6.9
CVE-2025-8376 - code-projects Vehicle Management updatebal.php sql injection
A vulnerability classified as critical has been found in code-projects Vehicle Management 1.0. Affected is an unknown function of the file /updatebal.php. The manipulation of the argument company leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed toβ¦
6.9
CVE-2025-8375 - code-projects Vehicle Management addvehicle.php sql injection
A vulnerability was found in code-projects Vehicle Management 1.0. It has been rated as critical. This issue affects some unknown processing of the file /addvehicle.php. The manipulation of the argument vehicle leads to sql injection. The attack may be initiated remotely. The exploit has been disclβ¦
6.1
CVE-2025-24854 - Apache JSPWiki: Cross-Site Scripting (XSS) in JSPWiki Image plugin
A carefully crafted request using the Image plugin could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.12.3 or later.
7.5
CVE-2025-24853 - Apache JSPWiki: Cross-Site Scripting (XSS) in JSPWiki Header Link processing
A carefully crafted request when creating a header link using the wiki markup syntax, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Further research by the JSPWiki team showed that the markdown parser allowed β¦
6.9
CVE-2025-8374 - code-projects Vehicle Management addcompany.php sql injection
A vulnerability was found in code-projects Vehicle Management 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /addcompany.php. The manipulation of the argument company leads to sql injection. The attack can be initiated remotely. The exploit has been disclβ¦
6.9
CVE-2025-8192 - Race condition in AndroidTV TvSettings
There exists a TOCTOU race condition in TvSettings AppRestrictionsFragment.java that lead to start of attacker supplied activity in Settingsβ context, i.e. system-uid context, thus lead to launchAnyWhere. The core idea is to utilize the time window between the check of Intent and the use to Intent β¦
0.0
CVE-2025-54846 -
Not used
0.0
CVE-2025-54847 -
Not used
0.0
CVE-2025-54839 -
Not used
0.0
CVE-2025-54840 -
Not used