…

The Sina Extension for Elementor (Header Builder, Footer Builter, Theme Builder, Slider, Gallery, Form, Modal, Data Table Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `Sina Posts`, `Sina Blog Post` and `Sina Table` widgets i…

πŸ“… Published: Aug. 1, 2025, 11:18 a.m. πŸ”„ Last Modified: April 20, 2026, 10:15 p.m.

6.4

CVSS3.1

CVE-2025-4684 - BlockSpare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites <= 3.2.13.1 - Authenti…

The BlockSpare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites – Post Grids, Sliders, Carousels, Counters, Page Builder & Starter Site Imports, No Coding Needed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTML attributes of Image Carousel and Image Sl…

πŸ“… Published: Aug. 1, 2025, 11:18 a.m. πŸ”„ Last Modified: April 22, 2026, 2:45 p.m.

6.7

CVSS4.0

CVE-2025-6398 -

A null pointer dereference vulnerability exists in the IOMap64.sys driver of ASUS AI Suite 3. The vulnerability can be triggered by a specially crafted input, which may lead to a system crash (BSOD). Refer to the ' Security Update for for AI Suite 3 ' section on the ASUS Security Advisory for mor…

πŸ“… Published: Aug. 1, 2025, 8:49 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-8443 - code-projects Online Medicine Guide login.php sql injection

A vulnerability was found in code-projects Online Medicine Guide 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument uname leads to sql injection. The attack may be launched remotely. The exploit has been disc…

πŸ“… Published: Aug. 1, 2025, 8:32 a.m. πŸ”„ Last Modified: Aug. 5, 2025, 6:53 p.m.

6.9

CVSS4.0

CVE-2025-8442 - code-projects Online Medicine Guide cussignup.php sql injection

A vulnerability has been found in code-projects Online Medicine Guide 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /cussignup.php. The manipulation of the argument uname leads to sql injection. The attack can be launched remotely. The exploi…

πŸ“… Published: Aug. 1, 2025, 8:02 a.m. πŸ”„ Last Modified: Aug. 5, 2025, 6:53 p.m.

6.9

CVSS4.0

CVE-2025-8441 - code-projects Online Medicine Guide pharsignup.php sql injection

A vulnerability, which was classified as critical, was found in code-projects Online Medicine Guide 1.0. Affected is an unknown function of the file /pharsignup.php. The manipulation of the argument phuname leads to sql injection. It is possible to launch the attack remotely. The exploit has been d…

πŸ“… Published: Aug. 1, 2025, 7:32 a.m. πŸ”„ Last Modified: Aug. 5, 2025, 6:54 p.m.

6.9

CVSS4.0

CVE-2025-8439 - code-projects Wazifa System updatesettings.php sql injection

A vulnerability, which was classified as critical, has been found in code-projects Wazifa System 1.0. This issue affects some unknown processing of the file /controllers/updatesettings.php. The manipulation of the argument Password leads to sql injection. The attack may be initiated remotely. The e…

πŸ“… Published: Aug. 1, 2025, 7:02 a.m. πŸ”„ Last Modified: Aug. 5, 2025, 6:54 p.m.

6.4

CVSS3.1

CVE-2025-7646 - The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <…

The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom script parameter in all versions up to, and including, 6.3.10 even when the user does not have the unfiltered_html c…

πŸ“… Published: Aug. 1, 2025, 6:44 a.m. πŸ”„ Last Modified: April 21, 2026, 4 a.m.
Total resulsts: 349182
Page 4439 of 34,919
Β« previous page Β» next page
Filters